ITDR has become a crucial layer of defense as attackers increasingly target identity systems. This webinar presents findings from the latest KuppingerCole Leadership Compass on ITDR, analyzing 24 leading vendors and outlining market trends, innovation drivers, and challenges. Attendees will gain an expert overview of how ITDR solutions detect, investigate, and mitigate identity-based threats across complex, hybrid infrastructures
Alejandro will unpack the market insights behind the ITDR Leadership Compass, highlighting the evolution of this critical segment and the interplay between detection, response, and identity governance. He will discuss real-world use cases, innovation dynamics, and how organizations can align ITDR strategies with their broader IAM architecture. Expect a clear, analytical perspective on what defines leadership and differentiation in the ITDR landscape.
Jason Shupp, Director of Solutions Engineering at Silverfort, will provide a technical deep dive into Silverfort’s approach, focusing on how unified identity protection can close visibility gaps, harden authentication pathways, and operationalize ITDR at scale. He will outline architectural considerations, deployment patterns, and practical guidance for teams seeking to implement or mature identity threat defenses.
Who Should Attend:
Wondering if this session is for you? Join us if you’re involved in identity, security, or IT strategy and want to stay ahead of emerging threats. Perfect for: IAM and security professionals, CISOs and IT leaders, SOC and incident response teams.
Gain actionable insights to strengthen your identity defense strategy.
Hello, everyone. Welcome to the webinar, Strengthening Cyber Resilience Through ITDR Strategies. My name is Alejandro Leal. I'm a Senior Analyst at KuppingerCole. I'm here in our offices in BS Baden, and I'm happy to be joined by Jason Shupp, Director of Solutions Engineering at Silverfort.
Hey, Jason, how are you? Great, how are you today?
Good, thank you. Glad to have you here. It's an exciting topic, quite popular, and there's a lot of questions, a lot of confusion out there, so hopefully this will be an informative session for a lot of you. And let's carry on then. I will begin with some rules. Just to set the stage, everyone is muted. Throughout the webinar, we will be conducting two poll questions, so please answer those if you can. It's helpful for us in our research and just to understand more what's going on. We will also have a Q&A section at the end, so please drop questions in the control panel anytime.
And we're also recording the session, so the recording and the slides, they will be available in the next couple days. So there's a lot of things that I need to cover, so I'll be moving quickly.
Again, the agenda is I will start setting the stage of ITDR. I will talk about what ITDR is, what are some of the trends that I see, and also I'll talk about the leadership compass that we published in October of last year. We had 22 participants in the report, so I think some of you will find some useful information from the latest research. And then Jason will jump in and he will do a technical deep dive on the topic. And as I said at the end, we'll have some time for Q&A. So here's the first question. How is your identity and access management infrastructure implemented?
Do you guys have a converged suit, or do you have orchestration of multiple solutions, or do you have a more loosely coupled combination of tools? So just to start with this motivational quote, we heard for many years that identity is the new perimeter. I put it slightly differently. Identity is definitely the perimeter. We see that account takeovers keep rising, both in the consumer and the enterprise space. And I'm sure a lot of you have seen the statistics. A large majority of attacks involve compromised credentials.
Some of the statistics say that 80% of data breaches involve stolen identities. So attackers don't always need malware. They can just buy credentials from brokers on dark web marketplaces. The twist is that identity compromise is increasingly the entry point, and also in the context of this webinar, it's the control plane for modern attacks. So the key takeaway is that if you're not defending identity infrastructure as a target itself, it becomes a blind spot. So here we see that identity as sort of the new frontier.
Let's set the frame that, you know, in most enterprises, the perimeter didn't just disappear. It just simply expanded. So traditional zero trust and IAM programs, they still concentrate on devices and logins. So is the device managed? Do the user authenticate? Is the session allowed?
Of course, that's necessary and important, but it's no longer sufficient. What changed is that the identity perimeter now spans people, machines, and continuous digital interactions, like browser sessions, API calls, service accounts, token exchanges. In that reality, a single authentication event is just a single event. The more relevant question is, what does this identity do next? And does it still make sense, given the context? And I think that's where ITDR extends this model, because it brings additional things to consider, such as behavioral and contextual telemetry.
