KuppingerCole Analysts

KuppingerCole Analysts

By KuppingerCole AnalystsTechnology
Download on the App Store

KuppingerCole Analysts episodes

  • Platform Dependence and the Growing Fragility of the Internet

    Every so often, the digital world gets a reminder that “The Cloud” is not a magical, omnipresent entity but just another complex socio-technical system operated by humans. Electricity usually comes from the socket, networks usually work, and cloud services are marketed as being always on… Until they are not. Recent outages expose inherent vulnerabilities, threatening global digital infrastructure. Learn why resilience and diversification are critical.

    Read the original blog post here: https://www.kuppingercole.com/blog/balaganski/platform-dependence-growing-fragility

    10 min
  • Mastering Web Scraping Defense with Qrator Labs: AI-Driven Threats & Modern Mitigation

    Web scraping has entered a new era and AI is changing everything.

    In this videocast, Osman Celik speaks with Dmitriy Loshakov from QRator Labs to explore how automated data collection has evolved from simple crawling into highly adaptive, human-like scraping attacks that operate invisibly.

    You’ll learn:

    βœ… What web scraping actually is (and why not all scraping is malicious)
    βœ… How AI-powered scrapers mimic real user behavior with mouse movements, delays & clicks
    βœ… Why classic defenses like CAPTCHAs and JS challenges no longer stop modern bots
    βœ… The industries hit hardest — from e-commerce and travel to betting, finance, and media
    βœ… How organizations can defend themselves using behavioral analysis & intent detection
    βœ… Why the future of cybersecurity is officially AI vs. AI

    πŸ“‰ With intelligent scrapers bypassing most legacy defenses and blending in with real users, organizations must rethink how they detect and mitigate automated threats.

    πŸ”’ Watch now to understand how to protect your data, your users, and your business from today’s invisible AI-driven bots.

    24 min
  • Analyst Chat #281: Cloudflare Incident - What It Teaches About Systemic Risk & Digital Resilience

    What happens when a single platform outage impacts half the internet? This week, Matthias Reinwarth is joined by Martin Kuppinger and Alexei Balaganski to analyze the recent Cloudflare disruption and what it means for modern digital infrastructure.

    πŸ”‘ Key Topics Covered:

    βœ… What happened during the Cloudflare outage and why it was so disruptive
    βœ… How platformization and consolidation increased systemic risk
    βœ… The shift from decentralized internet ideals to dependency on global platforms
    βœ… Lock-in challenges: hyperscalers, CDNs, and cloud services
    βœ… Understanding the hidden risks of convenience and integration
    βœ… Why organizations neglect risk management and how to correct it
    βœ… Business impact analysis: mapping critical services and dependencies
    βœ… How to architect for resilience, failover, and exit strategies

    πŸ’‘ Your Next Step: Evaluate your digital supply chain, map your dependencies, and identify where platform concentration creates unacceptable business risk. Small architectural decisions today can dramatically reduce the impact of tomorrow’s outages.

    31 min
  • Analyst Chat #280: What you can expect for IAM in 2026 and Beyond

    What will Identity and Access Management (IAM) look like in 2026? In this episode of the KuppingerCole Analyst Chat, Matthias Reinwarth, Jonathan Care, and Martin Kuppinger discuss the key trends, challenges, and innovations shaping the future of IAM.

    Key Topics Covered:

    βœ… Emerging IAM threats: AI agents with broad system access
    βœ… Managing the IAM tool zoo and avoiding integration chaos
    βœ… Identity Fabric: building a flexible, future-proof IAM architecture
    βœ… Continuous and passwordless authentication: improving security and user experience
    βœ… Automation and orchestration: reducing human intervention in IAM processes
    βœ… Shared signals, data-driven decisions, and overcoming alert fatigue
    βœ… Preparing for non-human and agentic AI identities

    πŸ’‘ Stay ahead in IAM by evaluating your organization’s readiness for AI-driven identities, passwordless authentication, and automated governance. Use these insights to plan your 2026 IAM strategy and ensure your tools, processes, and policies are prepared for the next wave of innovation.

    34 min
  • Mastering WAAP with Qrator Labs: Defending Against Bots, Attacks & DDoS

    Web application threats are evolving — and modern WAAP solutions must do far more than traditional WAFs ever could.

    In this video, Osman Celik speaks again with Andrey Leskin from QRator Labs to explore the capabilities organizations need to protect their web applications, APIs, and users from today’s most advanced threats.

    You’ll learn:

    βœ… The three core threat vectors: DDoS attacks, web application attacks, and malicious bots
    βœ… Why traditional WAFs are no longer enough to protect modern applications
    βœ… How WAAP solutions combine WAF, bot mitigation, API protection, and DDoS defense
    βœ… How attackers use low-and-slow techniques, scraping, and AI-driven bots to mimic real users
    βœ… Why half of all internet traffic is bots — and how to distinguish good bots from malicious ones
    βœ… How QRator Labs unifies Anti-DDoS, WAF, and Anti-Bot into a single platform and single point of truth

    πŸ“ˆ With automated attacks, scraping, and bot-driven abuse increasing across every industry, organizations need a holistic approach to defending their web applications.

