
Boston, April 2025
On the flight over to CyberArk Impact, I watched two films. One was Godzilla Minus One, a story about a radioactive monster ravaging post-war Tokyo. The other was Civil War, Alex Garland’s dystopian vision of a fractured, blood-soaked United States brought to its knees by a president gone rogue.
Which scenario feels more likely today? Hard to say, tbh! But both movies had some relevance to what’s happening in identity security and management. Machine identities are multiplying into a monster challenge. Identity management vendors are fighting a quiet civil war over terminology, categories, and control. And amid it all, CyberArk, the old guard of Privileged Access Management (PAM), is staging a campaign to assert dominance not just over humans with root access, but over every workload, container, API token, and AI agent that dares to call itself an identity. This was a big year for CyberArk, now a billion-dollar company with fresh acquisitions under its belt. But just like the movies, not everything made perfect sense.
Machine Identity: The New Frontline?
In my meeting with Kevin Bocek, who leads CyberArk’s machine identity strategy, it became quickly clear: CyberArk (or "CARK" for brevity) isn’t keen to talk about CIEM (Cloud Infrastructure Entitlement Management). I asked about convergence with PAM and Non-Human Identities (NHI), but I’m not entirely sure the question landed, or maybe that’s a sign I’m the one still figuring this conundrum out.
CARK’s position is this: NHI is simply a subset of the broader machine identity category. And honestly, I think I agree. The industry’s (and analysts) obsession with NHI as the hot new thing misses the forest for the trees. What we’re really talking about is machine identities, workloads, containers, service accounts, API tokens, IoT devices, basically everything not human, and how we govern their access.
CrowdStrike, for example, might disagree. They define NHIs by machine type: workloads, API tokens etc. But that’s a splitting-hairs game and, in my opinion, cynical. CARK’s view, and mine, is that it’s all machine identities – by its very definition a machine identity is non-human. Of course, a machine identity might have a human controller but please, industry, can we stick to one classification before someone launches "Post-Human Identity Management" and makes things even worse!
CIEM, PAM, and the Great Identity Convergence Confusion
OK, here’s how I see it or at least this is what I wrote in my notes.
CIEM = Governance and administration
PAM = Authentication and security enforcement
NHI/Machine = The entities themselves
So, the convergence, if there is one, is not between PAM, CIEM and NHI/Machine whatever, it’s between CIEM and PAM. These two can (and increasingly must) handle all identities, human or otherwise.
Now that’s fixed in my mind I can and will talk more about this in my session at EIC 2025. Of course, my view may differ slightly from my colleagues at KuppingerCole – but that’s because we don’t do groupthink at KC, one of our strengths is independent thought. We agree that identity is central to cybersecurity, but we are nuanced on how we make it so. Oranges are not the only fruit here.
Real Talk from the Field: Northern Trust’s Journey
One of the standout real-world sessions came from Lenin Cruz, SVP Global Head of IAM and Data Protection at Northern Trust. Deploying Endpoint Privilege Management (EPM) is hard enough, but when you’re facing over 400 policy definitions, migrating from a different PAM vendor, and wrangling teams with wildly different deployment experiences, it gets messier.
Cruz highlighted a major challenge: accountability. Privileged access isn’t just an admin job anymore. More and more, business users and non-technical managers are deciding who gets privileged roles and when. That’s not just a culture shift; it’s a security reality.
Northern Trust also built smart access with CARK’s ServiceNow integration so that users request access through a familiar interface. It’s simple, user-friendly, and probably harder to build than they made it look! But it’s the right approach for balancing convenience and security.

Figure 1: The three stages of an EPM migration at US bank Northern Trust.
Identity Hygiene with a Punchline
SPHERE founder and CEO Rita Gurevich gave one of the most entertaining talks of the conference, riffing on the importance of Identity Hygiene. Her point? Move beyond risk reduction toward risk prevention. And how? Ownership and Governance = Hygiene.
If you can’t tie an identity, human or machine, back to an actual owner, then you can’t manage it. It’s relatively easy with human identities but it’s at the heart of the machine identity problem. Who owns the API token your development team created six months ago? Who owns the VM spun up by an AI process at 2am? The answer, increasingly, is no one knows.
Just wait until agentic AI starts creating identities for other AIs. That’s when we’ll need to call Godzilla.
Keynote Energy and Metallica Moments
The opening day’s Keynotes made sure we knew the stakes. CyberArk now estimates there are 82 machine identities for every human identity. Whether that number is accurate doesn’t really matter. The point is: this is already a massive problem, and it’s only getting worse with AI.
Enter CyberArk Secure Workload Access Solution. Announced by Kurt Sands and backed by Metallica’s Enter Sandman (a cultural reference that may have been lost on half the audience), this solution promises lifecycle control for all machine identities, from creation to governance, rotation, and renewal.
CARK’s promise: visibility, automation, and enforcement of least privilege across hybrid and multi-cloud environments. Ambitious stuff. Whether they can deliver depends on execution, but the intent is clear: own the machine identity space.
AI Agents, Identity-First Security, and GitHub Goodies
Then came the announcement of CyberArk Secure AI Agents Solution. In a nutshell: identity-first security for agentic AI. As AI agents begin to act, escalate privileges, modify infrastructure, and talk to each other autonomously, the risks will explode. This, as they say, will be huge.
CARK’s new platform capabilities aim to mitigate those risks at least. CARK has dropped an open-source toolset on GitHub for developers building AI agents. It includes JIT credential provisioning and visibility tools for communication patterns. Useful stuff, especially if you’re working on AI agents with serious access requirements.
Reality Check: Vaults Still Matter
Not everyone at the conference was swimming in AI tokens and Kubernetes clusters. I spoke with a delegate from a US hospital group, just three months into his IAM role, and his organization has moved precisely nothing to the cloud.
For him, all this talk of NHI and AI was background noise. What mattered? A vault. Password rotation. Getting the basics right. And learning CyberArk.
As analysts, we sometimes forget that for many organizations, PAM is still a foundational technology, not just a capability. The same goes for CIEM. Different markets, different maturity levels, different problems.

Figure 2: Lest we forget among the rise of the machines: human privilege is still a huge risk area.
Final Thoughts: Platforms, Promises, and Persistent Problems
CyberArk wants to be THE identity security platform – just as SailPoint, BeyondTrust, Delinea and others do. They’re building the tools: policy automation, AI agent support, machine identity lifecycle management. They’ve acquired Zilla, giving them stronger Identity Governance capabilities. They’re pushing forward, no doubt.
But even with all that, the core challenges remain the same: too many privileged accounts, too many zombie identities, too little clarity on ownership. That’s not a vendor problem; it’s an industry one.
CyberArk’s direction is bold. Certainly, the company is thinking seriously about current and imminent identity management challenges and is now undoubtedly the dominant player in this sector. But the most curious (and, to me, welcome) aspect of my immersive three days in Boston was that PAM or Privilege was mentioned more often than Identity or Identity Security and CARK did not bang the Identity Platform drum as much as I thought. That and the interactions with actual users have changed my mind somewhat on the future of PAM and CIEM and machine identities. See you in Berlin at EIC!