Most enterprises can tell you the number of employees they have, but I think very few can tell you the number of machine identities they have in their environment. And that becomes dangerous because NHIs often accumulate privilege silently over time, and eventually you end up with machine identities holding persistent access across multiple systems.
So considering PAM being a key component for solving the overall area of NHI challenges, I think that is fair to say that PAM will play an important role, not the only role, but without a proper PAM solution, you might not get a grip on your NHI challenges. I believe that the organizations struggling most are usually the ones that are still treating PAM as a vault deployment owned by a small infrastructure team, security team.
And I believe that the organizations making progress are the ones that are shifting that mindset and treating privilege as a continuously governed operational capability across the entire identity ecosystem. Welcome to the Kupinger Coal Analyst Chat. I'm your host. My name is Matthias Einblatt. I'm an analyst and advisor with Kupinger Coal Analysts. Today we want to pick up on a topic that we covered a few years ago already, way back then with my colleague Paul Fisher.
The topic has changed, the analyst has changed, everything has changed when we talk about the topic of privileged access management. And for this, I welcome Alejandro Leal. He is the author of the new research on privileged access management. Hi Matthias. Thank you for having me. Great to have you. And when I say you have picked up the research in the PAM area, you've published quite some documents around this right now. So these documents are just out, they have been published along with the EIC conference because it is identity management, it's cybersecurity, it's privileged access.
So first of all, before we go into the details, how did the topic evolve for you? How did you approach it? What has been your approach as an analyst towards the changing market segment of privileged access management?
Well, I think a lot of things changed. For example, you mentioned the report that I just published, so the leadership compass on PAM. In this version, we had 36 participants, I believe around 10 more than the previous report. And I saw new entrants and new, let's say, well-established vendors that recently made acquisitions to enter the PAM space. So there's a lot of momentum. And I also covered vendors from all over the world.
I've done, I don't know how many you'll see so far, but I think this one was perhaps the most diverse in terms of geographical location. So we had PAM vendors from China, from the Middle East, from South America, from North America, Europe. So one of the, let's say, main challenges I had at the very beginning was to define privilege, because as you mentioned, the old, let's say, PAM model assumed that privilege was tied to a small number of non-admin accounts. So you had a domain admin account, root account, and the problem was mostly about protecting those credentials.
So vaulted the password, rotated, monitored the session, recorded the activity. That model made sense when infrastructure was, let's say, relatively static and most privilege operations were performed by humans.
Of course, those capabilities still matter, but that assumption no longer holds because today, privilege is distributed across APIs, cloud roles, service accounts, CICD pipelines, Kubernetes workloads, et cetera, et cetera. So the question is no longer, is this account privilege, but more about what can this identity do right now in this context? So the way I defined privilege was more about, let's say, less about who holds an identity and more about the ability of an identity to perform actions that affect systems, security controls, infrastructure, or other identities.
So in this sense, privilege is less defined by who holds a specific account and more by what an identity is capable of doing. Right, but when you say that, and we've seen that in earlier editions already, but this really has been exploding more or less. There's also changes where privileged access management actually is located, where it needs to sit, where it has to run. So we are no longer on-premises and with traditional software systems that had changed before as So we included key capabilities or something like that.
But right now, it's much more about monitoring identities and the processes they represent at runtime, wherever they are. And that is everywhere. It's in the cloud, it's in, as you said, in all these virtualization platforms. So you need to have PAM components everywhere. So we are moving towards a more hybrid PAM already?
Yes, and before I get into that, there were also two interesting insights, let's say, that I found out during my research. So one is that for organizations that build, let's say, PAM around the traditional features, in a way that creates a visibility problem, because most of them do not really know where privilege exists anymore as they continue to scale. So they know where the vault is.
They know, let's say, which human accounts are on-border, but they lack the visibility into delegated cloud permissions or inherited entitlements. But something that was interesting from this is that in the leadership compass, there were three to five vendors that just focus on small, medium enterprises. And what they told me is that a lot of the SMBs here in Europe or in other parts of the agentic AI, but many of them just want the vault. Many of them don't have large IT teams, identity teams. So they just want to get the basics right. They want to get the foundations right.
