How many admin passwords are floating around in your organization right now? How many hard-coded secrets live inside scripts or CI/CD pipelines? For most enterprises, the answer is “too many.” Traditional PAM tools promised control, but in practice they’re patchworks of code that don’t cover the realities of cloud, SaaS and DevOps.
Credentials and secrets are being stolen faster than evera nd legacy PAM simply wasn’t built for machine identities, containerized workloads or hybrid infrastructures. The new standard is agile, converged platforms that combine PAM with IGA and EPM, using AI and behavioral analytics to close the gaps vaults can’t.
Modern PAM must go beyond vaults to focus on usability, scalability, and real-world applicability, such as detecting shadow IT accounts, mitigating insider threats, and securing third-party access. As competition and innovation accelerate, converged PAM platforms are redefining how enterprises protect their most critical assets and maintain trust in an interconnected world.
Alejandro Leal, Senior Analyst at KuppingerCole, will provide a strategic perspective on the state of PAM today. He will discuss why many existing solutions fall short, highlight the key attributes of a modern PAM platform, and outline how convergence across PAM, IGA, and EPM creates an integrated identity security fabric for digital enterprises.
Pranay Bhatia, Head of Privilege Access Management at ARCON, and Siddharth Venkataraman, Identity Security Head and SME at Mastek, will share real-world insights from customer journeys. Together, they’ll discuss how organizations are tackling key challenges such as secrets management, secure DevOps, and passwordless access. They’ll also present ARCON’s vision for converged identity platforms and highlight the capabilities enterprises should expect from next-generation PAM solutions.
Hello, everyone. My name is Alejandro Leal. I'm a Senior Analyst at KuppingerCole. And today we have two guest speakers today joining me in this webinar. So we'll let them introduce themselves and then we'll carry on.
Hey, guys. Nice to meet you. I'm from the Access Management Working Group for ARCON.
Yeah, hi, Alejandro. I head the Cybersecurity Services for Mastek. Nice to meet you. Awesome. Thank you so much, guys.
Moving on, before we begin, we'll just like to remind the audience just a few things to keep in mind that all of you are muted centrally, so there's no need to mute or unmute yourself. We will also be conducting poll questions during the webinar, so feel free to participate on those. It helps us with our research to know what you're thinking. And during the webinar, you can always ask questions. So if you go to the Livestorm Control Panel, you can ask a question and then we can address those at the end. So we'll try to leave around 15 to 10 minutes for Q&A at the end.
And then we will be also releasing the slides and the recording of the webinar in the coming days. So if you would like to go over that, you can just check our website in the next days. Okay. So as I said, I will begin my part of the presentation, and then we'll continue with Ranae and with Cedar, and then we'll have some time for Q&A. But before, here's the first poll question. So what is your organization's biggest challenge in managing privileged access today? You can take your time to answer that, but I will continue with some inspirational quotes.
So for years, PAM was built around the idea that if we could just vault every password and rotate it often enough, we could stay secure. But as organizations scale across hybrid environments, as they integrate legacy systems with cloud-native apps, and as they embed privilege into fast-moving DevOps pipelines, something becomes very clear, which is control alone is not enough.
So most of today's PAM challenges come from treating PAM as a product, something you deploy once instead of an operating model that adapts to your architecture, your workflows, the threat surface, and how your business moves forward. So in a way, we can say that the future of PAM is context-aware, it's identity-centric, and it should be designed to understand what's happening in real time. It's not just about storing credentials. And this can help organizations move from, let's say, protecting passwords to now protecting intelligence, so the behavior and the contextual signals that reveal risk.
So this shift sets the stage for everything we'll be covering today. But to understand where PAM is going, I think it's helpful to understand where it came from. In the early days, PAM started in the access control era, so it was a time, as I mentioned, when the focus was more simple, rotating passwords, recording admin sessions, and keeping privilege credentials in one place.
Back then, automation was minimal, and PAM, in a way, lived in its own world. It was separate from broader identity and access management strategies. Then came the cloud and automation era, where APIs and connectors began emerging.