Not only to understand authentication logs, but also signals like anomalous privilege use, impossible travel, token reuse, device risk, all of these things. And then continuous verification is to detect anomalies as they emerge, and not after the fact. Another step is operational. Integrating all of these different identity signals into SOC workflows, so identity events aren't treated as just IAM noise, but as a first-class security telemetry. So ITDR is this solution that is bridging the gap between the identity teams and then the security teams.
So turning identity data into actionable security intelligence, that's, in a way, the goal. So the shift is from, let's say, verifying identities to understanding identities over time, and making decisions based on that. And this all relates to zero trust. So how can we close those gaps? So zero trust programs often fall, they often stall, because in a lot of situations, many organizations don't really know how to implement a zero trust maturity model. There's a lot of marketing hype out there that says, you know, we're not going to do this, zero trust maturity model.
There's a lot of marketing hype out there that says that this solution is zero trust, and this other solution is, you know, part of the latest zero trust technology. So there's a lot of misconception out there.
Of course, it's not about rip and replacing, but about integrating different tools with your existing infrastructure in a way that will make you reach that maturity level and to close those gaps. So hybrid environments, they are making those gaps more visible. So this is where the shared signals framework becomes relevant. So the goal is to treat threat signal sharing across different systems, so the identity, the endpoint, and security operations. So risk is portable, and decisions are also coordinated. So ITVR sits in that connective tissue.
It provides the missing connections between IEM, EVR, SOAR, and SIEM by taking identity telemetry and then mapping it into decisions that SOC teams can use. And one point worth emphasizing is that the human endpoint becomes a continuous source of telemetry and risk context. So if endpoint signals suggest compromise, identity events from that endpoint should be evaluated differently through step authentication, session restrictions, or immediate containment, depending on the severity. So the direction is clear.
We'll move from authentication as a checkpoint to identity as an ongoing analytical surface where risk is continuously assessed and fed into operational response. And I'm sure that Jason will go more deep into how this looks like in practice and in real use cases. So what is ITVR? How can we define it? ITVR is often misunderstood as just another DR tool. One of the things, the defining idea, I guess, is that identity is both a primary attack surface and a control plane for modern environments, especially SAS and cloud administration.
So ITVR focuses on collecting identity-relevant telemetry, detecting identity-native threats, and enabling response actions that reduce the blast radius. So at the base is enterprise-wide telemetry collection that includes directories, IDA, SAS, PAM events, access management, and all of these things. So here is a slide that we had in our report on ITVR, so the primary activities.
So a good, let's say, practical advice would be to first begin with your identity hygiene. So look at all your vulnerabilities, your dependencies, and try to see if there are any alternatives. So discovery is an important feature that was one of the areas that in the report we tried to focus on, so how these different solutions in the report manage discovery and what do they then do with all of the data that they find. So it's about finding owner for accounts, deactivating abandoned accounts, and then assess risk and take action.
And the second area is to monitor for events and threats and remediate them. And again, I already mentioned this, but it's supposed to be a continual, continuous process. It's something that organizations need to keep that in mind. It's something that you have to continuously do. So the second area is to monitor for events and threats.
Here is a, let's say, high-level technical requirements on ITVR. So we have the identity analytics capabilities and insights that then add that to the SIEM, to the SOAR, and to the XDR. I'm aware that I'm running a little bit out of time, so I'm just going to skip this. And I would like to talk about the main findings of the report. So just to start, we had a report two years ago on ITVR, and back then we only had, I believe, 12 participants. In this report, we had 22, so almost twice as many. And that's a key aspect of how this market segment is evolving.
A lot of organizations are starting to realize that identity is also the control plane. It's not only the new perimeter. So the beginning was a little bit tricky to define the market. There were solutions that came from a different background. They all had a different approach to ITVR. We saw new startups that maybe had a niche focus, such as, for example, Deception. So it was an interesting second report, let's say. We had new players. We had a more developed market. But we can still define ITVR more of a discipline, more of a security practice.
So in essence, ITVR platforms should integrate natively with other identity and access management tools. There were some vendors that still lack integrations. And one of the things that I tried to highlight in the report is that the more integrations you have with your IGAs, with your PAMs, with your XDR and ITSM systems, the more visibility you can get, right?
