KuppingerCole Analysts

KuppingerCole Analysts

By KuppingerCole AnalystsTechnology
Download on the App Store

KuppingerCole Analysts episodes

  • Analyst Chat #290: How to Work Smarter with Generative AI - Do’s, Don’ts, and Real-World Tips

    AI is everywhere, but are we using it the right way? In this Analyst Chat, Matthias Reinwarth speaks with CTO Alexei Balaganski about responsible AI usage, prompt engineering myths, data risks, and building a sustainable AI culture. From hallucinations to zero trust, this episode is your practical guide to using generative AI safely and effectively in business.

    Key Topics:
    βœ… AI is mathematics — not intelligence
    βœ… The biggest AI usage mistakes in companies
    βœ… Data leakage & third-party risks
    βœ… Prompt engineering made simple
    βœ… Context limits & hallucinations
    βœ… Building a responsible AI culture

    πŸ’‘Practice “Zero trust for AI”, skepticism is your strongest security control!
    πŸ’‘AI can boost productivity, but only if you stay responsible, transparent, and in control.

    39 min
  • Identity Fabric Explained: From Legacy IAM to Zero Trust with Cross Identity

    Identity is no longer just about provisioning and single sign-on. Today’s organizations face fragmented IAM architectures, API sprawl, non-human identity growth, AI agents, and increasing Zero Trust demands. In this episode, Matthew Gardiner speaks with Binod Singh, Founder and Chairman of Cross Identity, about what the Identity Fabric really means and why it has become essential for modern enterprises. They discuss how legacy IAM environments evolved into siloed systems, why integration “tax” is becoming unsustainable, and how a federated, API-driven identity fabric architecture enables scalability, orchestration, and Zero Trust.

    You’ll learn:
    βœ… What the Identity Fabric architecture actually is (and what it is not)
    βœ… Why IAM silos and legacy systems create integration and security risks
    βœ… How federated, API-based architectures improve interoperability
    βœ… The rise of non-human identities and AI agents — and how to manage them
    βœ… Why convergence and orchestration are critical for Zero Trust
    βœ… How organizations can transition from fragmented IAM to a fabric model

    Whether you are a CISO, IAM architect, or security leader, understanding how to evolve toward an Identity Fabric approach is critical to reducing complexity, enabling Zero Trust, and future-proofing your identity strategy.

    30 min
  • Analyst Chat #289: From 100 to Zero - Fixing Access Recertification the Right Way

    Access recertification is one of the most disliked processes in Identity & Access Management, and for good reason.

    In this episode, Matthias Reinwarth and Martin Kuppinger challenge the way organizations approach access reviews. Instead of endlessly optimizing broken campaigns, they ask a more fundamental question: What if we eliminated most of recertification altogether?

    Key topics:
    βœ… Why traditional access certification campaigns fail
    βœ… How overengineered role models create complexity and “rubber stamping”
    βœ… Why 80–90% of entitlements can be automated via policy
    βœ… How time-limited access dramatically reduces review effort
    βœ… Where AI and usage analytics can safely remove unused permissions
    βœ… Why static entitlements and standing privileges are the real root cause
    βœ… How modern authorization (e.g., externalized policy models) changes the game

    The discussion also touches on the 50-year legacy of IBM RACF and why we still haven’t fully embraced externalized authorization — despite knowing better since 1976.

    If you struggle with 70-page access review PDFs, role explosion, or endless recertification campaigns, this episode offers practical, implementable guidance — much of it possible with capabilities you already have in place.

    24 min
  • Analyst Chat #288: From Shadow SaaS to Shadow AI - Closing the Unowned Security Gap

    Shadow IT has evolved. Now it’s Shadow SaaS. Shadow AI. And it’s everywhere.

    In this week's episode of the KuppingerCole Analyst Chat, Matthias welcomes Matthew Gardiner for his first appearance to unpack one of the fastest-growing security domains: SaaS Security Posture Management (SSPM) and why that name may already be too narrow. Today’s organizations run on hundreds of SaaS applications. Many are sanctioned. Many aren’t. Some are connected via OAuth. Others are quietly leaking data through AI tools. And most security teams don’t have full visibility.

