Managing cloud entitlements across AWS, Azure, GCP, and SaaS is now one of the biggest challenges in cybersecurity. This webinar presents highlights from the latest KuppingerCole Leadership Compass on CIEM, showcasing the most capable and innovative vendors in this space. Learn how these solutions reduce cloud risk, enforce least privilege, and automate access decisions in real-time. Whether you're a CISO, cloud security architect, or IAM leader, this session will guide you toward better entitlement governance and cloud resilience.
In this session, Paul Fisher will walk through the key findings from the CIEM Leadership Compass 2025, including why CIEM is fast becoming essential for modern cloud security strategies. He will highlight standout vendors and what makes them leaders across product innovation, automation, and integration. Expect a deep dive into trends like ephemeral access, non-human identity control, and how AI is reshaping entitlement management. Whether you’re evaluating vendors or planning your next move, this will give you a critical head start.
Hello, and good afternoon from London. Good evening, if you're to the west of me. So that would still be good morning. If you're to the east, it could be good evening, or even good night. But here we are in London where it is currently three o'clock. And it's a nice sunny autumn afternoon. So that's enough about the weather. I'm Paul Fisher. I'm excited that you're here with me today to talk about CIEM or CIEM as some people pronounce it or CIEM, but that leads to confusion. So we'll call it CIEM.
And just a few bits and pieces about that based around what I wrote in a leadership compass not so long ago. And, and also just for you that maybe don't know what CIEM is or what it's about. We'll be talking about that too.
So you've, if you've been here before, you'll know these, this familiar, that you don't have to do anything, you just need to listen. There is a poll that we'll do during the webinar. And there will be time for Q&A at the end and just enter your questions into the control panel that you should see in front of you. And I'll do my best to answer them. It will be recorded. This will be stored forever, forever on the Cooking the Coal website.
So, you know, it's there for time memorial and who knows might see it in the future. Perhaps one of my ancestors, no, not my ancestors, my whatever the, the opposite of ancestor is a processor, maybe, I don't know. So here's the agenda.
Why, why CIEM matters? Then some details about the leadership compass that I spoke about came up earlier this year, and then some trends in, in entitlement management for cloud, et cetera, and then some recommendations for you and closing remarks. And then as I say, Q&A, if there's time. So have you deployed a CIEM platform? That's what we want to know right now. So you have four choices. Are you thinking about it, but waiting for the market to mature? You don't think you have any need for it right now. We use the CIEM capability in our PAM.
So you might have a PAM solution that has some kind of CIEM function in there, or right now you just don't see it investing in. So those four options of you to vote now, and we'll have a look at that later. Thinking about it, no need for it. We've got it.
Oh, we don't see it worth investing in, which is different from we have no need for it. Right. So why does it matter? Okay. So the whole world has gone crazy for cloud. Everything is in the cloud. Many businesses now use more than one different type of cloud provider. There is SAS operations everywhere, and it's increasingly hard to keep abreast of who's doing what, what identities are doing, and what they are looking for in the cloud.
So a few years ago, this conundrum or this challenge came to a number of vendors, mostly startups, that realized there was a marketing, a market opening for some kind of tool that could manage the entitlements that users had. And it was mostly focused at end users, as in humans to begin with, and to discover and find out and see what people are doing out there. And if they were doing things they shouldn't be, it would automatically block them from access and so on.
And one of the key things it did, which is where it overlaps a little bit with privilege access, was that it could find what Microsoft actually dubbed privilege creep, which is, I've always liked that phrase, actually, because it does perfectly describe what happens, is that unless you control this, the users end up getting access to stuff they shouldn't or have no real need to, and it gets left like that.
So unlike a specific PAM tool, which can focus on privileged accounts, these so-called privileged users didn't have traditional privileged accounts, they just had maybe just ordinary Azure accounts or Enter ID accounts. But because of the nature of cloud, which is much more open and loose, etc., they were able to get access to stuff that perhaps they shouldn't. So in a nutshell, KIM is a process of discovery, then enforcement, and then automation as you go forward.
And since KIM first appeared, those facilities have got more sophisticated, and with the coming of AI, then we're seeing more forms of automation as well. And it is, although not traditionally seen in sort of the IGA bracket, it is probably part of that.
I mean, it does govern identities, and it complements the traditional IAM, and like I said, PAM. So that's KIM. And why does it matter?