So the products in this space, they represent different strategic approaches, and we hope that our research can help both vendors understand the market, but also end users to see which solution will be better for them based on their own requirements and needs. So here we have the second poll question. So we're curious to know what are your organization's plans for ITVR? Have you already deployed it? Is it an ongoing process, or are you still considering it? And then if we have time after the Q&A, Jason and I can discuss the results.
So here is the overall leadership of the Leadership Compass on ITVR. It was published October 2025. On the left-hand side, we have the followers. There were none. Most of the vendors are either on the challenger section or on the right side, the overall leadership. We see a combination of well-established players, but also some smaller companies that focus on specific capabilities or niche areas or different industries.
And it's also important to highlight that in the report, we also considered the innovative features that these different vendors bring to the table, because as I said, ITVR is more of a discipline. So really, each vendor has a different understanding of what ITVR is. They all had a different approach on how to collect telemetry, how to discovery, how to do responses. So in a way, what distinguishes the challenger group from the innovation leader is that most of the leaders, they have automated identity-centric responses.
So in case of an event, they have some features or playbooks or workflows that can disable accounts, can terminate sessions, can revoke access tokens. But there were also some other players that had very interesting features, like there's a vendor that focuses on deception. So there's a lot of different things going on there. Other players offer playbook-driven responses, response orchestration, and real-time enrichment of alerts.
And we also have the product leadership and the market leadership but for this webinar, I just wanted to highlight the innovative players because really, ITVR is still changing. I still expect to see new players in the market. I still see, I expect to see new features. So hopefully, we will be doing an update of this report next year, 2027, and it'll be interesting to see how things have changed since then. Almost right on time, so now I would like to invite Jason to the floor and he can continue this technical deep dive.
So Jason, the floor is yours. All right.
Well, sounds good. Well, thank you, Alejandro, and thank you, everybody who's listening. So I guess I'm going to start here and just explain sort of what Silverfort is, who we are, what we do. And what we've evolved into is truly a unified identity security platform that's intended to protect everything from the human identity to machines to AI that span really that span really any identity plane, on-prem hybrid cloud environments. And where we started our protection and our focus is on systems that couldn't be secured before. All right.
So it's not about protecting NHI, it's not about protecting just cloud, it's about protecting your entire infrastructure to give you that complete visibility. And more importantly, that real-time protection. And without going into too much detail about Silverfort and what we do, but we have modular capabilities that span from universal MFA capabilities, authentication firewall, protecting NHI, and many more capabilities and features along with AI agent security, so on and so forth.
But really our goal and the result of what you get with Silverfort is full visibility, controlled access across all identities and closing the attack gaps, right, where most of the breaches are beginning. So that's a little bit about Silverfort. Just to underscore, I completely agree with the assessment here that Alejandro is going through. And it starts with understanding indeed that the new perimeter, and it's not really new, right? It goes back decades, right? The user has been in the forefront of being attacked since I've been in the industry, right? Go back to the year 2000.
And the biggest threat in 2000 was worms, right? Email worms, like I love you virus, things like that. And what's interesting about that 26 years ago is it still required a user, a human to click a button to initiate it. So in reality, users have been the perimeter forever, even back to the 70s, the very first piece of malware required a user to click something for it to start. So we're now recognizing it as an industry, and we need to adjust our traditional defenses to protect the identity perimeter. I'm going to pause here. Thank you.
Thank you, Jason, for sharing these things. Yeah, it's been a problem for a long time, but it's a little bit strange in a way that we start to hear more about it now. Is that something that you agree with? When you talk to some of the end users, are they asking these questions? Are they looking at having this identity control plane? What are they concerned about now that we hear about the NHIs and AI agents? What do you hear out there? We're all hearing the same things, right?
But I think the biggest thing that people are waking up to is we have spent, when I say we, as an industry, we spent billions of dollars protecting our assets. And we've done it with the latest and greatest advancements in technology. And really, when you think about it, all of the technology that we've deployed is to protect either a physical perimeter or protect the perimeter that is the human, which ultimately has access to the data protecting that data. So now that we're aware of this, that becomes the focus.
