Hello everyone. My name is Alejandro. I've been working at KuppingerCole for about five years, and today's session is on Privileged Access Management. This session is based on my leadership compass, which was published two days ago.
So, if you haven't checked the report, I strongly encourage you, because it contains way, way more information than what I can cover here in 20 minutes. The report had 36 vendors, so as Christopher said, it's a very diverse market. I believe that a good way to introduce the session is by starting with a simple observation. We know that most security breaches start with identity. We hear this all the time. Attackers don't hack in, they log in. And a lot of these cases involve privileged identities. But what we call privileged access today has changed.
It's not what it was back in the early days when we had traditional PAM, and it's something that I want to talk about more in the next slides. But first, let's just look at the agenda. By the end of the session, you should have a clear view of the PAM market. You will be able to see what are the changes happening beneath the surface, and you'll be able to see what that means for how you position and implement privileged access in your organization. So I'm going to walk you through two different things.
We're going to look at how privilege is expanding beyond PAM when we look at the market overview, and then we'll be able to also analyze the current market dynamics by looking at the leadership compass. And if we have some time, we can do some Q&A, or you can just try to find me during the next days or connect with me on LinkedIn for more questions. So I have this poll question, but I'm aware that it's not going to be on your phone. So if you guys would like to maybe raise your hand. So the question is, oh, okay. It's working.
No, it's not? Okay. Okay. No poll question, then. Just go back to the previous slide and then by raising the hand. The old style. Okay.
Okay, so we'll do this later. So one of the challenges I had when I conducted my research was to define privilege in a way that reflects what I see in the market. So I'm going to talk about these three things here. Privilege is defined less by who holds a specific account and more about what an identity is capable of doing within an environment. So this definition shifts the focus of PAM from managing accounts to controlling and governing privilege access across an environment. So in a way, PAM is not just an access problem, an identity problem.
If you then understand that PAM is no longer just about managing accounts, but about what are the actions of those identities, then you start to see that things have changed. And now it's not only about human identities, but there's also another dimension of machine identities covering APIs, workloads, and agentic AI. And on this last point regarding agentic AI, there's a lot of hype around that and a lot of conversations. And so far today and yesterday, I've had some really insightful conversations with some vendors on this topic.
And it's important to remember that for a lot of organizations, especially here in Europe, the European economy is driven by small and medium businesses. So for a lot of these SMBs, all the talk about agentic AI is to them, in a way, background noise. They just want to get the foundations right. So if we talk about session recording, vaulting, password rotation, these are the so-called traditional PAM capabilities. But for a lot of organizations, those features still matter, and they need those.
Of course, as they continue to scale, then they will ask more questions around NHIs and agentic AI. But that's something to consider, that vendors need to draw, in a way, some kind of balance between addressing the current challenges that organizations face and the emerging use cases as well. The second thing is that PAM is converging with broader identity security. So the Kupinger call Identity Fabric, what we see is that a lot of organizations operate in silos. So they have different tools, IGA, the Keem, ITDR, secret management tools, and they're all working independently.
So what the Identity Fabric is trying to solve is to connect all these different tools, not by replacing them, but by connecting them, so that identity, policy, and enforcement are consistent across the environment. And lastly, the market is expanding and changing. I've written, I believe, around 10 LCs in my time at Kupinger call, and this was the most diverse in terms of geographical presence. So there were PAM vendors from China, from Southeast Asia, from India to South America, Europe, North America. And that made me realize that PAM is more of a strategic business control layer.
It's not just a technical standalone tool. And that's, in a way, the key takeaway that I want you to take from this slide.
Okay, this is a sort of a timeline. It's a little bit simplistic. It's hard to put everything that has happened over the past 20 years in just one slide, but more or less we can see that PAM has evolved from being largely human-centric, focused on human admins and shared accounts, with features like session recording and password rotation, to move to cloud and automation. So APIs and automation also expanded the privileged access surface, and then we see how the era of DevOps and machines has changed things.
The explosion of NHIs, many organizations struggled to have full visibility of what's going on in their systems. And we also see a clear shift toward just-in-time access and ephemeral credentials. And now we're entering a new era of AI agents acting with delegated privileges. There's a lot of conversations at EIC around this topic, a lot of sessions on that. So there's a clear need for full lifecycle governance of these autonomous identities.
