Thank you Alexei and thank you Eleni. I like the talk and I dare to say if I have conversations about the same topic three times before noon on the same day at EIC, then it's a very relevant topic. And I had already two one-on-one meetings or one grouping, one meeting that has popped up. We have to talk here. I had a couple of other customer talks and yes, I think we have something to solve, to solve well. And I like the ideas, especially because Eleni's presentations always are way more structured than mine. So that's something really to look at.
So I'll talk a bit about my recently published Leadership Compass on Enterprise Secrets Management, or if I take the full title, Enterprise Secrets Management for Humans, Workloads, and Things. So I try to split up that term of non-human identity a bit and avoid the machine identity. So I'm not a believer in machine identity because a machine makes noise and moves and so on. So I would say if machine identity is probably closer to things than to workloads. And workloads probably is more precise than what we use in some other areas, but it's terminology. We need just to understand what we do.
What we did was this Leadership Compass and it caused quite some interesting discussions with the entire industry. We took an angle and I think for our Leadership Compasses, there are always two ways to look at it. The one is we look at a defined market segment and say, okay, what are the solutions in the market? How do we compare them and how do we see them? Or we take an angle of what is the customer challenge?
And interestingly from customers, from enterprises, we hear quite a lot that they say, okay, there's this problem of managing secrets of whichever type that pops up at many different places. And we don't want to end up with many, many, many different solutions, but we want at least to look at what can we do in an integrated manner? Where do we maybe need specialized solutions? And I think it's a mix and match nowadays anyway, with all that innovation in this non-human identity management space or workload identity management space, where we see really a large number of new vendors appearing.
Many of them, I have to say, with very, very attractive solutions, very interesting solutions, covering certain aspects, sometimes more, sometimes less of the topic. But from an enterprise perspective, there are other types of identities and there are a ton of secrets. And so we have a problem and we looked at it more from this sort of holistic perspective of various types of identities, various types of secrets, and I don't claim that this is by any means complete.
And these things appear, so I remember with one of our advisory clients a while ago, we had a conversation, they have a lot of smart cards and various form factors, they have X.509 certificates, but they also feel okay, there are the FIDO2 tokens appearing right now, moving to PaaS keys. For PaaS keys, then interestingly, the next question comes up, also part of this management, how can I, as an enterprise, really use PaaS keys? Because the standard PaaS key approach, put them everywhere, doesn't work for an enterprise. You want to have it on devices that are under your control.
The device-bound approach doesn't work, because users might have more than one device. So you need to figure out ways, and this pops up every now and then, and yes, you can figure out here a solution, there a solution, etc. We looked more at what is a really sort of a more integrated, comprehensive offering. We will come up with a separate leadership compass on workload identity or non-human identity management or machine identity, which ever term it will be at the end of the day. That is work in progress, and one of my colleagues, Nitish, is, I think it's Nitish, working on that.
So there will be a separate one, which then really comes more from this specialized pillar. This one will have more of a broader perspective. And there's another, sorry, I go back. There's another holistic element in that. By the way, the clock isn't ticking here, but I think I have the time here, so it's no problem. Usually in the preview screen, you see how much time you have left, and it helps. So the other thing is, however you paint that life cycle, and I don't say this is the life cycle for that, but you really can come up with a life cycle. And secrets, they are created.
You need to discover them, especially in that world of workload identities. In workload identity management, we have the big challenge. So for classical secrets, we tend to have identity management processes where at some point these evolve. When we look at things, then we have certain approaches for commissioning, for instance, secrets to things. It's way more challenging in an agile environment. And this is, I think, what makes the workload or NHI part so interesting.
We deal with something which is very dynamic, very agile, coming from agile software development and DevOps and so on, and very much at scale. And in that case, things pop up, they appear, and we need to understand what is happening there to discover them, to build sort of an inventory understanding where they are. Maybe also discovering them in areas where they shouldn't be, which is another interesting point. So AP tokens and Slack channels and stuff like that.
Also, we need to understand that, because otherwise we can't protect what we don't know. Very simple. Classification, vaulting, putting them into vaults potentially, and also working with vaults. And I think very important, especially when we look at this non-human identity thing, you can't go out and say, okay, you have to use this vault, because yes, there are the HashiVaults out there. There is an AWS vault, there's an Azure Key Vault, and they will be used. So you need to find out ways how you can gain control about that. Ownership management, an interesting element.
