KuppingerCole Analysts

KuppingerCole Analysts

By KuppingerCole AnalystsTechnology
Download on the App Store

KuppingerCole Analysts episodes

  • Analyst Chat #308: Beyond SASE - What a Real Zero Trust Platform Looks Like

    Zero trust has a label problem. After more than a decade, the term has been stretched, diluted, and attached to products that don't come close to delivering what zero trust actually promises. In this episode, Matthias sits down with Alexei Balaganski, lead analyst at KuppingerCole Analysts, to share the findings from six months of research and reveal which vendors actually built a real Zero Trust Platform.

    Key Topics:

    βœ… Why zero trust is a strategy, not a product — and what that means for procurement
    βœ… The four non-negotiable requirements for a real Zero Trust Platform
    βœ… What separates a genuine platform from a collection of tools with a zero trust label
    βœ… NHIs, AI agents, and data protection as the new frontiers of zero trust architecture
    βœ… Three critical questions every RFP for a ZTP should include

    πŸ” "Stop looking for a Zero Trust Platform" - yes, really. Alexei Balaganski explains why that mindset shift is the most important thing a CISO can do before opening a single RFP.

    πŸ“Š The KuppingerCole Analysts Zero Trust Platform Buyers Compass and Leadership Compass are both published: watch this episode first, then dive into the research.

    43 min
  • Analyst Chat #307: Fabrics Deep Dive I - Why "Fabric"? The term, the idea and how to use it

    Seven years ago, KuppingerCole Analysts introduced the Identity Fabric concept and it has shaped how organizations structure identity management ever since. In this episode, Matthias sits down with Martin Kuppinger, co-founder and distinguished analyst at KuppingerCole Analysts, to revisit the origins of the Fabric paradigm, explain why it still holds today, and preview where it's headed next into cybersecurity, AI security, and beyond.

    Key Topics:

    βœ… Why the Identity Fabric concept emerged in 2019 — tool sprawl, siloed IAM, and the collapse of the perimeter
    βœ… What "fabric" actually means: a capability-driven layer connecting all identities to all services
    βœ… Why capabilities should define tools — not the other way around
    βœ… How the fabric concept scales to cybersecurity and AI security architectures
    βœ… The fabric in practice: maturity assessments, requirements analysis, and target operating models
    βœ… A look ahead to 2040: why the core principles are built to last

    "The job of identity management is to provide seamless access for everyone and everything to every service" — seven years on, that definition still holds. Find out why in this episode.

    πŸ“… This is the first episode of a new series on the fabric paradigm, covering Identity Fabric, Cybersecurity Fabric, and AI Security Fabric.

    20 min
  • Analyst Chat #306: Make or Buy? A Structured Framework for Smarter Tech Decisions

    Build or buy, it sounds like a simple question, but for most organizations, it's one of the most consequential and poorly structured decisions they make. In this episode, Matthias sits down with analyst and advisor Phillip Messerschmidt, who turned his hands-on advisory experience into a structured framework for getting the make-or-buy decision right every time.

    Key Topics:

    βœ… Why "we can build it cheaper" is almost always a biased and incomplete argument
    βœ… How the originating perspective (business unit, IT, security) shapes — and distorts — the decision
    βœ… The most common and costly mistakes organizations make when going the build route
    βœ… When buying is clearly the better path: expertise gaps, speed, scalability, and vendor roadmaps
    βœ… Why security and risk must be part of the decision from day one — not an afterthought
    βœ… A structured, holistic framework for making the right make-or-buy call

    "This cheap solution can quickly turn into a security risk, an open attack, a breach — and much more cost than thinking about risk by design." Sound familiar? This episode is for you.

    37 min
  • Beyond SOAR: How AI Agents Are Transforming Security Operations

    Alert overload, 24/7 coverage gaps, and human threat actors who never stop — the SOC has problems that traditional SOAR and rule-based systems simply can't solve. In this sponsored videocast, KuppingerCole analyst Matthew Gardiner and Rick Bosworth, Head of Product Marketing at Torq, dig into the findings of KuppingerCole's Emerging AI SOC Leadership Compass and explore what it actually takes to build an AI-powered security operations center.

