
Sign up to save your podcasts
Or


Zero trust has a label problem. After more than a decade, the term has been stretched, diluted, and attached to products that don't come close to delivering what zero trust actually promises. In this episode, Matthias sits down with Alexei Balaganski, lead analyst at KuppingerCole Analysts, to share the findings from six months of research and reveal which vendors actually built a real Zero Trust Platform.
Key Topics:
β
Why zero trust is a strategy, not a product — and what that means for procurement
β
The four non-negotiable requirements for a real Zero Trust Platform
β
What separates a genuine platform from a collection of tools with a zero trust label
β
NHIs, AI agents, and data protection as the new frontiers of zero trust architecture
β
Three critical questions every RFP for a ZTP should include
π "Stop looking for a Zero Trust Platform" - yes, really. Alexei Balaganski explains why that mindset shift is the most important thing a CISO can do before opening a single RFP.
π The KuppingerCole Analysts Zero Trust Platform Buyers Compass and Leadership Compass are both published: watch this episode first, then dive into the research.
Seven years ago, KuppingerCole Analysts introduced the Identity Fabric concept and it has shaped how organizations structure identity management ever since. In this episode, Matthias sits down with Martin Kuppinger, co-founder and distinguished analyst at KuppingerCole Analysts, to revisit the origins of the Fabric paradigm, explain why it still holds today, and preview where it's headed next into cybersecurity, AI security, and beyond.
Key Topics:
β
Why the Identity Fabric concept emerged in 2019 — tool sprawl, siloed IAM, and the collapse of the perimeter
β
What "fabric" actually means: a capability-driven layer connecting all identities to all services
β
Why capabilities should define tools — not the other way around
β
How the fabric concept scales to cybersecurity and AI security architectures
β
The fabric in practice: maturity assessments, requirements analysis, and target operating models
β
A look ahead to 2040: why the core principles are built to last
"The job of identity management is to provide seamless access for everyone and everything to every service" — seven years on, that definition still holds. Find out why in this episode.
π This is the first episode of a new series on the fabric paradigm, covering Identity Fabric, Cybersecurity Fabric, and AI Security Fabric.
Build or buy, it sounds like a simple question, but for most organizations, it's one of the most consequential and poorly structured decisions they make. In this episode, Matthias sits down with analyst and advisor Phillip Messerschmidt, who turned his hands-on advisory experience into a structured framework for getting the make-or-buy decision right every time.
Key Topics:
β
Why "we can build it cheaper" is almost always a biased and incomplete argument
β
How the originating perspective (business unit, IT, security) shapes — and distorts — the decision
β
The most common and costly mistakes organizations make when going the build route
β
When buying is clearly the better path: expertise gaps, speed, scalability, and vendor roadmaps
β
Why security and risk must be part of the decision from day one — not an afterthought
β
A structured, holistic framework for making the right make-or-buy call
"This cheap solution can quickly turn into a security risk, an open attack, a breach — and much more cost than thinking about risk by design." Sound familiar? This episode is for you.
Alert overload, 24/7 coverage gaps, and human threat actors who never stop — the SOC has problems that traditional SOAR and rule-based systems simply can't solve. In this sponsored videocast, KuppingerCole analyst Matthew Gardiner and Rick Bosworth, Head of Product Marketing at Torq, dig into the findings of KuppingerCole's Emerging AI SOC Leadership Compass and explore what it actually takes to build an AI-powered security operations center.
Key Topics:
β
Why rule-based SOAR has hit a wall — and how AI agents address what it can't
β
The autonomy dial: why full automation isn't the goal and how to build trust incrementally
β
Integrations, RAG, and MCP: the new data infrastructure powering AI agents in the SOC
β
DIY SOC vs. managed providers: how agentic AI is reshuffling the build-vs-buy decision
β
Where to start: alert triage, phishing, and typosquatting as low-risk entry points
β
Guardrails, transparency, and the non-deterministic challenge of AI-driven security
"AI agents hate people because they're slow" — but full autonomy isn't the answer either. Find out how leading SOC teams are finding the right balance between speed and control.
This videocast is sponsored by Torq — featured in KuppingerCole's Emerging AI SOC Leadership Compass. Read the report, then watch this session to hear the findings brought to life.
IGA is often dismissed as a mature, stable market but that couldn't be further from the truth. In this episode, Matthias sits down with Nitish Deshpande, to explore how identity governance and administration is being reshaped by NHIs, AI-driven intelligence, deployment sovereignty, and a wave of challenger vendors.
Key Topics:
β
How IGA has evolved from static, siloed tools to integrated, multi-identity platforms
β
Non-human identities: IGA vendors are now covering NHI governance — and customers are demanding it
β
Where IGA still falls short: role mining, anomaly detection, policy simulation, and workflow automation
β
The deployment model debate: SaaS vs. on-premise vs. hybrid — and the feature parity problem
β
EU sovereignty as a competitive differentiator for European IGA vendors
β
What's coming next: real-time governance, access intelligence, and a new IGA report category
44 vendors evaluated, a surge of newcomers, and a market quietly reinventing itself — the KuppingerCole IGA Leadership Compass is out now and covers everything discussed in this episode.