So for many of these small, medium enterprises, all these talk about NHIs and AI agents, in a way, it's a little bit of a background noise. Of course, they have that in mind, but they just want to get the basics right. And the second trend is a change in, let's say, architecture. So a lot of these vendors now understand that there is a deeper convergence with the broader identity and security ecosystem. So BAM is now less isolated and it's more integrated with IGA.
In a way, there's some convergence going on there with Keem, ITDR, SIEM, SOAR, etc. So we're already seeing this in the market. Vendors are adding cloud entitlement management, secret management, ITDR. So I think that BAM is becoming less of a standalone admin security product and organizations are adapting quickly. But going back to your question about hybrid, I'm interested also in what you think here, because you recently told me that you're doing some work around advisory. Right.
Yeah, absolutely. And I think this is really a changing market. So even customers or prospects that we are talking to, they are not in the first generation of BAM. They need to adapt to a changing infrastructure world and they need to have the right tools where privileged access actually happens. And that is in AWS. That is in Azure. That is privileged accounts towards a SaaS environment. So it's really no longer just the traditional BAM that we know, session management, vaulting, etc. That is foundational. Absolutely, they need that.
But they need the same type of functionality, but translated into a cloud world. And that often needs, even on the vendor side, as far as I can see it, adding capabilities that have not been there because it's implemented differently. It's controlled differently. It cannot go through one single session management tool because the sessions happen everywhere. So it's really an expanding universe of privileged access management capabilities. And the second thing that you've mentioned holds true as well.
So the deep integration into an overall security infrastructure and in an overall IAM infrastructure, what we call identity fabric, is essential because ideally BAM focuses on what it does best and it consumes everything that other platforms do well. So human lifecycle management for humans using privileged accounts can be inherited from IGA. And reporting can be delegated to Seam, SOAR, or I've talked to our colleague Matthew about the AI SOC. There is a deep integration for that as well. So it's really like a spider in the web that consumes and provides capabilities from an overall fabric.
And I think that is really interesting. And the same holds true for the BAM itself, adding these new capabilities that need to be provided and consumed as well. So to have an overall hybrid BAM. But now I've been talking a lot. That is what we see from the requirements that we see in any type of organization. And it's interesting that you've mentioned the smaller ones that just want to make sure that they do the basics well. So that's really interesting.
And before you jump into the next question, I think that from what I hear, the challenge is that many organizations hear the phrase identity fabric, and they assume they need a fully mature identity architecture before integrating anything. And I think that's not realistic. It's not how we discuss this concept of identity fabric. So you don't need to have a perfect maturity to gain value from integration. But you need a reasonable, stable identity foundation.
So you don't need, as we've been talking in previous, or you've been talking in previous podcast recordings, that you don't need to add the latest technology to your existing infrastructure. You just need to be able to connect all the dots, to orchestrate them, to have a more signals-driven approach. So you have a strong identity foundation from the very beginning. Exactly. That also means that you can, and you typically will start with a lower level of maturity, which is perfectly fine. And such a fabric helps you in taking the right next step.
You won't move from maturity two to maturity five, all automated, all well. Nope, that won't happen. So it's really a continuous improvement process. And if you have a proper lifecycle management in your IGA, and you can inherit that, that really helps you in admin processes for PAM. So if a person is no longer with the organization, maybe there shouldn't be account for that person in the PAM system. So that is what I mean by integration.
So yeah, that's really clearly reflecting what we see also in the market. It's more cloud, it's more modern technologies. We'll get to that later.
And yeah, it's really an evolution of a security platform that was a bit boring five or eight years ago. And it is key and center for security infrastructure just right now. But back to your research, what was striking for you? What was added? What has been added to the set of capabilities that PAM now serves?
Well, a lot of vendors are starting to integrate some of the Keen features. But there was a lot of talk on agentic AI. And NHIs. And from what I get is that the biggest mistake organizations do is that they still treat NHIs as, let's say, technical artifacts rather than identities with operational authority. So service accounts, API keys, workload identities. They're often created quickly to solve, let's say, instant operational problems. But then they're forgotten entirely. And most enterprises can tell you the number of employees they have.
