
Sign up to save your podcasts
Or


AI is everywhere, but are we using it the right way? In this Analyst Chat, Matthias Reinwarth speaks with CTO Alexei Balaganski about responsible AI usage, prompt engineering myths, data risks, and building a sustainable AI culture. From hallucinations to zero trust, this episode is your practical guide to using generative AI safely and effectively in business.
Key Topics:
β
AI is mathematics — not intelligence
β
The biggest AI usage mistakes in companies
β
Data leakage & third-party risks
β
Prompt engineering made simple
β
Context limits & hallucinations
β
Building a responsible AI culture
π‘Practice “Zero trust for AI”, skepticism is your strongest security control!
π‘AI can boost productivity, but only if you stay responsible, transparent, and in control.
Identity is no longer just about provisioning and single sign-on. Today’s organizations face fragmented IAM architectures, API sprawl, non-human identity growth, AI agents, and increasing Zero Trust demands. In this episode, Matthew Gardiner speaks with Binod Singh, Founder and Chairman of Cross Identity, about what the Identity Fabric really means and why it has become essential for modern enterprises. They discuss how legacy IAM environments evolved into siloed systems, why integration “tax” is becoming unsustainable, and how a federated, API-driven identity fabric architecture enables scalability, orchestration, and Zero Trust.
You’ll learn:
β
What the Identity Fabric architecture actually is (and what it is not)
β
Why IAM silos and legacy systems create integration and security risks
β
How federated, API-based architectures improve interoperability
β
The rise of non-human identities and AI agents — and how to manage them
β
Why convergence and orchestration are critical for Zero Trust
β
How organizations can transition from fragmented IAM to a fabric model
Whether you are a CISO, IAM architect, or security leader, understanding how to evolve toward an Identity Fabric approach is critical to reducing complexity, enabling Zero Trust, and future-proofing your identity strategy.
Access recertification is one of the most disliked processes in Identity & Access Management, and for good reason.
In this episode, Matthias Reinwarth and Martin Kuppinger challenge the way organizations approach access reviews. Instead of endlessly optimizing broken campaigns, they ask a more fundamental question: What if we eliminated most of recertification altogether?
Key topics:
β
Why traditional access certification campaigns fail
β
How overengineered role models create complexity and “rubber stamping”
β
Why 80–90% of entitlements can be automated via policy
β
How time-limited access dramatically reduces review effort
β
Where AI and usage analytics can safely remove unused permissions
β
Why static entitlements and standing privileges are the real root cause
β
How modern authorization (e.g., externalized policy models) changes the game
The discussion also touches on the 50-year legacy of IBM RACF and why we still haven’t fully embraced externalized authorization — despite knowing better since 1976.
If you struggle with 70-page access review PDFs, role explosion, or endless recertification campaigns, this episode offers practical, implementable guidance — much of it possible with capabilities you already have in place.
Shadow IT has evolved. Now it’s Shadow SaaS. Shadow AI. And it’s everywhere.
In this week's episode of the KuppingerCole Analyst Chat, Matthias welcomes Matthew Gardiner for his first appearance to unpack one of the fastest-growing security domains: SaaS Security Posture Management (SSPM) and why that name may already be too narrow. Today’s organizations run on hundreds of SaaS applications. Many are sanctioned. Many aren’t. Some are connected via OAuth. Others are quietly leaking data through AI tools. And most security teams don’t have full visibility.
In this conversation, we explore:
β
What SSPM actually means (and why the “PM” might be limiting)
β
How Shadow IT evolved into Shadow SaaS and Shadow AI
β
The intersection of identity and cybersecurity in SaaS environments
β
Misconfiguration risks, MFA bypass, OAuth sprawl & SaaS drift
β
Why continuous monitoring beats periodic audits
β
CASB vs SSPM vs CNAPP — where the lines blur
β
The growing governance challenge in AI-powered SaaS
β
Why SaaS security can’t be ignored anymore
If your organization uses SaaS (spoiler: it does), this discussion is not optional.
Decentralized identity is moving from concept to reality, driven by the upcoming EU Digital Identity (EUDI) Wallet! But can digital identity truly become something we trust?
Join us in this Road to EIC episode of the KuppingerCole Analyst Chat where Matthias speaks with Martin Kuppinger about what decentralized identity actually means, how EUDI Wallets work, and why their success depends on real business value. Tune in to learn how verifiable credentials, issuer-holder-verifier models, and privacy-preserving architectures could fundamentally reshape authentication, onboarding, and digital transactions across Europe.
You’ll learn:
β
What decentralized identity and verifiable credentials actually are
β
How the EUDI Wallet changes control over personal data
β
Why trust depends on implementation, not just technology
β
The difference between mandatory use cases and real adoption
β
How businesses can reduce costs and streamline processes
β
Why success requires compelling everyday use scenarios
β
What organizations should do now to prepare
Beyond government interactions, the real potential lies in transforming complex business processes, from onboarding and compliance to loans, contracts, and digital transactions using trusted, reusable identity data. The EUDI Wallet isn’t just a new login method, it’s foundational infrastructure for Europe’s digital economy. Watch now to understand what decentralized identity means for enterprises, citizens, and the future of trust online.