    πŸ”’ Watch now to learn how WAAP, WAF, Anti-Bot, and DDoS mitigation come together in one platform to protect your business.

    17 min
  • Analyst Chat #279: Apple Wallet Digital IDs - Why This Is Progress, Not a Breakthrough

    Is Apple's Digital ID Wallet truly a game changer, or are we missing the bigger picture? In this episode of the KuppingerCole Analyst Chat, Matthias Reinwarth and Martin Kuppinger talk about Apple's announcement of digital IDs in Apple Wallet and what it means for the future of digital identity.

    πŸ”‘ Key Topics Covered:

    • Apple's Digital ID implementation in selected US states
    • The fundamental difference between ID cards and verifiable credentials
    • Why current wallet solutions fall short of their potential
    • Real-world use cases: employee onboarding and bank loan automation
    • The device-bound limitation problem
    • Standards and interoperability (mDoc, ISO, FIDO)
    • How enterprises should prepare for multiple wallet ecosystems
    • Comparison with EUDI Wallet and other digital identity initiatives

    πŸ’‘ Expert Insights: Martin Kuppinger explains why the real value of digital identity wallets lies far beyond simple ID verification, exploring complex scenarios involving hundreds or thousands of verifiable credentials for business process automation.

    19 min
  • Analyst Chat #278: Why Data Provenance Will Define the Next Phase of AI Compliance

    In this week's episode, Matthias Reinwarth and Alexei Balaganski discuss the growing importance of AI Data Provenance. The conversation explores why provenance is distinct from traditional logging, the operational gaps between ML engineering practices and regulatory expectations, and the regulatory context driving these requirements.

    They get into the risks of attempting to retrofit governance after AI systems are already deployed and explain why provenance must be built directly into data and model workflows.

     Key Topics Covered:
    βœ… AI data provenance is a new and urgent issue.
    βœ… Low-quality data leads to poor AI outcomes.
    βœ… Auditing and compliance are essential for AI systems.
    βœ… Organizations must establish governance for AI data.
    βœ… Data catalogs and traceability are foundational.
    βœ… Prepare for AI regulations like GDPR.
    βœ… Start small and apply a risk-based approach.
    βœ… Never trust, always verify your data sources.

    32 min
  • Analyst Chat #277: Mastering IT Governance - Strategy, Compliance & the 1.5 Line of Defense

    IT governance isn’t just paperwork anymore, it’s becoming a critical foundation for how modern organizations operate, stay secure, and stay compliant. This week, Matthias Reinwarth is joined by advisors Kai Boschert and Patrick Teichmann to break down what effective IT governance actually looks like in 2025.

    Together, they unpack:

    βœ… What IT governance really is — and how it bridges strategy and operations
    βœ… The differences (and overlaps) between strategy, governance, and compliance
    βœ… Why the “1.5 line of defense” model helps close crucial gaps
    βœ… The role of target operating models in making governance work at scale
    βœ… How to bring stakeholders, processes, and tools together effectively
    βœ… Practical steps to start improving governance today — without boiling the ocean

    Whether you’re shaping governance for a large enterprise or just beginning to formalize your processes, this conversation delivers real-world insights from active advisory work with end-user organizations.

    28 min
  • Mastering Cyber Resilience with ThreatLocker: How to Stay Secure During the Holidays

    The holiday season might be the most wonderful time of the year—but it’s also prime time for cybercriminals. In this Videocast episode, Warwick Ashford talks with Danny Jenkins, CEO and co-founder of ThreatLocker, about why attacks spike between November and December and what companies can do to stay protected.

    They unpack:

    βœ… Why cyberattacks surge during holidays
    βœ… How to close your organization’s biggest security gaps
    βœ… The importance of automated responses and real-time monitoring
    βœ… Why good backups (and tested restores!) still matter
    βœ… How a “cyber health check” can save your business from disaster

    πŸ“ˆ Whether you’re a security professional or a business leader, these insights will help you strengthen your defenses during the holidays and beyond.

    11 min
  • Analyst Chat #276: IPSIE Explained - Secure & Interoperable Identity

    The fragmentation of enterprise identity systems is creating real security risks but IPSIE is here to simplify and standardize.

    In this episode, Matthias Reinwarth and Warwick Ashford explore IPSIE (Interoperability Profiling for Secure Identity in the Enterprise), how it improves interoperability, enforces secure defaults, and provides measurable maturity levels for enterprise identity management.

    πŸ”Ή Key Topics Covered:

    βœ… What IPSIE is and why it matters for enterprise identity 🧠
    βœ… How fragmentation of SaaS and cloud identity systems increases risk
    βœ… Opinionated profiles and secure, consistent standard implementation
    βœ… Maturity levels for session lifecycle, account lifecycle, and entitlements
    βœ… How IPSIE fits into the broader Identity Fabric strategy
    βœ… Current limitations: focus on human identities and next steps for non-human accounts

    πŸ’‘ IPSIE doesn’t reinvent identity standards, it helps organizations implement what they already have consistently and securely, creating a foundation for stronger enterprise security.

    16 min

About KuppingerCole Analysts

From the publisher's feed

KuppingerCole Analysts AG is an international, independent analyst organization offering technology research, neutral advice and events in Identity Management, Cybersecurity and Artificial…