Welcome to the KuppingerCole Analyst Chat. I'm your host. My name is Matthias Reinwarth. I'm an analyst and advisor with KuppingerCole Analysts.
And so is, at least the analyst part, Matthew Gardiner. And I welcome you back to this episode.
Hi, Matthew. Happy to be back. Always enjoy these conversations. Great to have you. And when we talked about this just before this episode, I realized that cybersecurity experts are really great in hiding actually really fascinating and excellent functionality in three or four-letter acronyms that nobody understands and where people get bored when they hear the second one. Unfortunately, we want to talk about something like that. So let's start with the interesting part.
We want to identify whether a SaaS application, something in the cloud, those nice applications that are so helpful are used within your company without permission. If people are using AI in a way within your organization that is really not expected, whether they're connecting any data sources, any other cloud services to your AI that you did not expect to do so and where you do not want to get the data to go there. This is what we're talking about. And the acronym that it's hiding behind is an SSPM. So it's even a recursive acronym because the first S stands for SaaS, for SaaS.
So it's SaaS Security Posture Management. And when you joined me, Matthew, in February for the very first time for an episode, this was also our first topic. And we were looking into SaaS Security Posture Management and how it was evolving so that it was changing. It was encompassing Shadow, SaaS, Configuration Drift, OAuth Risk, and anything like that. And you continued working on that. Long introduction, but here we go. What happened in the meantime?
Well, one thing that happened is I don't use the SPM term anymore. It's sort of become passe because the market has moved on, as you say. So I came up with the name for this space, SaaS Security and AI Governance, the and being critical in that essentially what were SaaS security focused vendors, and that's the market that they operate in, has evolved to also include AI security and governance. And there's a lot of parallels between those two worlds, the Shadow SaaS and Shadow AI are sort of happening in the same way. The way that things are discovered shares a lot of the same functionality.
You have this new type of identity called an AI agent, but nonetheless, the identity and the controls and the monitoring around identities, both human and non-human, share a lot of commonality. So essentially the two worlds of AI and SaaS have merged, and the vendors have quickly pivoted to add sort of AI focused functionality while still having the SaaS posture management part of their equation. So you have this more complete solution space for what is a very sort of interrelated security challenge between SaaS applications and AI systems. Right.
So if I understand you correctly, you mean this and in between really, really as important. So there's a clear message for organizations who look at that market, they should look at both SaaS security and AI governance as a whole, because they belong together and present some kind of similar or together belonging risk surface, right? Yeah. And a simple way to think about it is now SaaS applications have AI functionality and AI agents in them, and AI systems are SaaS based. So these two worlds are really one in the same in many ways.
And so it kind of makes sense that the controls and the monitoring that you do for them have also joined up. So you can sort of kill two birds with one stone in a way, and that's really where the vendors in this market and where the market's been going for the last year or so. Right. And also one thing that we mentioned when we prepared for that, this is you said, okay, shadow IT was hard because this was hardware. Shadow SaaS was easier, you could buy it with your checkbook. And shadow AI, everybody has it, everybody does it, even not knowingly. So that belongs together as well.
So when you look at the market segment and you did really proper research on that topic, we will talk about that later. Also the capabilities, the functionalities, also the target, what we're aiming at has changed significantly. So I think even in, I don't know, six, seven months that it was that we talked last time, the market has changed, the capabilities have changed. What would be from your perspective, those capabilities that are essential? And on the other hand, those who are emerging that you see from your research will be the essential ones in half a year?
I mean, the absolute foundation, it's the cliche, of course, you can't secure what you don't know about or can't see. So the foundational functionality is discovery. So as you alluded to, in the world of shadow IT, it was relatively hard to create it because if servers needed to be deployed and software needed to be deployed, it was hard to do that without the IT and security teams knowing about it.
Now, of course, in the world of SaaS and AI, all those things can be essentially licensed and acquired. You shouldn't do it, but it happens all the time without IT and security involved. And so there's lots of stats out there, but I'd say the majority of SaaS and AI applications are yet unknown to the IT and security team. So thus discovery of those by the security team is critical. But then once you discover them, you need to inventory and monitor them. You need to understand who and what is using them and the permissions they have.