    In this conversation, we explore:
    βœ… What SSPM actually means (and why the “PM” might be limiting)
    βœ… How Shadow IT evolved into Shadow SaaS and Shadow AI
    βœ… The intersection of identity and cybersecurity in SaaS environments
    βœ… Misconfiguration risks, MFA bypass, OAuth sprawl & SaaS drift
    βœ… Why continuous monitoring beats periodic audits
    βœ… CASB vs SSPM vs CNAPP — where the lines blur
    βœ… The growing governance challenge in AI-powered SaaS
    βœ… Why SaaS security can’t be ignored anymore

    If your organization uses SaaS (spoiler: it does), this discussion is not optional.

    32 min
  • Analyst Chat #287: EUDI Wallet - Can Digital ID Finally Be Trusted?

    Decentralized identity is moving from concept to reality, driven by the upcoming EU Digital Identity (EUDI) Wallet! But can digital identity truly become something we trust?

    Join us in this Road to EIC episode of the KuppingerCole Analyst Chat where Matthias speaks with Martin Kuppinger about what decentralized identity actually means, how EUDI Wallets work, and why their success depends on real business value. Tune in to learn how verifiable credentials, issuer-holder-verifier models, and privacy-preserving architectures could fundamentally reshape authentication, onboarding, and digital transactions across Europe.

    You’ll learn:
    βœ… What decentralized identity and verifiable credentials actually are
    βœ… How the EUDI Wallet changes control over personal data
    βœ… Why trust depends on implementation, not just technology
    βœ… The difference between mandatory use cases and real adoption
    βœ… How businesses can reduce costs and streamline processes
    βœ… Why success requires compelling everyday use scenarios
    βœ… What organizations should do now to prepare

    Beyond government interactions, the real potential lies in transforming complex business processes, from onboarding and compliance to loans, contracts, and digital transactions using trusted, reusable identity data. The EUDI Wallet isn’t just a new login method, it’s foundational infrastructure for Europe’s digital economy. Watch now to understand what decentralized identity means for enterprises, citizens, and the future of trust online.

    29 min
  • Analyst Chat #286: Modern Authorization Architectures & AuthZEN

    Authorization is changing, moving from static roles and provisioning to dynamic, real-time, policy-based decisions. But without standardization, modern authorization quickly becomes fragmented and unmanageable.

    In this episode of the Analyst Chat, Matthias Reinwarth is joined by David Brossard, contributor and co-chair of the OpenID AuthZEN Working Group, and Phillip Messerschmidt, Lead Advisor at KuppingerCole, to discuss how authorization is evolving — and why AuthZEN is a critical missing standard.

    You’ll learn:
    βœ… Why RBAC is still relevant, but no longer sufficient on its own
    βœ… How ABAC and PBAC address scalability, context, and dynamic access
    βœ… Why role explosion and authorization silos limit visibility and governance
    βœ… How runtime, continuous authorization supports Zero Trust architectures
    βœ… What AuthZEN standardizes — and what it deliberately does not
    βœ… How externalized authorization improves auditability and compliance
    βœ… Why CISOs and architects should start asking vendors for AuthZEN support
    βœ… How AuthZEN fits into the Identity Fabric and Road to EIC vision

    Authentication has been standardized for years — authorization is finally catching up.

    Watch now to understand how AuthZEN enables scalable, future-proof authorization for modern applications, APIs, and identity fabrics.

    43 min
  • Analyst Chat #285: Future-Proofing Authentication in a Post-Quantum World

    Quantum computing isn’t just a future threat to encryption, it’s a direct risk to identity and authentication. In this week's episode, Matthias is joined by Jonathan Care to explore why identity is the quantum bullseye and what organizations must do now to prepare for a post-quantum world.

    You’ll learn:

    βœ… Why authentication protocols depend entirely on cryptography
    βœ… How “harvest now, decrypt later” (HNDL) already puts identity data at risk
    βœ… Why identity, not data encryption, is the weakest point in a quantum future
    βœ… What post-quantum cryptography standards (FIPS 203, 204, 205) change — and what they don’t
    βœ… How Passkeys and FIDO2 are quietly becoming post-quantum ready
    βœ… Why PKI, certificates, federation, and non-human identities face massive scale challenges
    βœ… What crypto agility really means for IAM and Zero Trust
    βœ… A practical 4-phase roadmap for CISOs to start preparing today

     The biggest risk isn’t a future quantum computer — it’s the long-lived certificates and identity data issued today.