Back then, organizations needed to manage privileges across SaaS and IaaS, so provisioning workflows became more automated, and PAM started to get closer to DevOps. But it was still very human-centric. And then next came the DevOps and machine identity era, where PAM now had to deal with ephemeral workloads, secret inside pipelines, containers, bots, service accounts. And this led to concepts like just-in-time access, zero-trust enforcement, and developer-friendly secret management.
Today, one could say that we're now entering the AI-driven PAM era. PAM is also converging with ITDR, which is something I will talk about later. It's integrating with KIEM, something also I'm going to talk about later. And it's becoming increasingly agentic. So it's about AI-driven contextual decisions, automated privilege enforcement, and also quantum-safe. Many organizations are starting to prepare for the Q day. So this evolution is accelerating more than most organizations realize. But in a way, there's an interesting paradox. Even as PAM evolves, traditional PAM demand is still very real.
Some organizations still need classic voting, session recording, and control admin access. But at the same time, the market is moving rapidly toward more modern, agile PAM. So systems that are designed for cloud and hybrid deployments built into identity fabrics with full support for non-human and human identities at scale. So in a way, this creates a bimodal market. Some organizations still buy classic PAM, while modern enterprises are pushing for cloud-native, NHI-aware, developer-friendly PAM. We can also talk about KIEM. So a few years ago, KIEM was a hot category.
But today, from our research and experience, vendors and customers rarely treat it as separate. So KIEM capabilities have been absorbed into PAM and NHI management. And the reality is that PAM is now a central building block of secret management and machine identity security. Not just a human admin control. I mentioned Identity Fabric a couple of times. At Coupling Your Call, we framed this PAM evolution within the Identity Fabric model. So Identity Fabric is not a product, so it's not based on a particular technology or solution.
But it's an architectural approach that unifies all identity services through shared telemetry, shared context, and shared policy. So you can think of it as a connective tissue that ensures identities are governed consistently, no matter where they operate. So within this model, here we can see PAM and KIEM. So PAM is not an accessory. It's woven into the fabric itself. PAM becomes a provider of real-time context. It interacts with IGA, with access management, with ITDR, device trust signals, analytics, etc.
So instead of bolting PAM on top of infrastructure organizations, embed PAM into the core identity architecture. So now, with that behind, we can look at the key market forces that we see today.
First, serial trust. So we're moving from vault-based control to continuous context-aware privilege protection that adapts based on behavior and risk. And we know, I'll have a separate slide on each of these four forces. But as we know, serial trust is about, you know, always verifying.
Second, we have non-human identities or NHIs. Service accounts, bots, and pipelines now outnumber human users by orders of magnitude. And they must be governed with the same rigor, or in many cases, even more as human identities.
Third, we see agentic AI. So we are entering an era where systems don't just follow rules, they make decisions autonomously. And in that context, PAM must also evolve and adapt by providing AI with control, monitor, and contextual access pathways.
Fourth, ITDR convergence. We published a leadership compass on ITDR two weeks ago. It's based on our latest research where 24 vendors participated. Many of these vendors come from the PAM. They have a PAM background. So I encourage all of you to check out our website and look for that report. And in the context of ITDR, what was in a way understood is that identity is now both the control plane and the detection surface. So in that case, PAM plays a key role in identity threat detection and automation response.
So together we can say that these forces are reshaping how organizations think about privilege access. So just to clarify about serial trust and expand a little bit, it has become a foundational concept in cybersecurity. But it's also widely misunderstood. We see some vendors out there labeling their product as serial trust. But in reality, serial trust is not a product. It's not something you can install. But it's more of a strategic mindset. Don't trust, always verify.
So at its core, serial trust means that every access request, every session, every workflow, every machine identity must be authenticated, authorized, and continuously evaluated. But again, it requires more than technology. It's not about rip and replacing what you already have, but about adapting your identity fabric and rethinking processes and policies across your organization. So every organization has a different, let's say, serial trust maturity level. We have also some advisory note reports on our website on how to assess your maturity level.
And there are also publications by, for example, the Department of Defense in the United States where they have a practical roadmap on how organizations can assess their maturity level and what they have to do to move forward. Now moving on with NHI. So these are perhaps one of the fastest growing identity types in the enterprise. They hold significant privileges. Often they run automated processes. And in many cases, they use static credentials. And that creates a massive attack surface. So addressing it requires a holistic identity framework.