We've already spent, like I said, billions of dollars trying to solve these problems. We have sophisticated endpoint security technology, XDR platform solutions, and we're still getting compromised. And what's happening is as our defenses get better, well, guess what? The adversary is not just saying, oh, shucks, I can't attack this organization anymore. They put it in the greatest XDR platform on the planet. They're going around it. And they're using traditional methods that look like legitimate activity.
And it is so hard to protect and defend against, which is why you ultimately need a platform, an identity security stack that's going to sit above all these environments, all these different identities, and offer core capabilities like observability and posture, knowing where the threats exist, detection and response capabilities, which is what we're talking about, that align directly with inline enforcement. You have to have these things. Definitely, yes. And as you say, we still see breaches, we still see attacks.
And one of the things that I mentioned in my presentation is that one of the core principles of zero trust is that it doesn't really require you to adopt the latest technology or to rip and replace what you already have. So you already alluded to this, but just to be more specific, maybe how should organizations rethink identity as an attack surface? And what capabilities are most critical for detecting and responding to identity-based threats in hybrid environments?
Yeah, so let me give you a high-level response to this, and then we can kind of dig into some of the details if appropriate. But I think we can all agree identity security has emerged as its own discipline. And you need something that's going to operate as an independent layer to protect how actual identities are being used on-prem and in the cloud. And part of the problem that I think that we've gotten ourselves into is we've siloed ourselves. We've siloed Active Directory from cloud. And we have different controls that we use to monitor and protect Active Directory.
And then we have different tools that focus on cloud. And we've got to converge them, right? Because the same people who are authenticating and using Active Directory are also in the cloud. So how can you have partial visibility with one or the other? And if you have partial visibility, you don't have the full picture. Right? So at Silverthorpe, we're seeing that you have to have the complete identity security, and it has to be built on deep visibility. You have to focus on identity first, detection and response, right? And with real-time in-line enforcement, okay?
Being able to contain early to reduce that blast radius is going to give you resilience in your organization without disrupting legitimate access, right? People are going to make mistakes. There are going to be configuration issues that cause additional exposures. You have to have real-time enforcement and monitoring on top of your identity in order to account and adjust for these things as they happen.
Yes, absolutely. One of the things that I noticed in the report is that most of the vendors have capabilities such as risk scoring, but they have different models, let's say. In your own opinion, what signals should carry the highest weighting when detecting identity compromise? Any thoughts on that? Yeah. So this is an interesting discussion, right? And I think extending ITDR, you have to also look at posture management in order to answer this question effectively.
So, for example, Silverfort, we have two distinct modules. One is ISPM, which is for posture management, and one is for ITDR, which is obviously detection and response. And I would say that really there's no single signal that is sufficient on its own, right? An effective ITDR solution is not going to say, you know, it's not going to choose between a posture, exposure, or behavior, or telemetry. It's going to look at all three of those things, and all those things that it has access to in order to make a determination, right? So if you look at posture, posture itself does not equal compromise.
It just expands your risk, right? It makes you more attackable. So if you look at signals like password age, or legacy protocol use, excessive privileges, all those things themselves, independent of each other, are really nothing, right? They add additional exposures, and response should get triggered when multiple things are happening, right? You've got an exposure combined with behavioral activity. It's looking at those things as a whole to make a determination.
Yes, and one of the things that is important to keep in mind is that ITDR solutions are also supposed to reduce false positives, reduce the noise when an event happens, and one of the key things, one of the things that I focused in the report was response, because when I was having briefings with vendors, they all tried to show me how they prevent breaches and compromises in the first place, and they wouldn't spend too much time on the response side, and that was one of the key areas where I was trying to, you know, get more information from them, because, you know, when an identity incident occurs, it requires an immediate response.
So, in your opinion, from a technical integration perspective, what does an effective identity response pipeline look like, and how can ITDR systems orchestrate actions across different tools? Yeah, again, let me kind of start high level.
So, I like the use of the pipeline, right, and I think we need to start thinking about identity response as a pipeline and not a single action, right? So, any effective ITDR solution is going to start with, has to start with real-time enforcement at the authentication layer.
It's just the way it needs to be, and use that shared identity risk and context to drive decisions, right, and what it enables you to do is, so with Silver Fork, for example, we can ingest from IAM solutions, XDR, SIEM, IGA solutions, and what that does is give us an effective view and visibility into how response should happen based on all these signals and inputs, right? So, if you think of response as a single pipeline and not an action, really what the result is, identity, well, the reason you have to do this partially is because the speed at which identity security evolves so quickly.
