KuppingerCole Analysts AG is an international, independent analyst organization offering technology research, neutral advice and events in Identity Management, Cybersecurity and Artificial Intelligence.
Analyst Chat #313: When AI Agents Don't Play Nice - Multi-Agent Security Risks
· 36:38
What happens when you put three AI agents in a room and tell them to solve the same problem? Anthropic ran the experiment — and the results are more unsettling than you'd expect. In this episode, Matthias Reinwarth sits down with Jonathan Care, KuppingerCole Analysts' newly appointed Director of Practice AI, to unpack the findings and ask what they mean for enterprise security, identity management, and the CISOs trying to govern it all. Key Topics: ✅ Anthropic's multi-agent experiment: three Claude instances, one codebase, unexpected outcomes ✅ Why coordination does not emerge naturally from i
Analyst Chat #312: Is AI Killing IVIP Before It Even Matures?
· 24:03
IVIP, Identity Visibility and Intelligence Platform, was one of the hottest acronyms to emerge from the identity market in 2025. But almost a year on, has it delivered on its promise? And more importantly, could AI already be making it obsolete before it even matures? In this episode, Matthias and Martin Kuppinger pick up where they left off and ask the hard questions about IVIP's future. Key Topics: ✅ IVIP revisited: still a set of capabilities, not a platform — and vendors are mostly relabeling ✅ Can AI make IVIP obsolete before it ever becomes a mature category? ✅ How AI is finally tackling
Analyst Chat #311: Architecting Your Own Digital Sovereignty
· 30:48
Digital sovereignty is one of the most talked-about topics in European tech policy right now and according to Alexei Balaganski, most of the conversation is going in completely the wrong direction. In this episode, Matthias sits down with Alexei to challenge the assumptions behind the sovereignty debate, redefine what the term actually means, and lay out what organizations should really be doing about it. Key Topics: ✅ Why the "digital sovereignty" conversation has gone wrong — and what Alcatraz has to do with it ✅ The only correct definition of sovereignty: can you keep operating when a depen
Analyst Chat #310: AI Escaped the Sandbox - The OpenAI Hugging Face Hack (special episode)
· 32:50
When an OpenAI test model escaped its sandbox and attacked Hugging Face's production infrastructure, headlines called it a Skynet moment. But was it? In this special flash news episode, Matthias Reinwarth brings together four KuppingerCole Analysts experts — Alexei Balaganski, Jonathan Care, John Tolbert, and Martin Kuppinger — to cut through the noise and ask the real question: what actually went wrong, and what should organizations do about it? Key Topics: ✅ What actually happened: two separate incidents dressed up as one dramatic story ✅ Why the sandbox failure was a containment and design
Analyst Chat #309: Fabrics Deep Dive II - the Identity Fabric as the Blueprint
· 27:23
The Identity Fabric isn't just a concept, it's a working tool that KuppingerCole Analysts advisors use every day with clients. In this second episode of the fabric mini-series, Matthias sits down with Martin Kuppinger and Phillip Messerschmidt to explore how the Identity Fabric and Reference Architecture are applied in real client engagements, why capability-based thinking beats tool-centric thinking every time, and how the fabric evolves to stay relevant in a world of constant buzzwords. Key Topics: ✅ How the Identity Fabric is used in practice: maturity assessments, gap analyses, roadmaps, a
Analyst Chat #308: Beyond SASE - What a Real Zero Trust Platform Looks Like
· 42:44
Zero trust has a label problem. After more than a decade, the term has been stretched, diluted, and attached to products that don't come close to delivering what zero trust actually promises. In this episode, Matthias sits down with Alexei Balaganski, lead analyst at KuppingerCole Analysts, to share the findings from six months of research and reveal which vendors actually built a real Zero Trust Platform. Key Topics: ✅ Why zero trust is a strategy, not a product — and what that means for procurement ✅ The four non-negotiable requirements for a real Zero Trust Platform ✅ What separates a genui