So integrating NHIs into identity and access management, adopting identity fabric principles, and ensuring that both human and non-human identities follow consistent governance. Organizations, they also need to automate lifecycle management. Cross-functional collaboration is equally essential. So identity and access management teams, IT security, and development teams, they need to have a shared understanding of what accountability and ownership means. If we look at key tools, they also help enforce least privilege in cloud environments. Secret management ensures continuous rotation.
And as I mentioned earlier, and I will talk about in the next slides, ITDR tools can help monitor behavior, detect anomalies, and respond. So adopting this sort of integrated approach can help reduce risk while also supporting DevOps practices. In the next slide, we have agentic AI. So managing identities for agentic AI introduces a new category of, let's say, governance challenges. So with human identities, we can understand intent. But with autonomous agents, intent must be defined, it must be monitored and constrained through policy and behavior.
So in this context, having observability becomes critical. Organizations need to have real-time visibility into what agents are doing, why they're doing it, and how their behavior changes over time. So logs must capture not only the action, but the rationale behind it. Guardrails must be also operational and policy-driven. Permissions must adjust dynamically based on context and behavior. And finally, we must also protect the integrity of these AI models themselves. And in the next slides, I'm just mindful of the time, so I want to make sure that we'll cover everything.
So ITDR has emerged because identity attacks now span multiple domains. So traditional team boundaries no longer work. You could argue that ITDR connects both the identity side of things and the security side of things. Because IT administrators, they understand identity systems, but sometimes they lack the threat context. On the other hand, SOC analysts, they understand threats, but they lack insights into IAM processes and governance. So ITDR tools serve as this connected tissue between them. The real value is about reducing false positives to accelerate detection.
And I think that based on our research, the most effective ITDR platforms provide real-time monitoring, contextual analytics, and adaptive controls. And integrating with many tools like SEAM, SOAR, ITSM systems, etc. These are some of the findings. I'm not going to go too deep here because we're running out of time.
And also, you can maybe check the report instead. But our research shows that the products in the ITDR space represent different strategic paths. Some products lean more toward SOC workflows, while others toward identity and access management, and others toward automated response. So some solutions were more focused, let's say, on the prevention side of things, while others were more focused on recovery and response. So understanding these differences is key to choosing the right platform.
But again, effective ITDR platforms must integrate natively with IGA, with PAM, with access management, SEAM, SOAR, XDR, etc. So challenges and limitations. Despite the progress in the market, we could say that PAM still faces several challenges. So first is scalability. Large hybrid environments create enormous operational demands.
Second, we still have fragmented identity ecosystems. That's why we started this webinar, or at least my slides, with the Identity Fabric. Because many organizations use multiple directories, clouds, on-prem systems, and PAM, in a way, needs to reconcile all of these fragmentations, right? Then we see integrating legacy systems with modern applications remains a major obstacle.
Fourth, real-time processing at scale. That introduces performance challenges. So legacy PAM tools often can't keep up with dynamic workloads. And finally, PAM has historically had, let's say, limited integration with DevOps and cloud-native environments. But that's, of course, changing. But it still remains a challenge. So these limitations motivate organizations to explore more modern and agile PAM solutions. And this is my last slide, future directions and recommendations. So as we look ahead, several clear trends are shaping the future of PAM.
We're moving more toward more context-aware adaptive access control. We will also see deeper integration with DevOps and pipelines. PAM will continue converging with ITDR and expanding support for non-human identities. Identity fabrics and adopting this mindset will help you unify identity services and will help you ensure that PAM is not isolated but fully integrated into broader governance frameworks. Crypto-agility will also become mandatory as organizations prepare for the post-quantum era. And it's also maybe important to clarify the convergence questions between Keem and PAM.
So the convergence isn't between, let's say, PAM, Keem, and machine identity as separate categories. But the real convergence is between PAM and Keem. So two disciplines that are increasingly responsible for managing all identities, human or non-human. And together they form the backbone of modern privilege governance. And with that, we're entering a new chapter in how organizations secure their most critical assets.
And again, you should stay tuned because in the spring of next year, in the late spring, we'll be publishing our leadership compass on PAM. And that will be based on the latest research that we see in the market. So with that, we'll just have one more poll question, and then I will give the floor to Pranay and Siddharth. So the question is, how mature is your organization's PAM program? And with that, the floor is yours. So what me and Pranay have discussed is to give a point of view of being in line with the theme, which is going beyond the vault and move on from there.