So, continuous monitoring plays a particular important role in this. As I mentioned previously, things are going to change, right, and if you cannot, if you have enough data, so when we have the data, right, it's putting all these signals together. When you have enough signals that say, I know for certainty, with great certainty, you know, put it in a 99 percentile, that something bad is happening right now, you have to block it, and if you don't have the ability to stop at the time when you've detected that activity, you're going to get breached, and there's just no way around it.
It's happening. We see this on a weekly basis with organizations.
Yes, that's also something we get from our research when we talk to some of the end users, one of the issues, and another misconception is that many of these organizations, they don't know how to start, so they, some of them have legacy systems, they rely on them, so for organizations just beginning their ITVR journey, where should they start? What practical steps can they take to build, as you mentioned, often visibility? How can they integrate existing IEM tools, and how can they move toward proactive identity defense?
Well, I can answer that quite simply. You have to purchase over for it, and to place over for it. I'm partially joking, but seriously, to answer the question is, for this problem, we truly have to start with the end in focus, and the whole thing, the whole concept behind ITVR is to enable security teams to stop breach, to prevent that bad thing from happening, right?
Minimize risk, but ultimately, ITVR is meant to respond in real time to something that's actually happening, so you've got to start with comprehensive identity visibility that has the ability to block, okay, and you need to move quickly in from the detection mindset into the inline enforcement, and that, it scares people to think about this, but, and you don't have to snap your fingers, and all of a sudden, you're blocking every single threat and risk that you've ever detected in your environment.
That's not what I'm suggesting, and that's not the way to go about it, but you can start blocking things almost immediately after deploying a tool like Silverfort, because of the visibility that we get. There's just certain things that shouldn't be happening in your environment, right?
Not, you know, a shadow admin, right, who has access to critical infrastructure. That should never happen, right? We can put active blocks and enforcements in place to prevent those things from happening day one.
So, and then, so starting with identity visibility, being able to block, and then identify the high priority risks, right? Focus on your privileged identities, the sensitive systems, the hybrid authentication pass. This is a big deal, right? How can you, you know, the hybrid authentication pass is where the compromises are happening, and that's where the most damage can control, or can happen, and then the other piece I'd say on this, too, is what we've already been talking about, but integrating your ITDR solution with the rest of your infrastructure and ecosystem.
It's going to give the picture that we don't have today, right? We've got all these point products. We've got all this data that exists, and before Silverfort, there's really not anything looking at all these things, and making decisions based on holistic view into the environment.
Yes, another interesting thing that I noticed is that there's a lot of marketing on AI, and a lot of organizations are a little bit skeptical with all these marketing claims, and one of the things that I that I tell vendors is that, you know, as long as you're solving the problems of your customers, as long as you listen to what they need, AI can be helpful.
AI features, AI capabilities can be helpful to solve those problems, but it shouldn't be the main slogan that some of the vendors promote, but yes, and maybe my last question to you, Jason, if you had a conversation with a CISO, and you had only 60 seconds to tell the CISO a key takeaway of today's webinar, what would that be? Wow, you put me on the spot here. I had to default go back to buying Silverfort.
Now, I think the most important things is recognizing the attack surface is the humans, right? It's human beings. It's the identity infrastructure, and maybe not just even humans. It's NHIs. It's the legacy service accounts. I'd say the biggest takeaway is we've got to stop the silos, right? The left hand is not talking to the right hand. The threat's happening right in front of you. The visibility is almost there.
Use something like a Silverfort to tie the visibility together, and then give you the ability to actually prevent the breach at the authentication layer, which is where the threat's happening, right? The sophisticated threats now look like normal logins, so you need something that's going to be able to determine and distinguish between those two, and you can't do it without full visibility. You've got to be able to see the big picture, and again, inline enforcement.
Thank you, Jason. Well, we do have some questions in the chat, and for those that are still listening, feel free to submit more questions. There's two questions, and I believe they're for you. One question saying, for the remediation part, how can Silverfort help on that? Will the solution deliver a ready action plan? Question mark.