So how to understand the relationship between secrets and humans, and maybe humans that are responsible for that can be quite interesting things. Posture management, well secured, not so well secured. Monitoring, that goes back to those of the inventory and discovery element.
Rotation, that's also where quantum safe encryption and stuff like that come into play. So when you know your secrets and then you know what, so in which state they are, then you know what you need to replace, if and when the sort of the quantum decryption, so to speak, becomes a real reality. Probably we'll see first some edge use cases of some sort of state-sponsored attacks for certain edge use cases, and when it will appear as a mass problem, I think that will remain to be seen. I'm honest, for me, I sometimes feel this thing is a bit like fusion energy.
So we can be pretty confident that someday it will be there, but we believe the same in 1960. It probably will not take as long, but it's extremely difficult to predict when this will become a sort of widespread user reality. And I think sometimes it might be, I think we need to be prepared, absolutely yes, but I think it's also partially overhyped. And we need to decommission secrets, good approach. I think the same like legal processes, and like we are horribly bad in legal processes and identity management, we probably are also horribly bad in decommissioning. Secrets.
Anyway, when we look at the market, I think a fair assessment is that the majority of solutions is focused. Probably I should have phrased it a little more friendly, but limited in coverage, but saying, okay, it's focused on certain aspects, reads better. Sorry about that, but it's identity types, secrets types, stages of the secrets management life cycle. And I think for you as a potential buyer, it's very important to understand what you need and what solves your challenge and maybe what fits together.
So when you sort of build a, it's ugly to build three-dimensional matrixes or cubes in that case, because you have three dimensions, but at the end of the day, you can clearly then say, okay, look at who does what in this and what do I get from whom and what are the gaps I need to fill? So you can at the end of the day, clearly fill such a pattern and analyze where are the things I need to fill? Also not only asking what is missing, because you just not may need it, then you don't need to address it.
But for the things you need, you should can, I think basically on the three previous slides, come up with something that already helps you here. Because at the end, you mostly will end up as a combination of tools, not as a single tool here. And I picked up a really old picture I created a couple of years ago, which is a bit just looking at, and I think just to illustrate how important this theme is, looking at the cycle. So and back then, it still said something like credentials in avertedly shared in repository.
So basically, I just added non-human here to the slide, which I created a couple of years ago. I could have also in a repository set slack channels and walls and stuff like that. But at the end of the day, it's still the same.
Clearly, we have other problems in DevOps, like standard libraries open to attacks or to bugs, malware injected somewhere. Inadequate security for access to infrastructure. That brings us back to secrets, by the way.
CI, CD management tools and protected service. And here, we have NHI management.
Here, we have probably Keen, which is what a type of solution we have. PAM. And we have IGA as well. So who can access it? Other privileged users. There should be, yeah, cybersecurity comes up over there. Software security, cybersecurity and IGA. So a couple of different technologies are needed. But at the end of the day, we have various types of challenges we need to address. And managing secrets is really relevant across the place. It's not just one single technology. I think this is basically the story of this picture.
There's more and there's even more beyond secrets management you need to look at. You need to really take a broader perspective when you, even when you just look at the DevOps field. So an NHI management solution will help you, but it won't solve everything. There's more around. And by the way, if you take Keen, I don't know how familiar you are with Keen Cloud Infrastructure Entitlement Management, one of these acronyms that not necessarily fit well to what it does. I think the better term could have been NHA, Non-Human Access.
So which services have access to which resources, which entitlements. So then you have Keen, Non-Human Access, and you have NHI, Non-Human Identity Management. What is the logic? There should result a non-human IAM, if you're with the term non-human here. But at the end of the day, some convergence, I think evolution in this market is logical and it's also very typical here. So what are some of the key findings? We looked at really decentralized solutions. We know that poor secrets management leads to risks. I think this is a no-brainer.