Well, as I was just saying, one of its key are key attractions for organizations is it can enforce least privilege at scale. So at scale is another IT cliche, but seriously, in this sense, it actually works because you can control a large number of users, a large number of identities that are using parts of the cloud without having to specifically control their accounts.
Instead, you can just see where these people are going, look at the policies, and you can quickly stop their access without too much fuss. It also increasingly supports regulatory compliance.
Right now, compliance seems to be, if not the number one reason, but certainly up there in the top three reasons for people buying identity management tools, such as this and privilege access as those legal requirements have become harder and more enforceable and more a challenge in many ways. And also, cyber insurance companies insist that companies meet these compliance challenges by, for example, having perhaps privilege access or a KIM or some other kind of tool which would make them compliant.
Otherwise, they don't get any insurance. And the better KIM tools also enable cloud resilience through adaptive controls. So they're now moving from just switching off access to something that becoming a little bit more like some just-in-time actions so that an identity could have access to something in the cloud depending on what they're doing right now, and then it could be switched off. So that's all being built into some forms of cloud entitlement management. So just looking at my time there.
So the challenge is for end users, for you, et cetera, to manage that sprawl across the three big clouds, AWS, Azure, Google, and SaaS applications. And also what's recently happened, which is affecting this market, is that the state of the world, let's put it like that, has meant that European sovereignty has become quite an attraction for European businesses that they want to keep this data that they hold in European hands or local hands rather than, say, United States or China.
So it means that these KIMs will also probably start supporting European clouds such as OVH and StackIt, which is another one from Germany. But it's likely in reality that many companies will still continue with American clouds because it's just easier. But it does mean that KIM itself needs to be able to manage different types of cloud. The challenge is also to reduce overprivilege, which is the same thing as privilege creep.
And also we're seeing everyone's talking about it, agentic AI or synthetic identities that are actually machines having access to stuff which can actually include other applications, et cetera. Those are much more likely to speak from cloud to cloud as they are in a more traditional client server-based way of computing. And those need to be controlled.
In fact, they need to be controlled more than human identities because they're much more likely to be created itself without too much governance. And many PAM solutions, although they have started to adapt KIM, et cetera, they're just not sufficient. They're not flexible enough, agile enough, or quick enough to work at the speed of cloud. And that is why KIM is becoming extremely attractive to those companies that have large DevOps organizations, where DevOps, for example, are quite, let's say, not notorious, but DevOps people tend to work around things.
They want to get stuff done and they work for speed. And again, traditional PAM or traditional AI actually tends to slow them down. So part of KIM is the enablement of access to cloud resources as quickly as possible, but securely. So that's the background of KIM. And you can find out a lot more about the market by looking at the leadership compass that I created, research and created earlier this year. So talking about that, let's have a look at some of the findings in that.
So a leadership compass is Kupinger-Cole's flagship reports, which do independent analysis of various types of software or solutions or platforms in particular areas or particular market sectors. Now, unlike other analyst firms, we do not limit who is eligible to appear in a leadership compass. We don't put limits on revenue. We don't put limits on how long the company has been in business.
Instead, we try and show as wide a view of the market as possible. So we will have the biggest vendors in there, and we'll also have some of the newest and smallest. And they all compete for different parts of the market. So we evaluate those vendors then on their actual product, their innovation, and where they stand in the market. And then those are further divided into leaders, challenges, visionaries, and specialists in each of those sectors. And it's important. I always tell people it's important to take a leadership compass, but not at face value.
Don't open the report, just look at the leaders and think, well, they must be the guys that I need, because you need to read through the report to see how perhaps those vendors further down may have exactly what you need if you have a particular niche area. So just to wet your appetite, I suppose, the leaders in this were Archon, CrossIdentity, NexLabs, SailPoint, Delinear, SSH, Savient, with SSH, EmpowerID, and Segura.
So you can see from that that these are not all, apart from perhaps Delinear, they're not all, and SailPoint, not huge vendors, which shows that this market is relatively new and relatively unmature. And it's likely that that will stay that way, that although there has been some, you know, getting together, you know, of merging of vendors or acquisition of vendors by bigger ones, there's still people coming into the market at the lower end, startups, et cetera, that are creating a bit of a buzz around this technology.
So as I said, Delinear, SailPoint, and Savient probably because Delinear for sure acquired a Kim capability to be part of this market, but Delinear as a large plan vendor already supports many clouds, and it also has a large install base, and it has benefits of being a long-standing vendor. But as I said, have a look at the report, don't just look at the leaders, even though I'm focusing on them right now, but make sure that you look through the whole report to see where other vendors might fit into what you are looking for.