Four weeks after EIC 2026 in Berlin, Matthias Reinwarth and Phillip Messerschmidt sit down to reflect on what the European Identity and Cloud Conference revealed about the state of identity and access management and what it means for the year ahead. Spoiler: agentic AI dominated, but it wasn't the only story.
Key Topics:
β
Agentic AI as a new class of insider threat — autonomous, non-deterministic, and without ethics
β
Data-centric defense vs. agent discovery: protect the vault, not the crowd
β
Why dynamic authorization and behavior analytics are the IAM industry's urgent next step
β
Data sovereignty and geopolitics: eroding trust in non-European SaaS vendors
β
AuthZEN wins the EIC Award — a standard built before anyone knew the problem it would solve
β
Martin Kuppinger's closing keynote: "Everything we failed to solve in the past decades bites back now"
"An agent behaves like a human insider threat — but without any sense of right or wrong." If your IAM program isn't ready for that, this episode is required listening.
Business relationships are complex and traditional IAM wasn't built for them. In this episode, Matthias Reinwarth sits down with Principal analyst John Tolbert, author of KuppingerCole Analysts' first-ever B2B IAM Leadership Compass, to explore why Business-to-Business Identity and Access Management is emerging as its own distinct market and what it takes to get it right.
Key Topics:
β
Why B2B IAM sits between workforce IAM and CIAM — and why neither alone is sufficient
β
Delegated administration: handing identity governance to partner and supplier organizations
β
Federation, lifecycle management, and the risks of trusting external HR processes
β
"Know Your Business" — vetting organizations, sanctions screening, and org-level trust
β
Fine-grained authorization: why RBAC falls short and ABAC/RBAC are taking over
β
Agentic AI in B2B IAM: agents acting on behalf of external organizations
Supply chains with thousands of partner organizations, freelancers with hour-long access windows, and AI agents acting on behalf of external companies B2B IAM has to handle all of it. KuppingerCole Analysts' first B2B IAM Leadership Compass is out now read it alongside this episode to get the full picture of an emerging market you can't afford to ignore.
Speed and security are no longer separate concerns. In this videocast, Osman Celik sits down with Andrey Leskin, CTO of Qrator Labs, to break down what Content Delivery Networks really are in 2026 and why they've become a critical piece of modern security infrastructure, not just a performance tool.
Key Topics:
β
What CDNs are and why they're no longer optional for competitive organizations
β
How CDN and DDoS mitigation differ — and where they overlap
β
Cache busting, HTTP floods, Slowloris and other real-world attack vectors
β
Why "security-first CDN" is fundamentally different from "CDN with security bolted on"
β
What CISOs and infrastructure leaders should look for when evaluating CDN solutions
β
How to measure CDN value from day one: round trip time and time to render
A CDN without security is just a bigger target — find out why building security in from the ground up changes everything.
Privileged Access Management has outgrown the vault. In this episode, Matthias sits down with lead analyst Alejandro Leal, author of KuppingerCole's newly released PAM Leadership Compass, to explore how the definition of privilege itself has changed, what NHIs and agentic AI mean for PAM, and why deployment sovereignty is now a boardroom conversation.
Key Topics:
β
How the definition of "privilege" has shifted from admin accounts to dynamic runtime identity capabilities
β
PAM convergence with IGA, CIEM, ITDR, SIEM, and SOAR — the end of the standalone PAM product
β
Non-Human Identities (NHIs) and agentic AI: the silent accumulation of machine privilege
β
Just-in-time access: the gap between concept and operational reality
β
Deployment sovereignty: who controls the keys to the kingdom — SaaS, on-prem, or hybrid?
β
AI and ML in PAM: separating genuine innovation from marketing inflation
"Most enterprises can tell you the number of employees they have — very few can tell you the number of machine identities." If that sounds familiar, this episode is for you.
Not all cyber threats target your systems, some target your reputation, your customers, and your brand. In this episode, Matthias Reinwarth sits down with research analyst Osman Celik to unpack three closely related but distinct markets: Attack Surface Management (ASM), Digital Risk Protection (DRP), and Brand Protection — and help organizations figure out which one they actually need.
Key Topics:
β
What Attack Surface Management is and its four subcategories (CAASM, EASM, TPRM, DRP)
β
How Digital Risk Protection monitors dark web, social media, and hacker forums
β
What Brand Protection adds on top of DRP — from takedown services to counterfeit detection
β
DRP vs. Brand Protection: lightweight vs. full-spectrum — and when you need which
β
Why brand reach matters more than company size when assessing risk
β
What KuppingerCole research is available now — and what's coming in August
Someone may be selling counterfeit versions of your product right now — or impersonating your brand online. DRP and Brand Protection tools exist to catch exactly that.
Check out KuppingerCole's Brand Protection Buyer's Compass here.
From the publisher's feed