KuppingerCole Analysts

KuppingerCole Analysts

By KuppingerCole AnalystsTechnology
Download on the App Store

KuppingerCole Analysts episodes

  • Analyst Chat #300: Shadow Agents and the Next Identity Crisis

    Shadow IT was manageable. Shadow AI was concerning. Shadow agents? That's a whole different problem.

    300 episodes already? Time flies when you're having fun! In this 300th Episode of the KuppingerCole Analyst Chat, Matthias sits down with Distinguished Analyst Martin Kuppinger to unpack one of the most urgent, and underestimated, security challenges facing organizations right now: employees building and deploying their own AI agents, with no governance, no oversight, and no accountability.

    Key topics:

    βœ… What "shadow agents" are and why they're fundamentally different from shadow IT or shadow AI
    βœ… Why vibe coding means anyone, not just developers, can now deploy autonomous agents inside your systems
    βœ… How AI agents massively expand the attack surface through prompt injection, data exfiltration, and uncontrolled access
    βœ… Why discovery and resource-side controls must happen in parallel and why neither alone is enough
    βœ… What organizations can actually do to gain control without just shutting everything down

    The bottom line: there's a thin line between agents that help your business and agents that harm it. Right now, most organizations can't tell the difference.

    15 min
  • Analyst Chat #299: AI Security Fabric - Identity, Governance & Authorization for Autonomous Agents

    AI is reshaping enterprise architectures, but is security keeping pace? In this episode, Martin Kuppinger, Matthias Reinwarth, and Darran Rolls talk about the urgent question of how organizations should structure their defenses for a world of autonomous, agentic AI. The answer: an AI Security Fabric.

    Key Topics:

    βœ… Why agentic AI breaks traditional, deterministic access models
    βœ… The concept of "AIdentity" — what makes AI agent identity fundamentally different
    βœ… Can the Identity Fabric scale to meet AI security demands?
    βœ… Discovery, authorization, and governance as the pillars of an AI Security Fabric
    βœ… The geopolitical divide: US "move fast" vs. EU "govern first"
    βœ… Token delegation as the hardest unsolved problem in AI security today

    "We didn't build IAM for a world where the actor, the path, and the destination are all unknown until the moment of access" so what do we build instead? Find out in this episode.

    πŸŽ™οΈ Catch Martin, Matthias, and Darran at the European Identity & Cloud Conference (EIC) in Berlin this May and get a head start on the conversation right here.

    57 min
  • Analyst Chat #298: Why AI Is Becoming Foundational to Cybersecurity

    Security teams have spent decades building deterministic, rule-based defenses. But the threat landscape has changed and AI is no longer just a feature add-on. In this episode of Analyst Chat, Matthias sits down with Matthew Gardiner to unpack his latest advisory note and Leadership Compass on AI SOC, exploring why probabilistic AI is becoming a core pillar of modern cybersecurity.

    Key topics:

    βœ… Why deterministic security has run its course — and what comes next
    βœ… The "two-sided coin" model: rules-based vs. probabilistic AI approaches
    βœ… Where AI genuinely outperforms traditional methods (and where it doesn't)
    βœ… Risks, hallucinations, and how to build trust in AI-driven security systems
    βœ… The AI SOC in practice: triage, agents, and phased adoption
    βœ… Market outlook: pricing shifts, platform vs. startup dynamics, and data sovereignty

    AI isn't replacing the security rulebook — it's completing the other half of it. Catch Matthew Gardiner live at EIC Berlin in May, and explore his advisory note and AI SOC Leadership Compass.

    33 min
  • Analyst Chat #297: AIdentity and the Limits of IAM

    AI agents don't just use identities. they create, delegate, and impersonate them. In this episode of Analyst Chat, Matthias Reinwarth sits down with KuppingerCole's founder Martin Kuppinger to dig into AIdentity (the concept at the intersection of AI and identity management) and why the IAM tools we've relied on for decades are no longer enough.

    Key topics:

    βœ… What AIdentity means and why it's more urgent than ever
    βœ… Why AI agents can't be treated like standard non-human identities
    βœ… The identity relationship challenge — from simple access to complex agent meshes
    βœ… Why "human in the loop" is mostly a misconception
    βœ… The role of verifiable credentials and decentralised identity in securing agents
    βœ… Where security and identity leaders should start today

    πŸ’‘ Traditional IAM was built for humans. Agentic AI plays by entirely different rules.

    21 min
  • Analyst Chat #296: Aldentity - Treating Al Agents as First-Class Identities

    AI agents aren't just software, they're a new class of actor that can impersonate users, bypass security policies, and operate across complex identity meshes. In this episode of Analyst Chat, Matthias Reinwarth sits down with Martin Kuppinger and KuppingerCole's newly appointed AI Security Practice Lead Jonathan Care to unpack the emerging concept of AIdentity and why it's the key to securing agentic AI.

    Key topics:

    βœ… What "AI Identity" means and why it's more than just a service account
    βœ… The dangers of agent impersonation and the "ClaudeBot dumpster fire"
    βœ… Authorization collapse, what happens when agents bypass security policies
    βœ… The limits of "human in the loop" as a security strategy
    βœ… Two new market categories: AVOP and ATDR
    βœ… Immediate actions CISOs and architects can take today

    AI is already in your organization, the question is whether you can see it. Stay tuned for upcoming KuppingerCole research on AVOP and ATDR, and catch Martin, Jonathan, and Matthias live at EIC Berlin in May.