    34 min
  • Analyst Chat #284: Beyond ZTNA, the Rise of Zero Trust Platforms

    Zero Trust isn’t dead, it’s evolving. In this week's episode, Matthias Reinwarth joins Alexei Balaganski to explore why Zero Trust Network Access (ZTNA) is no longer enough and how Zero Trust Platforms are emerging as the next evolution of modern security architecture.

    In this episode, we explore:

    βœ… Why Zero Trust is a strategy, not a product
    βœ… The limitations of ZTNA in modern hybrid and cloud environments
    βœ… What defines a Zero Trust Platform
    βœ… Universal access enforcement across human and non-human identities
    βœ… Continuous trust evaluation and intelligent segmentation
    βœ… Unified visibility, analytics, and policy enforcement
    βœ… How vendors and organizations should think about Zero Trust moving forward

    πŸš€ If you care about identity, cybersecurity, AI risk, or future-proof security architectures, this conversation is for you.

    25 min
  • Analyst Chat #283: Advisory Insights for 2026 - IAM Modernization, PAM & Governance

    AM and cybersecurity programs are under increasing pressure — not just from new threats, but from operational complexity, regulation, and organizational reality.

    This episode of the KuppingerCole Analyst Chat shifts the focus from analyst predictions to the perspective of end-user organizations and their real-world challenges in IAM and cybersecurity. Matthias Reinwarth speaks with Reiner Mertens and Charlene Spasic, KC Advisors with a focus on identity strategy, governance, and enterprise programs, specializing in IAM transformation and advisory practice. The discussion goes beyond technology to cover organizational aspects such as governance, compliance, processes, and policies, as well as the implications of modern Target Operating Models.

    You’ll learn:
    βœ… Why operability is the biggest IAM challenge for many organizations
    βœ… How unclear ownership and overlapping responsibilities undermine IAM success
    βœ… Why IGA modernization is rarely a one-off project — but a long-term program
    βœ… How Privileged Access Management (PAM) is evolving beyond password vaulting
    βœ… The growing importance of non-human identities (NHIs) and automation
    βœ… How regulation (NIS2, DORA) increases urgency — but doesn’t replace good architecture
    βœ… Why data quality, governance, and business alignment are foundational to IAM

    Rather than making abstract predictions, this episode focuses on real patterns, structural issues, and practical improvements advisors see across industries. Watch now to understand how IAM, PAM, governance, and identity architecture must evolve in 2026 and beyond.

    35 min
  • Analyst Chat #282: Cybersecurity & AI Predictions for 2026

    Cybersecurity and AI are evolving faster than ever, and 2026 is already proving that traditional predictions may no longer be enough. In this year's first episode of the Analyst Chat, Matthias Reinwarth is joined by Jonathan Care and Alexei Balaganski to attempt looking into some predictions for the coming year. Join to find out what organizations should realistically prepare for in cybersecurity and AI in 2026!

    You’ll learn:
    βœ… Why traditional cybersecurity predictions are becoming less reliable
    βœ… How geopolitical, economic, and societal shifts are shaping cyber risk
    βœ… Whether cybersecurity can exist without AI — and where AI actually fits
    βœ… Why governance, accountability, and responsibility matter more than tools
    βœ… What’s flying under the radar in AI and cybersecurity today
    βœ… The risks of AI hype, long-lived permissions, and autonomous agents
    βœ… Why agility and resilience should be your cybersecurity mantra for 2026

    πŸ“Œ This discussion focuses on patterns, risks, and preparation strategies security leaders should consider as AI and cyber threats continue to accelerate.
    πŸ”’ Watch now to understand how to think critically about AI, cybersecurity, governance, and resilience in 2026.

    30 min

About KuppingerCole Analysts

From the publisher's feed

KuppingerCole Analysts AG is an international, independent analyst organization offering technology research, neutral advice and events in Identity Management, Cybersecurity and Artificial…