So, let me answer this with a story, and let me tell the story sort of relating it to a home. I like comparing to a home, because I think most of us have a home, hopefully, but compare identity security to your own home, right? Someone broke into your house. Let's say you're not home. You're on vacation or whatever. They broke into your home. They found all the jewelry. They found, you know, they gathered up all your electronics, and they found a safe, and they're very close to cracking that safe, and they're going to be gone in a couple hours, right?
So, would you rather have an alert that that happened, or would you be able to stop that in real time? So, that really sort of becomes the question here.
So, being able to stop that enforcement in real time, and if you look at it, oftentimes, we're seeing signals, right? We're seeing signals that maybe someone, we detected somebody as a shadow admin, right? They have too many permissions on the network.
So, basically, their permissions mimic a real admin, even though at the surface, they're not an admin. Maybe they're in finance, or maybe they're in a custodian. It could be anything.
So, the issue there is if you detect that thing, or that shadow admin, or that shadow admin, right? It's not, you don't go out and just start blocking that person because they're a shadow admin, but look at the signals around that. If you then got a brute force attack where somebody was brute forcing a user, again, you're not going to go out and turn on the block and just stop that from happening, but if that user is also that shadow admin, now you've got a problem.
Oh, and by the way, if that shadow admin is now, if that same user is authenticating outside normal hours, that's even a bigger problem. What Silverford has created is the ability to take those signals and escalate it automatically and say, look, that one signal is not enough for me to take an action. The second one, right? That's enough for me to maybe step up authentication, right? Automatically push an MFA to that user to make sure that user can prove that they are that user. And when it gets to the stage of, it's now outside of normal business hours, right?
We have behavioral context along with misconfigurations you have to block. And Silverfort will automatically, when it gets to that critical stage, can be configured to block that authentication.
So, and if it's a mistake, right? If it's a false positive, false positives will happen, right? But in an instance like that, where you have so many signals, it's probably not a mistake. And the next successful authentication that happens after that is probably the bad one. And if you didn't block it, you've missed it. It's a good way to continue with the second question from that same user. This user is asking, with Silverfort, in case of blocking an action, how do you then follow the IGA process in place? What would be the next step for the identity team? Right.
For us, it's the integrations, right? So, we enforce bidirectional integration.
So, it could be sending a signal to IGA. It could be receiving a signal from IGA that even started the detection capability, right? Or raise that elevation, right? Maybe we received a signal from your IGA and said, hey, we got somebody over here that it looks a little risky or their system's risky, right? We receive that signal that raises the score a little bit of the threat score. And then something happens against that user. Now that escalates and bubbles that score up even quicker.
So, that's how the products kind of work hand in hand. And then after the action is taken, send that signal over to IGA and follow the normal response that you would employ.
Yeah, I think that was a good answer. It really illustrates the process in a practical way.
So, thank you for sharing that. There's another question.
I mean, I think I will know what your answer will be, but the question is, what are the top ITDR tools that you all recommend? From my side, well, if you look at the report, there are multiple vendors and each of them have their own strengths and their own challenges. It's really about what you have in place and what could work better for you.
So, you should, if you have access to the report, I recommend that you go through it and you look at each vendor chapter so you can understand better what could work for you. But Jason, if you want to answer that. All right.
So, let me do the right thing here and just cover up the Silverford side of me for a second. It actually, so being in industry, and I can't believe I've been in industry for over 25 years, I was thinking about this this morning, but it boggles my mind how companies, and not just companies, but vendors across the board are suggesting that visibility, especially when it comes to identity security, is enough. It just doesn't make sense, right? You see the threat unfolding in real time, right? You see the person navigating through your environment, right?
An email the next day or a log entry doesn't help you. It doesn't stop that breach from happening.
Again, that next authentication is the thing that's going to bite you. So, whether it's Silverford or some other vendor, you have to have the ability to block inline. And you have to do it in a way where you're not just siloed on prem or cloud or SaaS or whatever it might be, whatever control you have. It has to look at everything as a holistic view.
And again, by Silverford, of course. Thank you, Jason.
Moving on, I think we have still a couple questions and then we can just take a look at the poll results. One question maybe you can answer first and then I can give you my own opinion. How do we position ITDR outside the SOC team since threat and response immediately links to the SOC? But this should be an identity niche. How do you see that?