    39 min
  • Analyst Chat #295: Independent ROI - A New Model for Cybersecurity Investment

    What does an enterprise technology product actually deliver — in hard numbers? In this episode, Matthias Reinwarth sits down with Jonathan Care, KuppingerCole Analysts' newly appointed AI Practice Lead, for a behind-the-scenes look at a brand new research format: the Product Value Navigator (PVN).

    Key Topics:

    βœ… Why enterprise tech buying is broken — and what's missing from analyst rankings
    βœ… What the Product Value Navigator is and how it works
    βœ… How KuppingerCole independently validates ROI through real customer interviews and financial modeling
    βœ… Who the PVN is built for: CISOs, IT leaders, procurement teams, and vendors
    βœ… The first published PVN: ManageEngine PAM360 — 219% independently validated ROI
    βœ… What's next on the PVN roadmap: flexible modeling tools and competitive analysis

    In a world flooded with vendor-funded research and AI-generated content, truly independent economic validation has never been more valuable, or more necessary.

    16 min
  • Analyst Chat #294: Secure Remote Access as the Control Layer for OT Security

    As OT systems go online, controlling access becomes more critical than enabling it.

    In this episode of the Analyst Chat, KuppingerCole analysts Matthias Reinwarth and Warwick Ashford dive into one of cybersecurity’s most overlooked domains: OT (Operational Technology) security. As industrial systems become increasingly connected, the traditional boundaries between IT and OT are dissolving, bringing new risks and new security imperatives.

    Key Topics

    βœ… The rise of Secure Remote Access (SRA) in OT environments
    βœ… Why VPN-based access falls short for industrial systems
    βœ… Zero Trust and identity as the new security control plane
    βœ… Regulatory drivers (e.g., NIS2) and auditability requirements
    βœ… Convergence of PAM, SRA, and third-party access governance
    βœ… The growing role of non-human identities in Industry 4.0

    Identity is no longer just part of security, it is the control plane for modern cybersecurity.

    25 min
  • Analyst Chat #293: CIAM is Evolving - Scale, AI Agents, and Identity Challenges

    In today's episode of the Analyst Chat, Matthias Reinwarth welcomes John Tolbert to take a deep dive into the rapidly evolving world of Consumer Identity and Access Management (CIAM). As organizations manage millions, or even billions, of identities, CIAM is shifting from a standalone capability to a core component of broader digital ecosystems.

    Key topics:

    βœ… Consumer vs. B2B IAM segmentation
    βœ… Passkeys adoption and UX gaps
    βœ… Identity lifecycle and account recovery
    βœ… CIAM integrations and platform ecosystems
    βœ… AI agents and identity governance

    Increasing scale, regulatory pressure, and user expectations are reshaping CIAM requirements. AI agents begin to act on behalf of users, introducing new risks, but also new opportunities for automation and innovation.

    18 min
  • Analyst Chat #292: The Collapse of Trust - Deepfakes, Disinformation & Enterprise Security

    In the age of AI-generated content, the real challenge isn’t just detecting falsehood, it’s knowing what to trust at all. As deepfakes and disinformation scale, perception itself becomes a new attack surface.

    This week, Matthias Reinwarth and Jonathan Care explore how misinformation and disinformation are reshaping cybersecurity and enterprise risk. They clarify the difference between the two, examine how AI is accelerating the creation of deceptive content, and discuss why traditional trust models are breaking down.

    Key Topics

    βœ… Misinformation vs. disinformation: definitions and impact
    βœ… Deepfakes, voice cloning, and synthetic identity risks
    βœ… The “liar’s dividend” and erosion of trust
    βœ… Emotional manipulation vs. factual accuracy
    βœ… Enterprise attack vectors and real-world fraud cases
    βœ… Pre-bunking, awareness training, and process-based defenses

    AI has industrialized deception: are your security controls keeping up? In a world of perfect fakes, trust is no longer a given, it’s a security problem.

    43 min
  • Analyst Chat #291: The Emerging AI SOC Market Explained

    The future SOC won’t replace humans with AI, it will empower us with AI-driven automation, accelerating detection and response while keeping humans in control of critical decisions.

    This week Matthias Reinwarth and Matthew Gardiner discuss the evolution of security automation with the introduction of AI SOC (Security Operations Center). They explore the challenges of alert fatigue, the importance of human oversight, and the cautious optimism surrounding AI's role in cybersecurity. The conversation delves into the balance between automation and human intervention, the trust issues associated with AI systems, and the current landscape of vendors in the AI SOC market. They conclude with insights on the future of AI in security and the potential impact on managed detection and response services.

    Key Topics:
    βœ… Evolution from SOAR to AI-powered SOC
    βœ… Using AI agents as junior security analysts
    βœ… Managing alert fatigue and SOC analyst burnout
    βœ… Balancing automation with human oversight
    βœ… Explainability and trust in AI security systems
    βœ… Impact of AI SOC on MDR and security service providers

    AI is reshaping SOC operations—but fully autonomous security is still far away. Discover why AI agents may become the “junior analysts” of the modern SOC, handling repetitive tasks while humans focus on complex decisions.

    28 min

About KuppingerCole Analysts

From the publisher's feed

KuppingerCole Analysts AG is an international, independent analyst organization offering technology research, neutral advice and events in Identity Management, Cybersecurity and Artificial…