Things haven't been completely solved, there's still a lot of challenges, but a lot of the vendors that I've spoken to in this research and at EIC, they're already trying to come up with some ways to close those gaps. So where to focus now? If you're just starting your PAM journey, one way is to adopt an identity fabric, and to reduce silos and fragmentation. So what does that mean in practice? It means that you have to rethink identity as an integrated system instead of a separate domain. We need to shift from static to dynamic privilege, so no more static controls please.
And then we need to treat agentic AI and NHIs as first-class identities as we start to see these emerging use cases, because a large portion of privilege activity is being driven by identities that we don't fully discover, we don't fully see, we don't fully manage, we don't fully govern. So it's very, very important to have a shift of mindset as well. We need to start enforcing this privilege continuously, not periodically, and we need to design for hybrid cloud and machine-driven environments.
So the key takeaway here is that organizations must move toward continuous identity-centric, treating all identities equally, governing privilege dynamically, and building resilient architectures. And that's key, resilience, and also ties back with my previous slide on how PAM is also this sort of strategic business control tool that allows for business continuity. It's not just this technical tool that has been known for some time now.
Okay, second poll question, I'm going to skip this because I see that I only have less than 10 minutes. So these are the vendors that we rated in this report. So 36 in total, as I said, very diverse market. We see some well-known established vendors, there are some vendors that are new entrants in the market, some of them are solving specific niche areas. We see some European vendors as well. This is taken from the 36 vendors, so the capabilities that they cover, of course, all of them do just-in-time access. They're also starting to cover machine identities and those areas.
We see some gaps in operational technology and industrial control systems. Some vendors are already working on solving those issues there. And account discovery is also a big one. Most vendors are trying to solve this issue of lack of visibility. Here's another slide. So this market presence, it's about the customers that they have, it's not about the geographical location of the vendors. But where they are targeting. So it's very evenly split. And then deployment options. It's important that vendors offer deployment flexibility, especially in highly regulated industries.
And with all the talk around digital sovereignty here in Europe, it's one of the main areas where organizations, European organizations, are trying to figure out. Okay, so now we can take a look at the results of the leadership compass. So this is our new design, very good design. So we see the overall leadership on the top right corner. There are two vendors that are innovation leaders that are not overall leaders, that's Teleport and Brita. These two vendors are already looking at the agentic AI use cases. They're focusing on DevOps, on the cloud.
We see some big names there, like Octamping Identity that have recently done some work on privilege access. And then the usual suspects, CyberArk, now Adira, Palo Alto, Delinea, Beyond Trust, Archon, and Saviant. So this is a combination of product, market, and innovation leadership. And here you see the size of the market leader. And then this is part of our report. So if you go on our website, you can look at the separate leadership positions. You can get to see the product leadership, the market leadership, innovation leadership. And you also get to see each vendor has a spatter graph.
So we can take a look at the different areas that they cover. Are there any gaps? This is a real spatter graph. I just had to cover the name. But these are the areas, capabilities that we use to assess all of these vendors. So from security to deployment to credential, key management, endpoint privilege management. So there were some vendors that didn't fully cover all of these things. But that's for you to take a look in the report. So if we go and take a look at the key findings on the left, we see challenges. And then on the right, the future direction.
For challenges, there's still a reliance on static credentials. It's still an issue that all vendors are trying to figure out and to solve. Still some limited support for machine identities. One of the main issues is probably complexity and slow time to value. There are some vendors like NSFocus, Devolutions, and Nimble Nova that specifically target the SMB market. So they focus on fast deployment and time to value, which is one of the things that many organizations struggle. And also the large vendors are also trying to figure out ways to make everything more simple for their clients.
So future direction. So with the new definition, we are able to understand that it's now more about actions, about understanding what are these identities capable of doing. Theory of standing privilege.
Again, no more static controls. And becoming this part of the identity fabric, it should not operate individually as a standalone tool. People need to have this mindset that it's a more strategic control layer that businesses should incorporate. And it should not operate alone. It should be in communication with other tools.
And yeah, I think that's all from my side. If you have any questions, I know it was a fast session.
But again, if you want more details, it was a very big report. And you will get much more information on that report. So if you have any questions, I think we have like three minutes. You can just reach out to me, and we can continue the conversation. Thank you.