So, it's a good question. I think it plays into the overall, your overall identity security posture, right?
So, while... Well, actually, let me answer it this way. You can't really have an effective ITDR solution if it's going to disrupt operations.
So, I think the trick here is finding that balance to where the SOC can employ controls to actually stop things from happening or to prevent the escalation of an attack or to prevent lateral movement from happening while at the same time allowing that person to do their job, right? Like not being draconian and saying, hey, there's something fishy about your identity. I'm just going to shut you off in the network, quarantine your asset and make you sit there and wait for me to finish an investigation. We can slowly put controls in place to limit the blast radius and the exposure.
And we can do that in real time. We do it all the time with our identity first breach response. We focus on containment first, right? Containment's not something that you discover later in the response. It's early to isolate the affected entities.
So, I think SOC teams... It's a long way of me saying. I think SOC teams need to be able to work together with teams that are operationalizing to be able to have a balance, right? It's all about balance. You can't block too much. You can't not block enough. And you've got to find that sweet spot. And you've got to find a tool that can do it. You pretty much covered what I was going to address.
But yeah, just like going back to the initial slide of the webinar, ITDR is supposed to facilitate the job of both identity teams and the SOC team. It shouldn't be an obstacle. It should facilitate and promote business continuity so everyone can continue doing what they do. And it can increase both the security and the productivity of both teams. I believe that's all the questions in the chat. But now maybe we can take a look at the poll results. And you can give me maybe your opinion on that.
So, the first question was, how is your identity and access management infrastructure implemented? Converged, IAM suite, orchestration of multiple solutions, or loosely coupled, uncoupled tools?
So, if we look at the results, it's around 50% answer that they have orchestration of multiple tools. And then we have 25-25 for converged and loosely coupled tools. What do you think about that, Jason? When you talk to your customers or when you do your own research, how do you see this particular scenario in end users organizations? Do they have a converged IAM suite or multiple tools, from your experience?
Yeah, from my experience, we're seeing a mix of both, for sure. I think the thing that people get stuck on, though, is let's say you combine two technologies, right?
I mean, really, that's multiple tools. You're using multiple tools to solve a problem. You can do more, right? You're not limited. The limitations of identity security tools and all the things talking together are less limited than what they used to be.
So, I think an organization, while they say they have converged tools that are all working together, they're still not quite doing enough, right? And it's not a negative thing. It's just there's more that you can do that just wasn't previously possible. And for the other 25-25, I would say there's definitely, we got to get to a point where we're using, you've made the security investments. And at the end of the day, it's all about protecting the data, protecting your users, your identities. Use them all together.
Find the tool like Silverfort that's going to bring all those things together to actually help your organization. Yeah, so they can all work together in conjunction. Yeah. How about the second poll question?
So, the question is, what are your organization's plans for ITDR? So, turns out that 50% of those who voted are in the implementation process. 25 are considering or planning, and the other 25 have no plans yet. Are you surprised by that? Not at all.
Yeah, same. Yeah, not only am I not surprised, but all I'm going to say, and I don't want to beat this up too much, but I think within a year from now, those stats will change drastically. For sure. And the whole point of ITDR is to stop breach.
So, we've got to close our ears to the thought of visibility being enough, right? And being able, and again, I'm not saying, you know, take a drastic measure and block everything. I'm saying, do it in a controlled manner, right? When you have enough signals that you know something bad's happening, make sure that ITDR investment has the ability to do in-line enforcement. Because if it doesn't, I'm sorry, the breach is coming. You may slow it down, and you may be able to limit its exposure, but it is coming.
Thank you, Jason. There are no more questions. There was one question about one of the slides, but as I said in the beginning, we will make those slides available in a couple days.
So, feel free to check our websites, and you can take a screenshot or a picture of that particular slide. But thank you, Jason, for joining. I think it was a very informative conversation, and any last thoughts that you would like to conclude?
No, that's it. Find more silver for it, and I really appreciate the offer to be here and the content and everything. You've been a great partner for us, and I know for customers around the globe.
So, thank you. I appreciate it. Thank you very much, and thank you, everyone, for listening, and stay tuned. We have more webinars coming up this week and next week.
So, thank you, everyone. Thank you.
See All Locations
See All Locations