So we just wanted to provide three scenarios that has very recent repercussions within the cybersecurity space, where the vault wasn't just enough and it required a combination of multiple aspects to take into control the overall privilege part. So the three things are three different attacks. One is with the UK government organization. The other one is a large manufacturing firm in the UK. And the third is a global retailer firm that has operations across the world. The common thread across these three are just that there were additional privileges resulting in privilege exposure.
But it all started with a valid credential and ended up with an unvalidated exposure that we are talking about. So you could see that in one case that there were local admin rights that were given in the end user computes, resulting in a huge data loss. In the case of this manufacturing firm, it's more of a combination of IT and as well as OT related accounts that looked into all these things, which could have mitigated the results a little better. And here it is not just a technology or a problem statement, it's more of processes in place, which is one of our poll questions as well.
Is there a way to continuously identify the newly created privilege accounts as part of your process design? And can we continuously vault it and control from a session standpoint so that we have a very clear view of privilege account discovery and credential reuse in place? So that's a scenario just to get the problem in space. Just going on to the next slide.
I don't know some kind of learning, but eventually I'll just walk you through what is a thought process on us giving a platform for not only doing a basic privilege access management, but even getting a context for you in terms of a complete identity and access management platform without data-centric security bundled in, which will have human identities in the form of interactive users, non-interactive identities in terms of NHIs, in terms of application identities.
Kim sitting at the top, doing a governance, a visualization layer for everything which is beneath it in the form of applications, assets, infrastructure applications, cloud applications, cloud assets, in the form of new age databases, cloud controls, Kubernetes access management platforms. Lifecycle management for the complete privilege users. It's typically not a privilege access management that we're looking for. It's a complete privilege identity and access management platform, which helps you to do identity access, governance, single sign-on, all of those use cases too.
Of course, as Kim has bundled down with Pam in the new age systems, EPM becomes one of the critical points too, because as mentioned by Sid, there are use cases where the number one threat attack vector for any new ecosystem intrusion starts from endpoints. Protection of endpoints with EPM to other use cases that are bundled along with a privilege access management platform. That really then pushes to the point where identity becomes the new perimeter.
We have our identity mesh that is a combination of machines, your users, your OT accounts, your applications, SaaS accounts, and then you have agent AI coming in, resulting in a complete mesh and the use cases to not only bring in zero trust, but at the same time ensure that the session hijacking is prevented, your credential thefts are prevented, any privilege escalation is always through the right channels and completely bogged down lateral movement.
If you look at the examples that were cited earlier, either of one was invalidated, resulting in probably a major incident within the organization, resulting in a huge loss to the organization as well. What we wanted to showcase was to integrate Archon's identity-centric platform, which was described by Pranay in the last slide. And tighten it with a set of processes, be it in terms of establishing privilege hygiene with respect to risk scoring, integrating it back to identity lifecycle governance, and have those visualizations with respect to cloud entitlements management.
So it becomes very clear of the context of identity itself, like what is a particular account doing and others. And also providing the right set of services, be it in terms of continuous assurance through MSSPs or SOC integrations, have validations in place to ensure that if there are additional privilege creep or exposures that are happening, it's monitored and it is immediately mitigated before it is leveraged by an adversary.
And therefore, the outcome that any organization is looking out for is to reduce mean time to detect identity abuse and mean time to revoke any additional privilege creeps that are happening within the organization so that everything is controlled within the blast radius in a very particular front. Thanks. Pranay?
Of course, yeah. The new age use cases now align around with not only human users, but even machine users, application users, and agentic AIs, which are doing a proliferation around everything related to information and machine-to-machine communication.
The solution has even abandoned application-to-application and agentic AI access control built up, which does a complete lifecycle of any identities in the form of application IDs, machine IDs, doing a governance for those, doing a layer of lifecycle management for those, and of course, interacting with the digital world, which not only does an access control, but even acts as an API gateway for you for doing up the whole use cases of more and more analytics on a contextual data-centric platform as well.
