KuppingerCole Analysts

KuppingerCole Analysts

By KuppingerCole AnalystsTechnology
Download on the App Store

KuppingerCole Analysts episodes

  • Analyst Chat #318: Before You Build - IAM Customization Governance in the AI Era

    AI can build your IAM connector in an afternoon. But was the connector ever the bottleneck? In this episode, Matthias invited Patrick Teichmann, lead advisor at KuppingerCole Analysts, to talk about his newly published advisory note on IAM customization governance and ask the harder question: what happens when the cost of building disappears, but the cost of maintaining doesn't?

    Key Topics:

    • Why AI removes the development bottleneck in IAM — but exposes the real one: requirements definition
    • The danger of saying yes too easily: how AI makes it tempting to build what should never be built
    • Security risks in AI-generated IAM code: what the research actually shows
    • A seven-step framework for evaluating any IAM customization before writing a single line
    • The customization registry: how to build transparency and governance into what already exists
    • When to stop customizing and ask whether the platform itself is the wrong tool

    ⚠️ "AI makes code cheap but the bottleneck in IAM was never primarily creating the code." Patrick Teichmann on why removing the development barrier without fixing requirements definition is a recipe for a new generation of Lotus Notes.
    πŸ“„ Patrick's advisory note on IAM Customization Governance is published on the KuppingerCole Analysts website now; watch this episode first, then dive into the research.

    42 min
  • Analyst Chat #317: MCP Is Just Another API, and That's the Bad News

    MCP servers are showing up on the internet without authentication, malicious tool definitions are being injected into trusted projects, and three security teams are defending the same environment without sharing a single threat signal. In this week's episode, Matthias sits down with Alexei Balaganski, Lead Analyst and CTO at KuppingerCole Analysts, to dig into the real MCP security problem and why the answer isn't an MCP security product.

    Key Topics:

    βœ… The LocalAI attack: 23 unprotected MCP servers, root access in minutes, military data exposed
    βœ… Is MCP a new security problem or just a new label for old ones?
    βœ… The Deadbugs attack: how tool descriptions were silently poisoned to manipulate AI agents
    βœ… Who is responsible for MCP security: Anthropic, the vendor, or you?
    βœ… Tool poisoning, prompt injection, and the gaps between AppSec, NetSec, and endpoint teams
    βœ… Monday morning recommendations: what to actually do about MCP security right now

    πŸ” "Models reason, APIs act, and identity grants the authority to act" Alexei Balaganski's one-line summary of why MCP security cannot be solved by a single tool or a single team.

    πŸ“… MCP is a symptom, not the disease, join KuppingerCole Analysts at the upcoming AIdentity & NHI Impact Day, CIAM Impact Day, and Identity-Centric Cybersecurity Summit events in Germany to continue this conversation in person.

    52 min
  • Analyst Chat #316: Integration Debt & the Vibe Coding Trap in Identity Management

    Orchestration has been part of the Identity Fabric concept from the beginning but most organizations are still getting it wrong. In this episode, Matthias sits down with Martin Kuppinger, to explore why orchestration is one of the most underestimated architectural capabilities in identity management, what "integration debt" really means, and why vibe coding is the new Lotus Notes disaster waiting to happen.

    Key Topics:

    βœ… Orchestration inside the Identity Fabric: capability, not product category
    βœ… Integration debt: how organizations quietly accumulate orchestration they no longer understand
    βœ… The Lotus Notes warning: what vibe coding and no-code/low-code get wrong at scale
    βœ… Why AI can document and test code — but still doesn't understand what it's doing
    βœ… Start with orchestration strategy, not the tool — and always ask "how do I get rid of this?"
    βœ… Ownership and governance: who is responsible for orchestration artifacts when people leave?

    πŸͺ· "Lotus Notes: a wonderful example of where vibe coding went rogue — organizations ending up with thousands of databases, not knowing who did it, why, or if it's still needed." Sound familiar? Martin Kuppinger on why orchestration governance is non-negotiable.

    πŸ“… Join KuppingerCole Analysts at the AIdentity & NHI Impact Day on October 6th in Munich

    26 min
  • Analyst Chat #315: Shadow SaaS, Shadow AI & the Governance Gap

    SSPM is dead, long live SaaS Security and AI Governance. When Matthias and Matthew last spoke in February, SaaS Security Posture Management was the topic. Six months on, the market has moved decisively: shadow SaaS and shadow AI are now the same problem, and the vendors covering them have merged the two worlds into one. What changed? What do the new capabilities look like? And what does KuppingerCole Analysts' newly published research says about where the market is heading?