So going away from the report now, perhaps we should talk a little bit about some of the key trends that are affecting this market, affecting the software development, and affecting you as potential buyers. So here we have, this is kind of what I was alluding to, thanks there to Raphael, who is our graphic designer. He's put a fiery picture on there, so I guess that means this market's on fire. Maybe it is, but the Kim market is a pivotal stage. It's probably at a point where it's going to need even more automation through AI. AI is going to certainly help in that regard.
It'll probably need real-time adjustment just in time as default, as standard. So whilst it is more dynamic and the more static privilege access, it needs to be, I think, it needs to then develop into a totally live environment so that things can happen on a context, time, and policy basis as much as they do on just, for example, role-based. So cloud-native challenges are making significant inroads by focusing on those areas. They tend to come from modern DevOps-y environments themselves.
They tend to come from leaders in identity that have done great things in existing areas, such as privilege access or identity and access management, and then now moved into this area. So that's something else to look out for is who's starting these businesses because there's a lot of very well-known, very talented entrepreneurs and developers in this space. So differentiation for you, the buyers, will depend on how far you need automation, how far you need access. But probably manual entitlement governance will not be enough for the future.
As I said, more clouds need to be supported. So that includes not just the big three, but the emerging European clouds, which are being taken seriously now, very seriously. By European businesses and also Microsoft, as it says, has developed a sovereign European data center or data centers to work with this new demand. And of course, that means it is kind of a separate cloud. So more clouds might appear, more types of clouds might appear. Kim needs to keep up. And one thing I've noticed about the market is that there's still a number of players that don't even support the three at the moment.
Many just go with AWS or Azure and Google to a lesser extent. But I don't see that those big clouds are going to disappear, despite the geopolitical situations that we find. So it's important that Kim vendors cater for as many cloud infrastructure or cloud platforms as possible. And added to that, that Kim will also find its way into managing software as a service. So it will find its way managing tools, such as ServiceNow, or Salesforce, etc. So there is perhaps a convergence of Kim, Pam and IGA.
But I don't, at the moment, I think that Pam will continue to exist, but as a separate tool, certainly for legacy environments. So those environments that still wish to use vaults and passwords and things, but also the growing number of specialists, privileged access, such as EPM vendors will also start, I think, to be looking at ways of adapting EPM to a cloud entitlement model as well. So lots to look out for in the market, lots going on.
And I personally, you know, having covered it for the last two or three years, I do think it's one of the most interesting parts of identity management or access management, authorization, etc. And I shall continue to look at it. So what about that future? This is more based on what users might need. So they might have a unified privilege access cloud control platform, which may come out of one of the big vendors, it may come from doing integration itself. One thing that is hugely important now to any vendor is making sure that their platform works with other platforms through APIs.
So despite all the talk of platforms and identity platforms, and some of the stuff you might read on LinkedIn about vendors pushing numbers like 60 to 70% of end users want a single platform from the same vendor, when I said vendor speak, actually in the real world, I find that people don't want that. But what they do want is best in class. And they want the choice and the ability to have the tool, which is right for the job, and which works with everything else. So that could be convergence could be a hybrid privilege access book. We shall see.
But finally, I do think that, you know, the the vaulting the passwording for some environments, some buyers actually prefer that, but it's not usually, it's increasingly for low dynamic or low speed environment rather than the high speed environments, which Kim is more suited to.
And just to round this off, on you may, I said that Kim is moving to support things like service now, it may happen that one of these platforms might develop some kind of Kim itself, which eventually would give users for, for example, service now or, or some other admin, you know, tool like that, which would then govern the privilege access to various things. So you might see ITSM vendors providing their own Kim and Pam. And if you look at these two diagrams, you can see that the workflow is identical.
Therefore, to the end user, it may be it doesn't, this is, you know, the important part of any access platform is that the end user doesn't see it happening, doesn't see it in the background, it literally logs on, asks requests, gets an approval, whether that goes through a third party or whether it goes through the ITSM with integrated tools, doesn't matter.
So that's something else to think about, as this market develops that I know, from my own research that some platforms are actively thinking about how they can integrate some form of entitlement management and some form of privilege access to watch out for that. So coming quickly to the end of this brief overview of Kim. So let's just now I see that I've never had, I think that guy there is called Drake. I'm pretty sure that he's a rapper. And so Raphael has kindly put that on there, I think, to show to show me that I know nothing about modern music.