And just to add here, the context is not just the project, it's more of also having UEB and machine learning coming in to add more fringe use cases that needs to be detected upon if there is a major event that is happening and which is not usually controlled by the policies. Now, how do we combinely go with identity resilience? Start with the discovery, be it in terms of your privilege account discovery or your IAM accounts and work with that part. Build in the control layer, be it in terms of PAM or EPM or a combination of PAM, EPM, IGA, along with your identity threat detection and response.
And once this control layer is completed, start validating in terms of simulated attacks, in terms of attack path analysis or continuous threat exposure management with identity as a critical point of view. And bring in assurance layer with ensuring that the right correlation signals are integrated for SOC and there's a layer of ITDR that again comes back. And continuously optimize, be it in terms of analytics, automation, and self-learning entities within the Archon's analytic engine.
So the point is that the baseline is how do we find out exposure with Archon's UEBA ML solution, have a unified identity telemetry across NHRAs, machines, user accounts, agentic AI, which is your new use cases, have API integrations to ensure that there is seamless integrations going on further to make it much more seamless to enterprises to adopt this identity as a complete resilient function. Yeah.
So eventually, if you look at a broader landscape, right, what eventually does an organization want in order to not only protect, but even do an immediate response in the form of a complete identity detection and response? What's an identity behind a particular level of risk that is associated? Is a risk posture being signaled upon from various types of modules that are deployed within an organization? What's an intent in the term of an assurance, which is bundled, which typically allows you to not only detect anomalies, but give you an immediate response?
Are the signals enough for my access management platforms after spending a million dollars? If yes, those should be bundled upon in the case of a broader identity PO2. Is my endpoint being a bigger threat or my cloud applications being a bigger threat or my interactive users being a bigger threat? You need to have a visualization for that too. And of course, how soon am I able to isolate and respond to a better threat which is there in my ecosystem? That's the eventual goal that is typically needed across.
So we itself eventually help you to build across those use cases and help you beat across a complete identity data centric security platform. Right. So that will probably give a case in point of where we have jointly worked in helping one of the major organizations in improving their overall privileged access management and maturity and pushing them towards higher sets of maturity. So we wanted to start with what was in place when we were initially taking over. One was there was no active PAM in place. It was more of a solution where there is no password given to the end user.
So there was no vaulting. There's no session monitoring that was happening. Quite a flat AD in place, which means everyone was having a privileged access on endpoint privileges for their own tasks and making it more and more riskier and with risky local privileges at the UC devices. Lack of process maturity in terms of how do we control the real privilege accounts with limited set of visibility and as well as legacy devices coming into play for the volume that has been suggested over here.
So considering this was our starting point, what we created was a journey for them where we were able to combine both PAM and EPM and implement them and run for the customer, which includes setting up the policy processes, integrating with critical systems, an agile way-wise onboarding of all your target systems in place. Similarly, do something similar from an EPM standpoint.
Figure out those apps that have to be whitelisted as part of regular day-to-day operations for that particular community and have that as part of your baseline policy itself, saying that these are your listed accepted applications that would be running or will be allowed to run on endpoints. And then use way-wise rollout. But then every transformation was never smooth. It was always hurdled with our own set of problems and challenges. So definitely one is not a huge asset inventory was given at the first place, which we talked about. A good amount of legacy devices that were there.
So how do we go about managing the session monitoring for them? How do we do noisy end-users? So we are touching VIP users. We'll be touching DevOps users who wants to look at time-to-value and time-to-market as more important than the security control itself. So how do we manage them? So that's where what we were working out is to leverage the proper discovery scans, which is a combination of not just automated, but as well as validation through manual controls in place. Have baseline policies and processes created for PAM as a foundation itself.
Vault all legacy accounts so that it becomes, if there is a timeline to reduce them, we can go ahead and decommission them or migrate it to a newer set of endpoints. So we have a very clear organization change management in place, especially from a communication standpoint that a particular set of community is going to be affected when we roll out EPM in this place.
Yeah, Kiran, do you want to add more? Yeah, what we eventually wanted to focus more about is this is typically not a big bang approach, right? Because there are different personas, there are different people within the organization, ranging from employees to VIPs to tech ops across a distributed environment. So what we typically bring about is it's a face-to-face approach on how a particular process needs to be put up in the form of going deeper into the use cases and typically minting those within the product ecosystem and being at the same side available to you in terms of a goal life.