    Key Topics:

    βœ… Why SSPM is passé — and why SaaS Security and AI Governance belong together
    βœ… Shadow IT, shadow SaaS, shadow AI: the same problem at increasing speed and scale
    βœ… Discovery as the foundational capability: you can't govern what you can't see
    βœ… Where to sniff: browser plugins, email, endpoints, identity providers, and procurement systems
    βœ… AI agents as a new identity type — and why the controls for humans and NHIs are converging
    βœ… Market outlook: the AI side is hitting another gear, and acquisitions are coming

    πŸ” "The majority of SaaS and AI applications are still unknown to the IT and security team." Matthew Gardiner on why discovery is the gating capability — and why most organizations haven't closed that gap yet.

    30 min
  • Analyst Chat #314: Can You Trust AI to Verify AI Code?

    AI writes the code. But who checks it, and who is accountable when it goes wrong? In this episode, Matthias is joined by two colleagues: Guillaume Teixeron, bringing 20 years of experience on the product side of identity and authentication, and Jonathan Care, KuppingerCole Analysts' Director of Practice AI. Together they tackle the security gap opening up between how fast AI generates code and how slowly organizations are catching up on assurance, provenance, and accountability.

    Key Topics:

    βœ… AI in software development: from hype to structural baseline — but governance is still improvised
    βœ… Three tectonic shifts in AppSec: provenance, scale, and non-human identity
    βœ… Why organizations have industrialized code production but not code assurance
    βœ… The core question: can you trust AI to verify AI-generated code?
    βœ… Agent autonomy in production pipelines — the next flashpoint nobody has resolved yet
    βœ… How regulation (CRA, NIS2, DORA) will settle the provenance argument before the market does

    ⚑ "We have industrialized code production. We have not industrialized code assurance." Jonathan Care on why the security control set was built for human-authored code moving at human speed — and neither assumption is true anymore.

    πŸ“… Join KuppingerCole Analysts at the AIdentity & NHI Impact Day in Munich this October — where the accountability and provenance questions raised in this episode will be front and center.

    37 min
  • Analyst Chat #313: When AI Agents Don't Play Nice - Multi-Agent Security Risks

    What happens when you put three AI agents in a room and tell them to solve the same problem? Anthropic ran the experiment — and the results are more unsettling than you'd expect. In this episode, Matthias Reinwarth sits down with Jonathan Care, KuppingerCole Analysts' newly appointed Director of Practice AI, to unpack the findings and ask what they mean for enterprise security, identity management, and the CISOs trying to govern it all.

    Key Topics:

    βœ… Anthropic's multi-agent experiment: three Claude instances, one codebase, unexpected outcomes
    βœ… Why coordination does not emerge naturally from intelligence — in agents or in humans
    βœ… The anthropomorphism trap: why comparing agents to dogs, kids, and wizards is useful but dangerous
    βœ… Social pressure, mechanisms, and the open research problem of agent cooperation
    βœ… Risk tolerance as a prerequisite for any agentic architecture — and how to define it
    βœ… Why correlated agents without coordination break your redundancy and business continuity assumptions

    πŸ€– "If agents are highly correlated but lack coordination, redundancy does not provide the risk diversification we would expect." Jonathan Care on why multi-agent systems are a different beast and why CISOs need to treat them that way.

    πŸ“… Join KuppingerCole Analysts at the AIdentity & NHI Impact Day on October 6th in Munich where many of the open questions raised in this episode will be on the agenda

    37 min
  • Analyst Chat #312: Is AI Killing IVIP Before It Even Matures?

    IVIP, Identity Visibility and Intelligence Platform, was one of the hottest acronyms to emerge from the identity market in 2025. But almost a year on, has it delivered on its promise? And more importantly, could AI already be making it obsolete before it even matures? In this episode, Matthias and Martin Kuppinger pick up where they left off and ask the hard questions about IVIP's future.

    Key Topics:

    βœ… IVIP revisited: still a set of capabilities, not a platform — and vendors are mostly relabeling
    βœ… Can AI make IVIP obsolete before it ever becomes a mature category?
    βœ… How AI is finally tackling IGA's oldest unsolved problem: application integration at scale
    βœ… Why IVIP falls short on action — spotting anomalies is not the same as acting on them
    βœ… IVIP, ITDR, and IGA convergence: does the category distinction even matter anymore?
    βœ… Strategic advice for IVIP vendors: observability, automation, and the path to relevance

    πŸ€– "The MVP can frequently be done well with AI doing it at scale, manageable, as a real solution and not a set of homegrown tools? That is a very different story." Martin Kuppinger on why AI changes everything for IVIP — and nothing at once.