But I think I'm right in saying that that's Drake. But so what should you look out for apart from Drake is visibility, as I said, across AWS, Azure, GCP, SAS and container and every kind of cloud that like Mondo, I didn't even mention Mondo development cloud, etc. Look out for risk based prioritization. So we the contextual scoring, the context based access is, is something that you might not want right now, but certainly would be good to have as a feature in the future.
And make sure that if you if you do have existing IAM and PAM that a kind of Kim will integrate if you don't want to get rid of those existing platforms. And then make sure that, you know, automation supports just in time, the right sizing, and that there is some degree of remediation, not not huge amounts of remediation needed. Don't forget, this is about mostly preventative.
But also, and again, this is these are kind of nice to have usability and reporting, like most came as some form of reporting. But again, you might not need that for your own particular use case. But it's the more more comprehensive platforms do have that. What does Drake avoid?
Well, he avoids tools tied to one provider. Yes, very good. What are tools that perhaps overload you with alerts, I overload the administrators with stuff. And also the end users don't need to be have multiple windows or notifications telling them stuff when all they want to do is get on. So ease of use is becoming not just in Kim, but in every area, hugely important.
Just as the motor car industry has suddenly realized that sticking every control for a car onto a screen, which is hard to find and hard to adjust is actually a mistake, and are now going back to the old fashioned buttons and and dials because they work quicker. So think about what your users are going to go through, how you want them to get access, etc. And if there's no remediation at all, then avoid that. Having said, you don't need to have full kind of DR capability. But you do need to be able to stop the number one thing, which is privilege creep or privilege sprawl.
So I would say it is becoming essential to modern cloud security. And if you want to know more, you want to see the full market, the full vendors, the runners and riders, then please take a look at the leadership compass on the website, which is KupingaCole.com. And I'll leave it there. Let's just see if I can find a poll actually.
Well, excellent. 57% of you have said or 50% of people that voted, I should say, are thinking about it, but waiting for the market to mature.
Well, that's actually very insightful. Because I do believe it is a long way from maturity. But it's not so immature that I would say keep waiting. Then we're evenly split between 14% for people that said they have no need for it yet. We already use Kim in their path, which is good. Or we just simply don't see it worth investing in right now. So thanks for your questions.
Okay, I've got time for one or two questions. Chris Daly.
Hi, Chris. Nice to meet you.
You asked, will PAM be complemented by AI analytics? Yeah, I guess that it would. And whether the AI would be qualified or accepted as a higher level of assurance by compliance bodies, I don't know. But certainly AI is every single PAM vendor is looking at AI. But we have to be careful of the zero trust effect when zero trust was the kind of word of the day or the theme of the day a couple years ago, every vendor was adding zero trust to their software, but at least to their marketing.
So thoroughly investigate what this AI actually does for the product, whether it actually does provide a better level of assurance. Agentic AI, also Chris, is going to have massive impact, massive impact on not just multi cloud, but everything.
I don't think we quite yet realize or comprehend the level of the sort of coming storm of non or non human identities or machine identities, as I prefer to say, are going to have the impact they're going to have on the, let's just say, not the identity market, but the access management and authentication, which is actually, for me, the more important part of identity management, because I think, in a way, the coming of agentic AI means that almost the identities will become irrelevant.
So you have an identity, like say, pf.cookingthecold.com, that's kind of my identity, but it is almost meaningless, because what's attached to that, what is that identity doing, what is the context, and all these tools will hopefully use some kind of intelligence to determine whether that pf. at cooking the coal or a machine, which is literally a number, or a URL or something like that, has or is safe to allow authentication.
And yeah, sovereign identity, not so sure about distributed decentralized identities so much, but certainly sovereign identities having an impact on inter-cloud identity approaches, only really in that companies are more interested now in where their data is resting, who has access to it beyond their business, etc. So Chris, Daley, thank you very much for your questions there.
That, I think, is it for me. So once again, I will thank my producer, Oscar, out there in cool Berlin, who always keeps me on point, keeps me from saying anything stupid. Also Raphael for putting together those slides, as I said, it's the first time I've had, was it, Drake or Rake in there, but I was glad to see it. Thank you for listening. Thank you for watching. And I hope to see you all again soon. So from London, goodbye.
See All Locations
See All Locations