So it typically covers a wide area of ecosystem across a distributed geography and of course helps you to meet your BAU operations in a much better manner so that your existing work is typically not affected from an end-user perspective. So what was the point of departure?
So we started with almost no PAM to no process to what we arrived at or what we have reached to the organization is a robust implementation of PAM, which is completely scalable with automated session monitoring in place with blacklisted commands so that anything that is blacklisted automatically triggers the alert back into SIEM for automated responses and remediation.
The EPM solution so that there's a clear white list of target systems along with the applications based on persona so that a VIP user may use a different set of applications to what a DevOps user would use and what a normal user would use. So it felt seamless to them when it comes to adopting EPM itself. Establish clear policies, mainly in terms of how do we identify new discovered accounts? How do we ensure that these accounts are vaulted and create a lifecycle management for the newer set of accounts or the privileged accounts that are coming into play?
And for high volumes, it was always implement OCM, continuously train the end-users. So PAM is never seen as an obstacle to the DevOps team or to your infrastructure team it's more of how do we course correct them and make sure that the adoption comes into play. So it's communication, having a solid OCM plan and working with your end-users in the training and training them in such a way that they adopted rather than using your traditional ways of working.
Yeah, it's of course moving because that's a typical in terms of access management platform. The important part about this is that we typically have to move beyond, as mentioned by Dameem, it's of course moving beyond the normal access management in terms of credentials and everything towards a more adaptive framework for a multi-adaptive MFA going across with AI embedded within the platform which helps you meet a self-adaptive contextual model which typically help in the PAM and the EPM ecosystem to scale up. For example, at day zero, you cannot apply a whitelisting, right?
It learns on the user personas, what the user is doing, what recommendations the user have in terms of an administration, establishing policies in terms of what is the best governance and what is the best access management that could be applied in terms of a BAU operation. And of course, at the product standpoint, you eventually learn in terms of what the user is or what the module is able to do at a wider ecosystem in terms of better signals, in terms of risk profiling and better signals in terms of MCPs too. Right. So what was in it for the organization?
So improved the PAM maturity over a period of 12 months, became much more robust when it comes to operations, 100% SLA delivery so that it becomes much more meeting the deadlines and as well as ensuring that if there are any major incidents or policy violations, it is managed right then and there. Therefore, it becomes much more seamless for the customer.
Improved account visibility and protection where we had leveraged Archon's visualization layer just to give a fair view of specifically from a privilege access management standpoint on the entitlements and the accounts and the mappings to users. So it becomes a very clear view to the organization to understand what type of risks and what type of user risks are carrying and how are they getting mitigated. And vaulting has always been a continuous process. 95% of vaulting achieved for the identified accounts that we have. So it becomes much more seamless.
Therefore, to the organization, it's definitely a reduced cyber insurance premium. It's something that directly impacts enterprises when a robust PAM is implemented. A complete coverage of EPM and PAM put into place with increased maturity. And with automation, it made it much more easier for us to onboard a lot more target systems and work it out. Now we are continuing with the journey, bringing on ITDR and other aspects of identity mesh security so that identity is traditionally not seen as an outside part. It's more of a boundary for organizations to look at it from that perspective.
Yes, of course. So what at the broader footprint that every vendor, every platform is looking about is moving away from hard-coded credentials, credentials between applications and all of those through tokens. So there is, of course, a vault for all of our applications, which are not being able to move to a token-based ecosystem. But of course, at the modern application layer, in terms of cloud applications and everything, everyone has moved ahead in terms of a vault.
And everyone is moving more towards just-in-time tokens, ephemeral co-tokens, HTS tokens, all of those, which typically helps us to move more towards diving deeper into a wider footprint of coverage. And of course, increase more maturity in terms of how better a signal can be adopted in terms of a complete threat detection response framework.
Of course, there are some points on KEM2, which helps us not only relate to a single cloud platform, but a multi-cloud platform and a hybrid cloud too, which gives all possible signals of the cloud infrastructure and entitlements management platform and then hook those into the access management platform. That's actually what we have for today. Thank you so much for such a well-prepared presentation. I think now we have some questions already in the chat. But before, just quickly, we'll share some of the latest research we've done.