    πŸ“… Don't miss the KuppingerCole Analysts Identity Fabric Impact Day on September 9th in Cologne 

    25 min
  • Analyst Chat #311: Architecting Your Own Digital Sovereignty

    Digital sovereignty is one of the most talked-about topics in European tech policy right now and according to Alexei Balaganski, most of the conversation is going in completely the wrong direction. In this episode, Matthias sits down with Alexei to challenge the assumptions behind the sovereignty debate, redefine what the term actually means, and lay out what organizations should really be doing about it.

    Key Topics:

    βœ… Why the "digital sovereignty" conversation has gone wrong — and what Alcatraz has to do with it
    βœ… The only correct definition of sovereignty: can you keep operating when a dependency disappears?
    βœ… Why sovereignty is just business continuity engineering — not a procurement decision
    βœ… How sovereign Europe really is today: the numbers are worse than you think
    βœ… Why "buy European" is a political preference, not a security strategy
    βœ… Decentralization, crypto agility, and distributed storage as practical sovereignty tools

    πŸ›οΈ "Sovereignty is not about who you're buying from, it's about what happens when you can no longer buy from them." Alexei Balaganski on why the European sovereignty debate is asking the wrong question entirely.
    πŸ” "Nobody, not even the EU, should prescribe how to solve your sovereignty issues." A rare episode with almost no AI but possibly the most important conversation KuppingerCole Analysts has published this year.

    31 min
  • Analyst Chat #310: AI Escaped the Sandbox - The OpenAI Hugging Face Hack (special episode)

    When an OpenAI test model escaped its sandbox and attacked Hugging Face's production infrastructure, headlines called it a Skynet moment. But was it? In this special flash news episode, Matthias Reinwarth brings together four KuppingerCole Analysts experts — Alexei Balaganski, Jonathan Care, John Tolbert, and Martin Kuppinger — to cut through the noise and ask the real question: what actually went wrong, and what should organizations do about it?

    Key Topics:

    βœ… What actually happened: two separate incidents dressed up as one dramatic story
    βœ… Why the sandbox failure was a containment and design problem — not an AI apocalypse
    βœ… Jonathan Care's core argument: the breach was credentials, not packets — you can't firewall your way out
    βœ… Non-human identity and agent identity as the real unsolved problem at the heart of the incident
    βœ… Secrets sprawl, overprivileged service accounts, and the absence of least privilege for AI agents
    βœ… Was it a containment failure, an identity failure, an observability failure, or a governance failure?

    🐯 "OpenAI had a pet tiger and the tiger escaped, Hugging Face was just walking down the street." Alexei Balaganski on why the most dramatic AI security story of the year was actually two separate failures.
    πŸ” Four KuppingerCole Analysts experts, one incident, and the identity governance lessons every organization needs to hear.

    33 min
  • Analyst Chat #309: Fabrics Deep Dive II - the Identity Fabric as the Blueprint

    The Identity Fabric isn't just a concept, it's a working tool that KuppingerCole Analysts advisors use every day with clients. In this second episode of the fabric mini-series, Matthias sits down with Martin Kuppinger and Phillip Messerschmidt to explore how the Identity Fabric and Reference Architecture are applied in real client engagements, why capability-based thinking beats tool-centric thinking every time, and how the fabric evolves to stay relevant in a world of constant buzzwords.

    Key Topics:

    βœ… How the Identity Fabric is used in practice: maturity assessments, gap analyses, roadmaps, and tool selection
    βœ… Why the right order always goes capabilities → services → tools — never the other way around
    βœ… What happens when tools are used for things they were never meant to do
    βœ… Why organizing teams around capabilities — not tools — is the future of IT operations
    βœ… The Identity Fabric built for 2040: long-term thinking in a fast-moving market
    βœ… How the fabric absorbs buzzwords like IVIP, ISPM, and ITDR — and why that proves the concept

    🧡 "Every second day someone comes up with a new buzzword, the Identity Fabric helps you strip it down to capabilities and ask: is there really something new here?" Martin Kuppinger on why structured thinking beats buzzword bingo.

    πŸ“… This is episode two of KuppingerCole Analysts' fabric mini-series, the Cybersecurity Fabric and AI Security Fabric episodes are coming next. Subscribe so you don't miss them.

    28 min

About KuppingerCole Analysts

From the publisher's feed

KuppingerCole Analysts AG is an international, independent analyst organization offering technology research, neutral advice and events in Identity Management, Cybersecurity and Artificial…