    Key Topics:

    βœ… Why rule-based SOAR has hit a wall — and how AI agents address what it can't
    βœ… The autonomy dial: why full automation isn't the goal and how to build trust incrementally
    βœ… Integrations, RAG, and MCP: the new data infrastructure powering AI agents in the SOC
    βœ… DIY SOC vs. managed providers: how agentic AI is reshuffling the build-vs-buy decision
    βœ… Where to start: alert triage, phishing, and typosquatting as low-risk entry points
    βœ… Guardrails, transparency, and the non-deterministic challenge of AI-driven security

    "AI agents hate people because they're slow" — but full autonomy isn't the answer either. Find out how leading SOC teams are finding the right balance between speed and control.

    This videocast is sponsored by Torq — featured in KuppingerCole's Emerging AI SOC Leadership Compass. Read the report, then watch this session to hear the findings brought to life.

    38 min
  • Analyst Chat #305: IGA in 2026 - NHIs, Sovereignty & the Platform Shift

    IGA is often dismissed as a mature, stable market but that couldn't be further from the truth. In this episode, Matthias sits down with Nitish Deshpande, to explore how identity governance and administration is being reshaped by NHIs, AI-driven intelligence, deployment sovereignty, and a wave of challenger vendors.

    Key Topics:

    βœ… How IGA has evolved from static, siloed tools to integrated, multi-identity platforms
    βœ… Non-human identities: IGA vendors are now covering NHI governance — and customers are demanding it
    βœ… Where IGA still falls short: role mining, anomaly detection, policy simulation, and workflow automation
    βœ… The deployment model debate: SaaS vs. on-premise vs. hybrid — and the feature parity problem
    βœ… EU sovereignty as a competitive differentiator for European IGA vendors
    βœ… What's coming next: real-time governance, access intelligence, and a new IGA report category

    44 vendors evaluated, a surge of newcomers, and a market quietly reinventing itself — the KuppingerCole IGA Leadership Compass is out now and covers everything discussed in this episode.

    21 min
  • Analyst Chat #304: Agents, Fabric, and the Unfinished Business of IAM, A Look Back at EIC 2026

    Four weeks after EIC 2026 in Berlin, Matthias Reinwarth and Phillip Messerschmidt sit down to reflect on what the European Identity and Cloud Conference revealed about the state of identity and access management and what it means for the year ahead. Spoiler: agentic AI dominated, but it wasn't the only story.

    Key Topics:

    βœ… Agentic AI as a new class of insider threat — autonomous, non-deterministic, and without ethics
    βœ… Data-centric defense vs. agent discovery: protect the vault, not the crowd
    βœ… Why dynamic authorization and behavior analytics are the IAM industry's urgent next step
    βœ… Data sovereignty and geopolitics: eroding trust in non-European SaaS vendors
    βœ… AuthZEN wins the EIC Award — a standard built before anyone knew the problem it would solve
    βœ… Martin Kuppinger's closing keynote: "Everything we failed to solve in the past decades bites back now"

    "An agent behaves like a human insider threat — but without any sense of right or wrong." If your IAM program isn't ready for that, this episode is required listening.

    36 min
  • Analyst Chat #303: B2B Identity & Access Management - A New Market Unpacked

    Business relationships are complex and traditional IAM wasn't built for them. In this episode, Matthias Reinwarth sits down with Principal analyst John Tolbert, author of KuppingerCole Analysts' first-ever B2B IAM Leadership Compass, to explore why Business-to-Business Identity and Access Management is emerging as its own distinct market and what it takes to get it right.