Analyst Chat #307: Fabrics Deep Dive I - Why "Fabric"? The term, the idea and how to use it
· 19:15
Seven years ago, KuppingerCole Analysts introduced the Identity Fabric concept and it has shaped how organizations structure identity management ever since. In this episode, Matthias sits down with Martin Kuppinger, co-founder and distinguished analyst at KuppingerCole Analysts, to revisit the origins of the Fabric paradigm, explain why it still holds today, and preview where it's headed next into cybersecurity, AI security, and beyond. Key Topics: ✅ Why the Identity Fabric concept emerged in 2019 — tool sprawl, siloed IAM, and the collapse of the perimeter ✅ What "fabric" actually means: a ca
Analyst Chat #306: Make or Buy? A Structured Framework for Smarter Tech Decisions
· 36:39
Build or buy, it sounds like a simple question, but for most organizations, it's one of the most consequential and poorly structured decisions they make. In this episode, Matthias sits down with analyst and advisor Phillip Messerschmidt, who turned his hands-on advisory experience into a structured framework for getting the make-or-buy decision right every time. Key Topics: ✅ Why "we can build it cheaper" is almost always a biased and incomplete argument ✅ How the originating perspective (business unit, IT, security) shapes — and distorts — the decision ✅ The most common and costly mistakes or
Beyond SOAR: How AI Agents Are Transforming Security Operations
· 37:09
Alert overload, 24/7 coverage gaps, and human threat actors who never stop — the SOC has problems that traditional SOAR and rule-based systems simply can't solve. In this sponsored videocast, KuppingerCole analyst Matthew Gardiner and Rick Bosworth, Head of Product Marketing at Torq, dig into the findings of KuppingerCole's Emerging AI SOC Leadership Compass and explore what it actually takes to build an AI-powered security operations center. Key Topics: ✅ Why rule-based SOAR has hit a wall — and how AI agents address what it can't ✅ The autonomy dial: why full automation isn't the goal and ho
Analyst Chat #305: IGA in 2026 - NHIs, Sovereignty & the Platform Shift
· 20:17
IGA is often dismissed as a mature, stable market but that couldn't be further from the truth. In this episode, Matthias sits down with Nitish Deshpande, to explore how identity governance and administration is being reshaped by NHIs, AI-driven intelligence, deployment sovereignty, and a wave of challenger vendors. Key Topics: ✅ How IGA has evolved from static, siloed tools to integrated, multi-identity platforms ✅ Non-human identities: IGA vendors are now covering NHI governance — and customers are demanding it ✅ Where IGA still falls short: role mining, anomaly detection, policy simulation,
Analyst Chat #304: Agents, Fabric, and the Unfinished Business of IAM, A Look Back at EIC 2026
· 35:19
Four weeks after EIC 2026 in Berlin, Matthias Reinwarth and Phillip Messerschmidt sit down to reflect on what the European Identity and Cloud Conference revealed about the state of identity and access management and what it means for the year ahead. Spoiler: agentic AI dominated, but it wasn't the only story. Key Topics: ✅ Agentic AI as a new class of insider threat — autonomous, non-deterministic, and without ethics ✅ Data-centric defense vs. agent discovery: protect the vault, not the crowd ✅ Why dynamic authorization and behavior analytics are the IAM industry's urgent next step ✅ Data sove
Analyst Chat #303: B2B Identity & Access Management - A New Market Unpacked
· 29:48
Business relationships are complex and traditional IAM wasn't built for them. In this episode, Matthias Reinwarth sits down with Principal analyst John Tolbert, author of KuppingerCole Analysts' first-ever B2B IAM Leadership Compass, to explore why Business-to-Business Identity and Access Management is emerging as its own distinct market and what it takes to get it right. Key Topics: ✅ Why B2B IAM sits between workforce IAM and CIAM — and why neither alone is sufficient ✅ Delegated administration: handing identity governance to partner and supplier organizations ✅ Federation, lifecycle managem
Is Your CDN Secure? CDN vs. DDoS Mitigation Unpacked with Qrator Labs
· 16:51