You need to know what they're integrated to, to what other third-party systems are they sharing data with. So those are the core functions. And then you start getting into some of the more innovative areas where once you have what I just talked about, how do you detect threats? How do you remediate these systems that maybe you've discovered but don't think should exist? Or maybe there needs to be a business rationale? And also looking at the data that's moving around and compliance and governance.
So most of the vendors do most of those things, but not all of them do all of them to the same level of depth. Right. And as an advisor, when I talk to organizations and people responsible for such solutions, or hopefully soon responsible for such solutions, one question that I always get asked, so I hand it over to you. If discovery is this important gating capability and you don't know what you want to detect, you obviously have to ingest tons of different kinds of signals, which you have to interpret. So when it comes to the telemetry that you are consuming for discovery, what is essential?
What is unexpected? What surprised you? What they can take into consideration? How broad is that aspect of discovery to really mostly catch all the fish? Yeah. So there are a lot of places you have to sniff basically at the end of the day. So some of the more popular ones that catch a lot of things is in the browser. So to the extent the user is using a SaaS application or an AI application, they're often doing it from the browser. So if you have a browser plugin, which many of these vendors provide, looking at email.
So a lot of times when you're registering for a new account, there's an email administration or email happening. So sniffing the email, looking for applications that you didn't know about as a place to go.
Endpoints, those are some of the common places. Looking at the identity provider, sometimes things are provisioned in the identity provider, but not in the SaaS, security and AI governance monitoring system. So you sniff the identity provider. One of the weird ones is in the procurement systems. So you can see what maybe people are buying through the official channel, but not necessarily letting IT and security know. So basically you're keying this database, what some people call the enterprise graph, of who's using what applications.
And then you have the gaps, like the things we didn't, that aren't in the graph. And that's the thing where you have to start hunting down, what is this thing? Do we have an alternative that we should suggest to the user to use instead? Is it something we should block because it violates policy? The whole remediation side thing. Ultimately, you want to have this highly reliable central, in a sense, database of everything that's going on in your environment, such that you can then start to monitor. Right.
And as you already hinted a bit at, and this is where me as an identity guy comes in, all of this is related to people doing things and people initiating actions through agents. So as this identity guy that I am since the 90s, my favorite question, how is identity becoming the organizing layer for governing users, associated service accounts, API keys, and in the end, AI agents acting autonomously in the worst case?
Yeah, I mean, the term of identity often historically has been associated with humans. Obviously, we need to break that mental model right immediately. And it was already somewhat broken by service accounts and API keys, but now it has some gasoline poured on it with AI agents. So now agents really are considered full-fledged identities and they have permissions. Where they get them is a different question, but they're like dogs, someone needs to own them. With a human identity, nobody needs to own the identity with a human, but you might have a boss.
Not that that's ownership, but there's some sort of hierarchy. Well, there needs to be a hierarchy for agents where someone needs to own it. And you need to be able to monitor what your humans and your agents are doing. So basically, that identity layer is a foundational piece in that enterprise graph. Because at the end of the day, if there's a misbehaving agent, you need to go, well, who do you go to find out, should it exist or should it change or who owns it?
So just like in SaaS applications, you have administrators, you have end users, what level of privileges do those administrators have? That's all part of the equation.
And again, why SaaS application security and AI have sort of joined up, because really the principles are all the same. The actors are a little different, but the type of controls and visibility you're trying to provide is largely the same. Right. Thank God I'm not the CISO in any company, but I think if I was one, I would be really scared of my users using sanctioned AI platforms, using sanctioned SaaS platforms and connecting both to each other, which I would not consider to be sanctioned.
So we all know this when it pops up, hey, you're using this nice AI platform, why not connect your system X, Y, Z to that? So things will get much easier and then data flows from A to B, which you do not expect to go there.
This is, from my perspective, I think one of the most difficult to control aspects of communication. And in the end, this is a kind of supply chain risk. Do these solutions also cover that aspect?
Well, yeah, absolutely. I mean, once you know they exist, then particularly AI systems, but the SaaS systems as well, have relatively good APIs. So these systems will just connect to the APIs of these sanctioned systems and then monitor them and watch, both for posture and activity. At the end of the day, this test, the sort of, for lack of a better term, the political position of the security team, how strong a hand do they have or do they want? But at the end of the day, it starts with visibility. So once they have visibility, they can start exploring what's correct and what's not correct.