It goes, comes from different dimensions. So we have the traditional enterprise key certificate management market, which is moving in one direction. We have NHI coming from another direction. NHI is really interesting due to scale and the dynamics in that. We need an integrated lifecycle management, especially an integrated governance. We need automation, especially when it comes to larger scale things, be it SYNC, be it ResearchServ, or be it non-human identities. And especially all the stuff which pops up and disappears quickly, like around workload identities.
We can't handle it without automation. The humans are just too slow to do it in any other way. So we need to do it. We see the convergence.
We see, or expect, integration with DevOps tools. So these are some of the things. And basically, we could differentiate between different types of solutions here. Like the ones coming more from a human identity perspective, the ones with the workload non-human identity perspective. Some are really strong and more device or SYNC identity, which is a fascinating topic.
And with, I would say, some room for improvement in some areas. So because I think it's still working relatively halfway okay to roll out the secrets to a physical SYNC device, but look for proper update change processes or other things. It's basically just reprovisioning it. So there's still a huge room for improvement. Discovery lifecycle management, so the tools that are really more focused on discovery life cycles. And then there's also this PKI and cryptographic key management element which comes in. So the solutions come from different angles.
And to be very clear, it's in such a leadership compass, when we look at it from a huge holistic perspective, then vendors are frequently super good in a certain area. But they are not the top leaders here because they are the specialists for certain areas. So that's the reason why it's very good then to read the full 70 page or so report or look at the details. There are many details. There are spiders for every vendor looking at where are the strengths. You will see in this leadership compass, for instance, that the spiders are very edgy.
So some strengths, very few vendors that have strength area. Most vendors strong in one or two or three areas, which helps you also identifying what is your problem, which vendor might be really the specialist here. So go through that. Never just look at the main picture. That's nice, but the value for you as a user comes when you go into the details. And that's why we have these long leadership compasses with a lot of information. So in that case, from an overall perspective, I think we see a bit cyber argue ahead, which comes just from the fact with their Venafi acquisition decision.
They added, so they are very strong in the human part, more from a privilege as access management perspective. They had already something for DevOps world. They added Venafi. So in that combination, it gives them, I would say, quite some breath compared to others. But we see a couple of other players and it's an interesting mix of specialists coming in from different areas, but also the PEM vendors moving into the broader world of non-human identities, etc. Plus specialists like, if we go to the left, Cryptomatix, which are super good in dealing with PKIs and stuff like that at scale.
So very specialized. And all of these vendors have definitely a right to win, depending on what your need is. When you look a bit deeper in the product perspective, I think there's one thing I highlighted yesterday as well. If you just look at the size of the, or the height of the challenger box compared to the leader box, it also makes it clear, none of the leaders is, so to speak, at the very top of the leader's box. So we were able to cut it for readability, which means there's still room in the market to improve.
And in this context, by the way, it might be also very interesting to look at our rising star reports, because several of the players, the specialized players in these boxes are not yet the leader in enterprise secrets management. They may have a strong potential to become a leader in the workload or NHI leadership coming out later probably this year. And they are what we consider being a rising star, someone who has a strong innovation, a strong product market fit. So also look at the other types of research we have.
As I said, this will be soon to come. We have maybe time for a question. And thank you for listening to me. Thanks for the talk. I think it was very interesting. And personally for me, it's been a discovery on non-human identities. Everybody has, I think many of you have mentioned, is trying to sell the next shining thing outside. But how much of this is process and how much is tooling? Where is the balance if you really want to do the 60-40, 50-50? I know I'm asking a very ambiguous question. It's a good question.
I would say the majority of conversations I currently have around this is about how do we, especially when we look at the non-human identity management part, we have at least, at least in the best case, we have two worlds to work with together, which are the identity security people and the development people. And then a lot of process organization, building understanding, all the other stuff. This is really the main thing.
Otherwise, you can throw a technology on that, but it will not be sufficient. So I would say it is, at the beginning, it's probably 100-0 in building, really bringing the teams together and understanding. You can't go out and bring a technology and say, okay, you're not allowed to use HashiWallet anymore. It will not work. We need to figure out how we get control, how we shift responsibilities, do it right. And this is, at the beginning, it's talking, working on that, and then technology arrives.
I can't take further questions because my next star is talking in four minutes, one floor below here. Well, thank you very much, Martin. Thank you.