    Key Topics:
    βœ… Why B2B IAM sits between workforce IAM and CIAM — and why neither alone is sufficient
    βœ… Delegated administration: handing identity governance to partner and supplier organizations
    βœ… Federation, lifecycle management, and the risks of trusting external HR processes
    βœ… "Know Your Business" — vetting organizations, sanctions screening, and org-level trust
    βœ… Fine-grained authorization: why RBAC falls short and ABAC/RBAC are taking over
    βœ… Agentic AI in B2B IAM: agents acting on behalf of external organizations

    Supply chains with thousands of partner organizations, freelancers with hour-long access windows, and AI agents acting on behalf of external companies B2B IAM has to handle all of it. KuppingerCole Analysts' first B2B IAM Leadership Compass is out now read it alongside this episode to get the full picture of an emerging market you can't afford to ignore.

    30 min
  • Is Your CDN Secure? CDN vs. DDoS Mitigation Unpacked with Qrator Labs

    Speed and security are no longer separate concerns. In this videocast, Osman Celik sits down with Andrey Leskin, CTO of Qrator Labs, to break down what Content Delivery Networks really are in 2026 and why they've become a critical piece of modern security infrastructure, not just a performance tool.

    Key Topics:

    βœ… What CDNs are and why they're no longer optional for competitive organizations
    βœ… How CDN and DDoS mitigation differ — and where they overlap
    βœ… Cache busting, HTTP floods, Slowloris and other real-world attack vectors
    βœ… Why "security-first CDN" is fundamentally different from "CDN with security bolted on"
    βœ… What CISOs and infrastructure leaders should look for when evaluating CDN solutions
    βœ… How to measure CDN value from day one: round trip time and time to render

    A CDN without security is just a bigger target — find out why building security in from the ground up changes everything.

    17 min
  • Analyst Chat #302: PAM Is No Longer a Vault - The New Identity Security Layer

    Privileged Access Management has outgrown the vault. In this episode, Matthias sits down with lead analyst Alejandro Leal, author of KuppingerCole's newly released PAM Leadership Compass, to explore how the definition of privilege itself has changed, what NHIs and agentic AI mean for PAM, and why deployment sovereignty is now a boardroom conversation.

    Key Topics:

    βœ… How the definition of "privilege" has shifted from admin accounts to dynamic runtime identity capabilities
    βœ… PAM convergence with IGA, CIEM, ITDR, SIEM, and SOAR — the end of the standalone PAM product
    βœ… Non-Human Identities (NHIs) and agentic AI: the silent accumulation of machine privilege
    βœ… Just-in-time access: the gap between concept and operational reality
    βœ… Deployment sovereignty: who controls the keys to the kingdom — SaaS, on-prem, or hybrid?
    βœ… AI and ML in PAM: separating genuine innovation from marketing inflation

    "Most enterprises can tell you the number of employees they have — very few can tell you the number of machine identities." If that sounds familiar, this episode is for you.

    36 min
  • Analyst Chat #301: Know Your Attack Surface - ASM, DRP & Brand Protection

    Not all cyber threats target your systems, some target your reputation, your customers, and your brand. In this episode, Matthias Reinwarth sits down with research analyst Osman Celik to unpack three closely related but distinct markets: Attack Surface Management (ASM), Digital Risk Protection (DRP), and Brand Protection — and help organizations figure out which one they actually need.

    Key Topics:

    βœ… What Attack Surface Management is and its four subcategories (CAASM, EASM, TPRM, DRP)
    βœ… How Digital Risk Protection monitors dark web, social media, and hacker forums
    βœ… What Brand Protection adds on top of DRP — from takedown services to counterfeit detection
    βœ… DRP vs. Brand Protection: lightweight vs. full-spectrum — and when you need which
    βœ… Why brand reach matters more than company size when assessing risk
    βœ… What KuppingerCole research is available now — and what's coming in August

    Someone may be selling counterfeit versions of your product right now — or impersonating your brand online. DRP and Brand Protection tools exist to catch exactly that.

    Check out KuppingerCole's Brand Protection Buyer's Compass here.

    28 min

About KuppingerCole Analysts

From the publisher's feed

KuppingerCole Analysts AG is an international, independent analyst organization offering technology research, neutral advice and events in Identity Management, Cybersecurity and Artificial…