But I think very few can tell you the number of machine identities they have in their environment. And that becomes dangerous because NHIs often accumulate privilege silently over time. And eventually, you end up with machine identities holding persistent access across multiple systems. And that's one of the challenges that I mentioned earlier. So this visibility issue. And agentic AI, well, it's amplifying this problem because these systems are not only executing predefined tasks, but they can also make conditional decisions. They can invoke APIs dynamically.
They can operate semi-autonomously. And many organizations approach this in the wrong way, from my perspective, by focusing almost entirely on authenticating the AI agent itself.
Of course, authentication matters, but it's not the central problem. I think that the critical issue is authorization, granularity, and runtime constraints. So what actions can the agent perform? What's the intention behind? Under what conditions?
Et cetera, et cetera. So we see a lot of these vendors trying to address these agentic AI challenges.
And also, there's a lifecycle problem, like you mentioned not long ago. And that creates another issue. And that's why we also see this convergence between IGA and PAM. So if I can say with AI agents, I think that the industry is only beginning to understand the operational implications. And most enterprises are still thinking about AI risk at the model layer. The more immediate issue from, let's say, a PAM perspective is the privilege execution authority. So how are we going to manage privilege over time with these new systems?
I think whenever I talk to our advisory customers and how we can categorize or assess these NHI and even agentic AI, consider them as privileged, because most probably they are. So they hold more access rights than the typical user, more access rights than they typically should. Or they have to have more because the actual decision which access will be needed is done at runtime. And then they are only limited by more or less rough guidelines or guardrails, and that's it.
So considering PAM being a key component for solving the overall area of NHI challenges, I think that is fair to say that PAM will play an important role, not the only role, as you said, well integrated into an architecture. But without a proper PAM solution, you might not get a grip on your NHI challenges. That's what I'm convinced. So it's good to see that it's in the market out there. And one solution that we often say is, we need to have short-lived credentials, ephemeral credentials, just-in-time access. How has that evolved? Just-in-time comes or stems from privileged access management.
Is this now capable of doing that at scale, at volume, and also at machine speed when we're talking about NHI and just-in-time access? Well, yeah, that's the challenge. If I'm not mistaken, in my report, as I mentioned, there were 36 vendors participating and only one of them did not provide just-in-time features. It was on the roadmap. So let's just say that all of them are covering this. So conceptually, just-in-time is easy to agree with. Very few security leaders argue, of course, in favor of admin access, on persistent admin access.
So although these vendors claim to, they're trying to get rid of standing privilege, they still exist and it's still a problem. And just-in-time access is supposed to reduce this friction, supposed to solve this issue. But many organizations struggle with implementing it right. So the first challenge that I see is that, again, is this identity and entitlement visibility. So you cannot implement just-in-time effectively if you do not have an overall picture and you don't understand who currently has access, who has privilege, why they have it, and which systems are impacted by that.
The second issue is operational integration. So just-in-time is not just a single feature. It also depends on orchestration between identity providers, between platforms, ticket systems, policy engines. So in heterogeneous environments, this can be very complicated. And the third issue is, in a way, you can understand it as maybe cultural resistance. So security teams often underestimate how much organizational behavior depends on persistent privilege. So developers want deployment velocity, infrastructure teams want rapid troubleshooting capabilities.
So if just-in-time is introduced as a security mandate without any operational redesign, it could be challenging for those teams. So in a way, a realistic transition usually starts with a higher privilege reduction rather than a universal just-in-time everywhere on day one. So focusing first on high-risk admin access is typically maybe the first target. Then organizations expand toward cloud privilege elevation, developer workflows, and ephemeral infrastructure access. So it's like step-by-step, right? It's not something that can be done from one day to the next.
All vendors are attempting to implement just-in-time and get rid of standing privileges. But I believe that the operational reality for a lot of their customers and a lot of enterprises, it's much harder than it sounds.