Speed and security are no longer separate concerns. In this videocast, Osman Celik sits down with Andrey Leskin, CTO of Qrator Labs, to break down what Content Delivery Networks really are in 2026 and why they've become a critical piece of modern security infrastructure, not just a performance tool. Key Topics: ✅ What CDNs are and why they're no longer optional for competitive organizations ✅ How CDN and DDoS mitigation differ — and where they overlap ✅ Cache busting, HTTP floods, Slowloris and other real-world attack vectors ✅ Why "security-first CDN" is fundamentally different from "CDN with
Analyst Chat #302: PAM Is No Longer a Vault - The New Identity Security Layer
· 35:06
Privileged Access Management has outgrown the vault. In this episode, Matthias sits down with lead analyst Alejandro Leal, author of KuppingerCole's newly released PAM Leadership Compass, to explore how the definition of privilege itself has changed, what NHIs and agentic AI mean for PAM, and why deployment sovereignty is now a boardroom conversation. Key Topics: ✅ How the definition of "privilege" has shifted from admin accounts to dynamic runtime identity capabilities ✅ PAM convergence with IGA, CIEM, ITDR, SIEM, and SOAR — the end of the standalone PAM product ✅ Non-Human Identities (NHIs)
Not all cyber threats target your systems, some target your reputation, your customers, and your brand. In this episode, Matthias Reinwarth sits down with research analyst Osman Celik to unpack three closely related but distinct markets: Attack Surface Management (ASM), Digital Risk Protection (DRP), and Brand Protection — and help organizations figure out which one they actually need. Key Topics: ✅ What Attack Surface Management is and its four subcategories (CAASM, EASM, TPRM, DRP) ✅ How Digital Risk Protection monitors dark web, social media, and hacker forums ✅ What Brand Protection adds o
Analyst Chat #300: Shadow Agents and the Next Identity Crisis
· 14:45
Shadow IT was manageable. Shadow AI was concerning. Shadow agents? That's a whole different problem. 300 episodes already? Time flies when you're having fun! In this 300th Episode of the KuppingerCole Analyst Chat, Matthias sits down with Distinguished Analyst Martin Kuppinger to unpack one of the most urgent, and underestimated, security challenges facing organizations right now: employees building and deploying their own AI agents, with no governance, no oversight, and no accountability. Key topics: ✅ What "shadow agents" are and why they're fundamentally different from shadow IT or shadow A
Analyst Chat #299: AI Security Fabric - Identity, Governance & Authorization for Autonomous Agents
· 56:17
AI is reshaping enterprise architectures, but is security keeping pace? In this episode, Martin Kuppinger, Matthias Reinwarth, and Darran Rolls talk about the urgent question of how organizations should structure their defenses for a world of autonomous, agentic AI. The answer: an AI Security Fabric. Key Topics: ✅ Why agentic AI breaks traditional, deterministic access models ✅ The concept of "AIdentity" — what makes AI agent identity fundamentally different ✅ Can the Identity Fabric scale to meet AI security demands? ✅ Discovery, authorization, and governance as the pillars of an AI Security
Analyst Chat #298: Why AI Is Becoming Foundational to Cybersecurity
· 32:12
Security teams have spent decades building deterministic, rule-based defenses. But the threat landscape has changed and AI is no longer just a feature add-on. In this episode of Analyst Chat, Matthias sits down with Matthew Gardiner to unpack his latest advisory note and Leadership Compass on AI SOC, exploring why probabilistic AI is becoming a core pillar of modern cybersecurity. Key topics: ✅ Why deterministic security has run its course — and what comes next ✅ The "two-sided coin" model: rules-based vs. probabilistic AI approaches ✅ Where AI genuinely outperforms traditional methods (and wh
Analyst Chat #297: AIdentity and the Limits of IAM
· 20:14
AI agents don't just use identities. they create, delegate, and impersonate them. In this episode of Analyst Chat, Matthias Reinwarth sits down with KuppingerCole's founder Martin Kuppinger to dig into AIdentity (the concept at the intersection of AI and identity management) and why the IAM tools we've relied on for decades are no longer enough. Key topics: ✅ What AIdentity means and why it's more urgent than ever ✅ Why AI agents can't be treated like standard non-human identities ✅ The identity relationship challenge — from simple access to complex agent meshes ✅ Why "human in the loop" is mo