As I said, we published our leadership compass on ITDR. We also have some good reports on how to bridge DevOps, NHI management, PAM, and KEEM. We have the PAM LC from last year. But as I said, we'll be doing a new LC in the spring of 2026. And we also have webinars on identity fabrics. We will also be having our EIC conference in Berlin. You can still submit proposals. And here's just more information on our research webinars and advisory. So if you have any questions, you can always reach out to me, or you can reach out to Pranay and Siddharth if you want to discuss more things in depth.
But now let's talk about the questions. So we have some questions already in the chat. I think Pranay already answered one of them. But maybe you guys can expand a little bit more. So one question is, do you imagine there is a world where PAM moves toward being a password solution instead of using credentials and bolts?
Yeah, my immediate thought process was yes. Because of legacy systems, legacy apps, there could always be a vault in terms of a credential broker and all of those. But the new age platforms are typically now working with tokens being embedded into the platform. So you typically just move away from a vault as a service to just being authentication as a service through token-based platforms. Yeah.
I mean, on top of it, it also has to, when we have users coming into play, we have to bring in a lot of more context outside of it. It's also from a zero trust standpoint, whether he's from the trusted device with the trusted GOIP, so that the right set of data is coming in. So I think maybe for machines to machines, the answer is probably yes. And for NHIS, it is probably yes. But from a user standpoint, it might still be extended, maybe for another two, three years, at least. Because that's not going to be pretty straightforward for everyone to pick up the context and start working on it.
At least that's my point. Absolutely. That makes a lot of sense. We have more questions here before we wrap it up. So one question is around the machine identities. So the question is, visibility into all machine identities remains a major challenge for a lot of organizations. What would you say is the first step organizations should take to map their machine identity landscape? From my perspective, if I can quickly jump in, I'd say that is to have an inventory.
So the right starting point is to have, let's say, discovery and classification processes that cover all the environments of cloud, on-prem, and DevOps. And that would mean to scan for service accounts, API keys, certificates, tokens. So I guess once organizations have this visibility, the next step is to categorize these identities by risk, function, and lifecycle maturity.
But, of course, every organization has a different approach to this. But I'm interested to hear your thoughts on this.
So, Pranay, you want to go? Yeah. So basically, the same thought process is more towards diving into discovery, where the application IDs, machine IDs lie, what communications do they carry?
And, of course, knowing the traceability of where the communication floor is and all of those. And typically allowing them to go towards a secure access control of what scope does the application carry, what scope does the machine ID carry?
And, of course, at the same time, if there's an API gateway available, it becomes a complete machine-to-machine communication with a layer of application gateway. Yeah. I'll probably take a slightly different approach. Everyone says that we need to have assets in place or the asset list or CMDB in place. But we know for sure that 100% of every organization in this world do not have the best of CMDBs. They probably are at, say, 50% accurate. That's the max that they were able to achieve. So it has to be a combination of continuous discovery.
And this is from a services angle standpoint, which means that shadow IT assets have to be discovered because that's a sprawl that cannot be controlled by any of the services. And that's where your major attack vector starts with. So it is a combination of outside IAM that we'll have to step out from an external attack surface management, identify if there are any sprawls in IT shadow assets, then create the list and then move towards it.
So it's just left shifted a little bit and then use that as an input to start working on the context that makes it much more helpful to most of the organizations. Yeah. Thank you for sharing that.
Yeah, I think you cannot secure what you cannot see. But second question, slightly a different topic. The question is, what challenges do customers face based on your experience when extending time to multi-cloud environments and how do you help solve them? So let me take this, Pranay, and you add more to it. So cloud has always been more of what should we say as a continuous adoption. We saw that initially data centers to cloud was the first carpet. So we probably chose AWS or Azure. And then because they wanted to have further functionality, they started spreading it across GCP everywhere.
So one of the problem statements that most of the enterprises have is that I still have some of my Microsoft Windows server licenses in on-prem or in a particular system in place. How do I transition it smoothly without any major cost imperative? And at the same time ensuring that the transformation or the migration is smooth when you migrate workloads from one point to another point. That has been one of the major challenges that I've seen with respect to this one. And second is definitely on cloud entitlements management.