And that's actually an area where I've started to see pop up somewhat consistently, having like an AI governance committee, cross-functional, that obviously hopefully the CISO hasn't seen that. But at the end of the day, it's not just the security team's responsibility for agent behavior. They can't totally own the application functionality. They can externalize security and controls. But at the end of the day, given what an agent in theory can do, it's not reasonable for them to know all the boundaries for those agents.
So that's why you sort of need this AI governance committee, which is made up of business unit and executive leadership and security and control and compliance and all the sort of parties to the issue, so that they can come up with sort of an approach that fits that company. But then bringing in potentially one of these solutions as a key platform for them to essentially operate their governance on top of. Right. And that also would be the enforcement part of an acceptable use policy in the end.
So tell your users, yes, no, you're not allowed to connect this service, although you can use it to your AI, because you will never know which classified data will go from A to B. And usually that should be within the actions and the brains of our colleagues. But in the end, you can also enforce it when you identify that there is somebody who uses transitive trust to hand over data from your mail to a platform in the cloud, which does project management. And it raises the issue of like, are you going to block it?
Or are you going to raise the question to the end user and say, do you really need to do this? What's the business justification? That's where sort of the business, you know, culture, risk culture, security culture comes into play. At the end of the day, these platforms can do a lot of those things.
It's like, what do you want them to do? And so, you know, the most implementations that I've, you know, been hearing about, you know, the first thing is they're surprised by how many things they didn't know about. So that's usually test number one, is all these SaaS applications and AI agents that are out there, you know, many of them are complete surprise. And so the next question is, okay, now you know about them, what are you going to do about it?
And that's where sort of the, you know, the culture, the governance committee concept, you know, the security team can't decide for the business, but they can point out potential points of risk. And that's what the platforms are really good at, is that they're continuously doing this. It's not like a one-off, you know, they're just continuously monitoring, continuously updating their inventory, continuously updating the gaps of things they didn't, you know, the system didn't know about yesterday or today.
So, you know, this creates this whole new management challenge, basically, is that now this stuff is happening, what do you want to do about it? How do you want to get them proper control? Right. So really interesting. And I think you're perfectly right in redefining that market segment by including both aspects, both the SaaS and the AI aspect, and bringing this together. And coming back to the roles that we both play within our organization, I'm an advisor, I rely on your analyst work.
So you looked at the market, and in parallel, we are all seeing this consolidation, people buying companies, platformization. Given all this ongoing market consolidation, what should buyers do? And should they initially already look at larger platforms and wait for them to buy the experts? Or do you expect these experts that really cover that market and cover it brilliantly, as you discovered in your research, should focus on these unicorn solutions, which are easy to integrate within a platform? What would be your recommendation? It's a crystal ball question. I know. Yeah. Yeah.
You have to have to self-assess, like there's no blanket statement I can make. Obviously, if you're already wedded to a platform, one of the major platforms that part in this study was CrowdStrike. One of the penultimate platforms that are out there, they acquired a chemical adaptive shield in the SaaS security space and have expanded into AI, just like the others. So if that's an attractive route to add on to what you're already doing with a platform vendor, that's great. But it's still relatively early market.
There are thousands of implementations of these systems, most historically have been done for the SaaS application. Side of the equation, but the AI side is rapidly gaining traction. So there's still quite a few standalone vendors that have some staying power and some innovation. So you have dozens of vendors to choose from. Some are platforms, some are standalone. And so you just have to sort of figure out whether you like the platform route in general and want to add another piece to it, or whether you have been well served by specialist vendors. Both options are available in this market.
Right. And it brings us back to the Kupinger-Cohen term of the fabric, which applies to AI security, applies to cybersecurity in general, and the identity fabric where we come from. I think this is exactly the approach, though it's not necessarily the tool that you choose, but the capability that you need and how to integrate that into your overall security approach. Yeah. And none of these, all these vendors like for remediation will use your ITSM system. They'll connect to your IDPs, they'll connect to all of your core infrastructure.