Analyst Chat #296: Aldentity - Treating Al Agents as First-Class Identities
· 38:29
AI agents aren't just software, they're a new class of actor that can impersonate users, bypass security policies, and operate across complex identity meshes. In this episode of Analyst Chat, Matthias Reinwarth sits down with Martin Kuppinger and KuppingerCole's newly appointed AI Security Practice Lead Jonathan Care to unpack the emerging concept of AIdentity and why it's the key to securing agentic AI. Key topics: ✅ What "AI Identity" means and why it's more than just a service account ✅ The dangers of agent impersonation and the "ClaudeBot dumpster fire" ✅ Authorization collapse, what happe
Analyst Chat #295: Independent ROI - A New Model for Cybersecurity Investment
· 15:45
What does an enterprise technology product actually deliver — in hard numbers? In this episode, Matthias Reinwarth sits down with Jonathan Care, KuppingerCole Analysts' newly appointed AI Practice Lead, for a behind-the-scenes look at a brand new research format: the Product Value Navigator (PVN). Key Topics: ✅ Why enterprise tech buying is broken — and what's missing from analyst rankings ✅ What the Product Value Navigator is and how it works ✅ How KuppingerCole independently validates ROI through real customer interviews and financial modeling ✅ Who the PVN is built for: CISOs, IT leaders, p
Analyst Chat #294: Secure Remote Access as the Control Layer for OT Security
· 24:47
As OT systems go online, controlling access becomes more critical than enabling it. In this episode of the Analyst Chat, KuppingerCole analysts Matthias Reinwarth and Warwick Ashford dive into one of cybersecurity’s most overlooked domains: OT (Operational Technology) security. As industrial systems become increasingly connected, the traditional boundaries between IT and OT are dissolving, bringing new risks and new security imperatives. Key Topics ✅ The rise of Secure Remote Access (SRA) in OT environments ✅ Why VPN-based access falls short for industrial systems ✅ Zero Trust and identity as
Analyst Chat #293: CIAM is Evolving - Scale, AI Agents, and Identity Challenges
· 17:30
In today's episode of the Analyst Chat, Matthias Reinwarth welcomes John Tolbert to take a deep dive into the rapidly evolving world of Consumer Identity and Access Management (CIAM). As organizations manage millions, or even billions, of identities, CIAM is shifting from a standalone capability to a core component of broader digital ecosystems. Key topics: ✅ Consumer vs. B2B IAM segmentation ✅ Passkeys adoption and UX gaps ✅ Identity lifecycle and account recovery ✅ CIAM integrations and platform ecosystems ✅ AI agents and identity governance Increasing scale, regulatory pressure, and user ex
Analyst Chat #292: The Collapse of Trust - Deepfakes, Disinformation & Enterprise Security
· 42:15
In the age of AI-generated content, the real challenge isn’t just detecting falsehood, it’s knowing what to trust at all. As deepfakes and disinformation scale, perception itself becomes a new attack surface. This week, Matthias Reinwarth and Jonathan Care explore how misinformation and disinformation are reshaping cybersecurity and enterprise risk. They clarify the difference between the two, examine how AI is accelerating the creation of deceptive content, and discuss why traditional trust models are breaking down. Key Topics ✅ Misinformation vs. disinformation: definitions and impact ✅ Deep
Analyst Chat #291: The Emerging AI SOC Market Explained
· 27:29
The future SOC won’t replace humans with AI, it will empower us with AI-driven automation, accelerating detection and response while keeping humans in control of critical decisions. This week Matthias Reinwarth and Matthew Gardiner discuss the evolution of security automation with the introduction of AI SOC (Security Operations Center). They explore the challenges of alert fatigue, the importance of human oversight, and the cautious optimism surrounding AI's role in cybersecurity. The conversation delves into the balance between automation and human intervention, the trust issues associated wi