So how do we combine what we have in PAM with the newer entitlements that each and every cloud service providers are bringing in to create a holistic view of the attack surface with identity as well. My view is slightly more from a perspective, the same thing that I've done on-premise, you cannot extend it to cloud. Because if that becomes a lift and shift and you typically not are able to scale across. In terms of new age, because it's typically a different world altogether, you cannot do a lift and shift.
It's typically new thought process that looks to be bundled in new set of entities, new set of applications. The nature is sometimes different, sometimes the same. And in cloud, typically you want the solution to be scalable. You do not want the solution to be not being able to meet your simple basic use cases using a farm of servers or something. So you need to have something which is quite linear to you, available in a multi-cloud environment, talking across different cloud platforms, across tenants, across regions.
And at the same time, we do not want any latency in terms of scalability and reliability. Absolutely. Thank you for sharing that. I think we have time for maybe one or two more questions, but there's a very good question in the chat. So if you guys can take a look at that, I will read it, but you can maybe read it on your own at your own pace. And it's a good question. So the question is, in real world enterprise, do most privileged breaches still start with a compromised human account, or have they shifted to machine slash workload identities? Even the tools sprawl across traditional PAM?
You can go for it. Give me the first question. So I think it still starts with the human account. That's what has been in the news of late recently. But while it starts with the human account, the privilege escalation and lateral movement is always with a machine related account. Because there is definitely something that is accessible at the server layer from that endpoint, which is not protected. That is definitely the bridge for lateral movement, be it within a segmented network to moving from IT to OT side of the story as well. That's definitely where we are at this point.
I do have a similar approach. It starts from a human account on a certain level, either due to a compromised human, we can say an interactive account. Which could be cloud-optimized, any account. And it shifts more towards proliferation using these accounts. For example, access keys, API keys, hard-coded within the applications, available in configs, available on my endpoint laptops. So the proliferation starts across lateral movements, starts across with these non-interactive accounts. And of course, once you are in, it's typically available as a complete attack service.
It's a combination of both interactive, non-interactive account proliferation. Yes. I want to make sure that we cover one more question before we conclude the webinar today. How do you see the PAM market moving forward in the next one to two years?
I mean, of course, it's hard to predict. And again, we'll be conducting further research on this at KUPPINGER call. So you better stay tuned for that. But I'm interested to hear your perspective on that. How do you see it? The PAM market in the next one or two years is solidly looking into a layer of convergence. The convergence has typically been there in the last 10 years, just by acquiring solutions or something. But of course, convergence would lead to a solid threat detection response.
And with the new agentic AI bundled in within the platform, the thought process has become much more linear, saying that all interactive, non-interactive access for privilege would be done through PAM. I think the next one year people will slowly adapt to it in the form of full use cases. And the second year would be more related to a complete shift in terms of what use case does that particular thing carry with MCP and other deep AI related use cases of GPDs of the world being compromised and all of those. So mine is also pretty similar to what Pranay has mentioned.
So it is going to be a consolidation journey, and it could be a combination of existing solution providers bringing in natively or acquiring those from the market to ensure that they are stitching a complete identity fabric, like what Archon is talking about. So it's in that line or in that thought process that is going to happen. And on top of it would be your ITDR, code and above. So ITDR is more of just a detection and response scenario, but never really looks at it from a protect standpoint. So that's where the journey is about. Final question.
If you could talk to a CISO of an organization, what will be the main takeaway of today's webinar? If you had 60 seconds to talk to the CISO.
Yes, sir. Okay, so, so there are ITDR solutions which are claiming that there's no need for PAM. That's not the way we approach things. It's always defense in depth with protect and detection layers working together to get a coherent point of view and identity should be considered as a perimeter in itself with multiple contexts added to make it much more safer. That's it.
According to me, talking to a CISO would be after spending millions and millions of dollars, how soon are you able to trace down or how soon are you able to protect an identity when there's an identity theft attack or something. Awesome.
Well, thank you guys for such a fruitful conversation. I appreciate all the comments, questions and insights.
And again, anyone from the audience. If you have any further questions, feel free to reach out to me. Thank you very much and have a nice day. Thank you. Have a nice day.
See All Locations
See All Locations