Right, and I think, yeah, once you introduce just-in-time access as a mandate and this is not done properly, people will find a way to evade it. So when we think of PAM having started out of more or less managing shared accounts, so the typical root DB admin, domain admin accounts, they are still around. So I think this is also at least a part of the responsibility of the vendors to make this as easy as possible. So the most secure solution should also be the most easy option to choose.
And I think that's something where these highly technological solutions sometimes struggle, but this is just my perception because everything that is more secure sounds more complicated, let's avoid it. That's not the way to move forward.
Yeah, so, but at least as you say, practically every vendor provides just-in-time access. So there is the way to move away from standing privileges and go to more least privileged, more time-bound and ephemeral access only when it's needed. Otherwise it's not even assigned to the account. A question that is close to my heart that I see in my practice at several customer sites already. This is the question about, where does the system actually run when it comes to ownership? Not only which platform it runs on, cloud, on-prem, private cloud, software as a service.
It's really about who owns it, who runs it, who has access to the system, who has in the end final access to the keys to the kingdom, or can I run it on my own? So the other extreme is complete deployment sovereignty. This is trend that you also see with the vendors that they allow to run this where you want.
Yeah, so the decision has become much more strategic than it was, let's say five years ago. So historically the question was mostly operational. So do we want to manage the infrastructure ourselves or outsource that burden to the vendor? And now the conversation is increasingly moving into topics such as sovereignty, jurisdiction, auditability, regulatory exposure, especially among the European vendors. So something interesting is that the first two to three slides when I was talking to them, they would show me a slide on how we are gonna take Europe on this digital sovereignty journey.
So that was an interesting, let's say, change from previous reports. So PAM platform sit close to the core of enterprise control infrastructure. So they manage, as we know, privileged credentials, secrets, session telemetry, policy decisions, et cetera. So in many organizations, PAM becomes one of the most sensitive security systems in their environment. On the one hand, if we look at SAS, so SAS delivery has advantages. So it's faster deployment, lower operational overhead, quicker feature delivery, easier scalability.
But for many organizations that are in highly regulated industries, that's becoming interesting to think about. So the key issue is not simply, let's say where the data is stored, but it's where the operational authority resides. So if privileged access, telemetry or session recordings or secrets, and they are controlled through externally hosted infrastructure subject to foreign jurisdiction, subject to foreign laws, some organizations will view that as an unacceptable dependency vulnerability. That does not mean that SAS is insecure.
It means that organizations need to evaluate deployment through a risk governance lens rather than purely a convenience lens. So what wasn't before efficient for some organizations, it could become now a vulnerability or a dependency. And the question is not really, so which deployment model is modern? I think the right question should be which deployment model aligns with our operational risk tolerance, with our own regulatory obligations. Sovereignty requirements or internal capability maturity.
So hybrid models are becoming increasingly common precisely because organizations want some sort of flexibility and control over sensitive components. And what I see is that European organizations and European vendors increasingly view identity and access control as a strategic infrastructure. So not just purely technical. So it's not about is this spam solution secure, but about who controls the platform? Where is it operated? What legal exposure exists? Can we avoid vendor locking? And I think that reflects a broader European concern about reliance on non-EU providers.
It doesn't mean that Europe should pursue sovereignty in a purely ideological or isolationist way, but from a more practical perspective. So where does dependency create real risk for me? And just to conclude, I think that's also an opportunity for European vendors to try to address and close these gaps that European organizations are starting to talk about, but also non-EU providers and let's say North American vendors, they should focus more on the scalability, on the components, on execution, and maybe be more careful with marketing claims because marketing claims are not enough.
Buyers increasingly want structural safeguards of clear governance, transparent operations, contractual protections, and all of these things. But in an ideal world, that also would mean that I can really choose a vendor based on the capabilities they provide and then choose the adequate deployment model to say, okay, yeah, I take this from vendor XY who is from the EU or is not because it doesn't matter because I run it on my own private cloud and I have the full control over the platform independent of the way that they decide to provide the service.
So if I have full choice in the full spectrum between SaaS and self-hosted, so then I can really look at the capabilities and even can change deployment over time with the same product. That would be in an ideal world, a good approach. And you can always readjust your risk assessment when it comes to I entrust this product with my most secret details of the organization. So that might change over time. Yes. Or it's changed by somebody else. I'm looking at you, Dora, or at you, Nis2 or something like that. So that might also be an issue when it comes to third-party risk management, etc.