Authorization is changing, moving from static roles and provisioning to dynamic, real-time, policy-based decisions. But without standardization, modern authorization quickly becomes fragmented and unmanageable.
In this episode of the Analyst Chat, Matthias Reinwarth is joined by David Brossard, contributor and co-chair of the OpenID AuthZEN Working Group, and Phillip Messerschmidt, Lead Advisor at KuppingerCole, to discuss how authorization is evolving — and why AuthZEN is a critical missing standard.
You’ll learn:
β
Why RBAC is still relevant, but no longer sufficient on its own
β
How ABAC and PBAC address scalability, context, and dynamic access
β
Why role explosion and authorization silos limit visibility and governance
β
How runtime, continuous authorization supports Zero Trust architectures
β
What AuthZEN standardizes — and what it deliberately does not
β
How externalized authorization improves auditability and compliance
β
Why CISOs and architects should start asking vendors for AuthZEN support
β
How AuthZEN fits into the Identity Fabric and Road to EIC vision
Authentication has been standardized for years — authorization is finally catching up.
Watch now to understand how AuthZEN enables scalable, future-proof authorization for modern applications, APIs, and identity fabrics.
Quantum computing isn’t just a future threat to encryption, it’s a direct risk to identity and authentication. In this week's episode, Matthias is joined by Jonathan Care to explore why identity is the quantum bullseye and what organizations must do now to prepare for a post-quantum world.
You’ll learn:
β
Why authentication protocols depend entirely on cryptography
β
How “harvest now, decrypt later” (HNDL) already puts identity data at risk
β
Why identity, not data encryption, is the weakest point in a quantum future
β
What post-quantum cryptography standards (FIPS 203, 204, 205) change — and what they don’t
β
How Passkeys and FIDO2 are quietly becoming post-quantum ready
β
Why PKI, certificates, federation, and non-human identities face massive scale challenges
β
What crypto agility really means for IAM and Zero Trust
β
A practical 4-phase roadmap for CISOs to start preparing today
The biggest risk isn’t a future quantum computer — it’s the long-lived certificates and identity data issued today.
Zero Trust isn’t dead, it’s evolving. In this week's episode, Matthias Reinwarth joins Alexei Balaganski to explore why Zero Trust Network Access (ZTNA) is no longer enough and how Zero Trust Platforms are emerging as the next evolution of modern security architecture.
In this episode, we explore:
β
Why Zero Trust is a strategy, not a product
β
The limitations of ZTNA in modern hybrid and cloud environments
β
What defines a Zero Trust Platform
β
Universal access enforcement across human and non-human identities
β
Continuous trust evaluation and intelligent segmentation
β
Unified visibility, analytics, and policy enforcement
β
How vendors and organizations should think about Zero Trust moving forward
π If you care about identity, cybersecurity, AI risk, or future-proof security architectures, this conversation is for you.
AM and cybersecurity programs are under increasing pressure — not just from new threats, but from operational complexity, regulation, and organizational reality.
This episode of the KuppingerCole Analyst Chat shifts the focus from analyst predictions to the perspective of end-user organizations and their real-world challenges in IAM and cybersecurity. Matthias Reinwarth speaks with Reiner Mertens and Charlene Spasic, KC Advisors with a focus on identity strategy, governance, and enterprise programs, specializing in IAM transformation and advisory practice. The discussion goes beyond technology to cover organizational aspects such as governance, compliance, processes, and policies, as well as the implications of modern Target Operating Models.
You’ll learn:
β
Why operability is the biggest IAM challenge for many organizations
β
How unclear ownership and overlapping responsibilities undermine IAM success
β
Why IGA modernization is rarely a one-off project — but a long-term program
β
How Privileged Access Management (PAM) is evolving beyond password vaulting
β
The growing importance of non-human identities (NHIs) and automation
β
How regulation (NIS2, DORA) increases urgency — but doesn’t replace good architecture
β
Why data quality, governance, and business alignment are foundational to IAM
Rather than making abstract predictions, this episode focuses on real patterns, structural issues, and practical improvements advisors see across industries. Watch now to understand how IAM, PAM, governance, and identity architecture must evolve in 2026 and beyond.
Cybersecurity and AI are evolving faster than ever, and 2026 is already proving that traditional predictions may no longer be enough. In this year's first episode of the Analyst Chat, Matthias Reinwarth is joined by Jonathan Care and Alexei Balaganski to attempt looking into some predictions for the coming year. Join to find out what organizations should realistically prepare for in cybersecurity and AI in 2026!
You’ll learn:
β
Why traditional cybersecurity predictions are becoming less reliable
β
How geopolitical, economic, and societal shifts are shaping cyber risk
β
Whether cybersecurity can exist without AI — and where AI actually fits
β
Why governance, accountability, and responsibility matter more than tools
β
What’s flying under the radar in AI and cybersecurity today
β
The risks of AI hype, long-lived permissions, and autonomous agents
β
Why agility and resilience should be your cybersecurity mantra for 2026
π This discussion focuses on patterns, risks, and preparation strategies security leaders should consider as AI and cyber threats continue to accelerate.
π Watch now to understand how to think critically about AI, cybersecurity, governance, and resilience in 2026.
From the publisher's feed