And then the third-party risk is something to address with your PAM provider. Okay. I have to ask this question because we are in 2026. AI and machine learning in PAM, is it a thing? I think yes. But how do you see it from the research perspective?
Yes, of course it is. But there's an enormous amount of marketing inflation around AI capabilities. Many vendors describe, let's say, basic statical thresholding or rule-based correlation or risk-based assessment as AI-driven behavioral analytics. Buyers need to test whether the platform is actually producing meaningful detection improvements or it's simply relabeling existing analytical functions. And I know that buyers are skeptical around all these marketing claims. They don't really want AI if it's just going to be fancy or because the competition is doing it.
They just want you to solve their problems. And if AI is going to be able to do that, then that's great for them. But I think that there's a lot of marketing around that. I also think that the other issue is false positives. For example, when I published my report on ITDR in October, there were a large number of PAM vendors that are also incorporating ITDR capabilities. So that's an area where PAM can leverage some AI features to be able to not only detect threats, but also be able to respond to them. But ultimately, as I said, buyers, they want answers to their problems.
They don't want more AI just because it's going to be fancy. And I think when we combine the last two topics that we have, AI and sovereignty, the question is, where is the AI provided from? So you have a highly secure PAM solution run on-prem, but if you want to use AI features, you need to go back to a SaaS service. I think that is not necessarily where you want to provide the distilled essence of your privileged access management telemetry to the cloud. So I think this is not nothing that... So the question is, can you run even the AI for yourself? I think that's...
Or in the self-hosted cloud with the proper power behind that to actually have the information available and the right velocity at the right scale. But I think for many organizations, using AI as a SaaS service provided by a shared platform somewhere is not an option either. So that might be difficult as well. If you sum it up, if you look back on the research that you do, have we come to a point where it has consolidated or is this still a quickly evolving market? It has matured, of course, because they've been around for years. But is the cloud part mature? Is it changing? What does NHI do?
There's more to do in the next years, right? Of course, yeah, it's mature. But since the definition of privilege has not only changed, but it continues to evolve based on what we see in the industry, I expect more momentum. There are new vendors, new entrants. And even after completing my research, I spoke to two or three new European PAM vendors. So there's for sure room for more dynamics around the market. But if I can conclude with something, it would be, as we discussed, PAM should not be thought about as an admin security product, as a standalone solution.
We need to change our mindset and view PAM as an enterprise authorization layer that is part of this identity fabric, because it's governing the execution of high impact actions, not only of humans, but of machines, of workloads, AI agents, et cetera. And I believe that the organizations struggling most are usually the ones that are still treating PAM as a vault deployment owned by a small infrastructure team, security team.
And I believe that the organizations making progress are the ones that are shifting that mindset and treating privilege as a continuously governed operational capability across the entire identity ecosystem. And I expect to see more convergence moving forward with IGA and other areas of identity. So I'm not sure where the market will be in the coming years, but I expect that there will be some interesting and exciting developments. Great summary. I don't ask any other questions. I just highlight that your research is out there.
So if you are interested in reading more of what Alejandro has provided as research, so have a look at the Leadership Compass PAM that just has been released a few weeks ago. So please do so. If you have any questions regarding this podcast episode, regarding what we could cover, what Alejandro and I could cover in an upcoming episode on more details about PAM, let us know, reach out to Alejandro, reach out to me. We are easy to find on LinkedIn. The mail address is easy to find.
And if you have an immediate question regarding this video or this podcast, just leave a message, a question on the platform that you're using on YouTube in the comment section. We do reply and we take your feedback serious. And you can influence the next episode on PAM by your questions. So having said that, Alejandro, thank you very much for being my guest today. Thank you very much for this great research, because I use it as an advisor in my daily work. So this is really something that is also fruitful for our work in the advisory business. So thank you very much for being here today.
Thank you, Matthias. I appreciate it. Thank you and bye-bye.