So they're not trying to, they're adding essentially a new functionality that does these sort of specialized discovery and inventory and monitoring functions, but fully cognizant that a lot of your other enforcement or IT processes run on other systems. So they're trying to, you know, they all collaborate with the systems that you would expect that you'd want them to collaborate with. Right. And coming back to your research, first of all, talking about topical or current evolutions that we see right now, today is the day that your both reports have been published.
And when we publish that podcast episode, it will be just four days away. So it was last week when you listened to that. So your bias compass on that market segment and your leadership compass on SaaS security and AI governance is available right now. So you can have access to that. If you briefly distinguish between bias and leadership compass for those who are not familiar with the terms. Yeah.
So a leadership compass provides a market assessment and sort of findings of trends, but also does a deep dive into, in this case, 14 vendors in this space and then does a high level summary of a handful of others. So it does a, you know, comparing of the functionality and innovation and market position of the vendors, you know, the classic charts you might think of comparing vendors.
So that's useful for figuring out, well, which, if, you know, if you're interested in this market, which, which two or three or four vendors should I really seriously consider based on whatever your priorities and what your infrastructure is like. The buyer's compass doesn't really talk about vendors at all. It basically talks about capabilities and the, you know, the relative functionality and each capability set and the capabilities are most important to us, which are less important.
And so then that will help guide your buying process, which then you can then lean over into the leadership compass and figure out, okay, well, there are the three or four vendors that make sense for me to, to evaluate, you know, in the next stage. So they're typically published together because they're sort of first cousins of each other. Right. And if people ask, how do I get to these reports?
Yes, this is something that is covered within our subscription or membership, however you want to call it. So if you are a member of Kupinger Coal as a, as a consumer of our research, you will have access to these documents anyway, for those who are not, but who should be, of course, is there anything else that you can tell us about where people can learn more apart from this episode? We will later, of course, ask you to raise your, raise your questions in this, in the comments of this YouTube video or send us a mail. But where else? I think blog posts, webinars, something like that. Yeah.
Yeah. So I've been doing some blogs as I've been developing the, the research, which obviously free and open to everybody. So just check out our blog site under me, but the next big sort of public facing activity is on October 7th. You can go to our webinar page. There's a webinar that I'm putting together called security at the, at the integration of SAS, AI, and identity. So October 7th, that's open for anyone to sign up for. Hope you will. Obviously it's, you know, relatively short window. I'll do sort of the highlights of the reports.
But, you know, it'll provide you at least the, the key findings and key recommendations that I have from doing this research, but then obviously pointing to the, the buyer's compass and leadership compass for more of a deep dive into, you know, all the above. Brilliant. Also Q and A section, I guess so, right? Of course. Yeah. Normal webinar. Okay. So that's it. We made it full circle. We started with the first episode that we did together. We watched the market evolve up until now and it will evolve. I did not ask the question, what do you expect to happen in the next two years?
Because I think we do not know. Well, I mean, I know a little bit on that.
I mean, okay, here we go. So one of the things I've been watching, you know, as I mentioned this, this, what was the SAS security posture management market, which, you know, started four or five years ago, really. They quickly adopted AI as sort of, because of the commonality between SAS discovery and controls and AI discovery and controls. There's definitely early signs that the AI side of that equation is, is speeding up quickly. SAS is still there.
So, you know, maybe in, in, in next year, I'll call this the AI governance or, you know, the SAS will become sort of a slow, a lower end part of the equation. There's so much energy going into the, the AI side of, you know, agentic security and governance that SAS may be kind of just the, you know, an accepted functionality, expected functionality.
So they, they, the market grew relatively quickly over the past four or five years based on the SAS posture challenges and shadow SAS, but it seems to hit another gear on the, because of the AI challenges. So I think these vendors find themselves in a very good position because they're, you know, they, they made a lot of investments over the years, which have become immediately useful in the slightly, you know, related domain or closely related domain of AI governance. So I think the whole market is, this side of the market is picking up speed.
So there'll probably be more acquisitions of them and they're really turning into some pretty substantial companies. So the market has good lice to it, let me put it that way. Interesting. That really sounds brilliant. Thank you. Sorry for saying that we cannot look two years ahead. Maybe we can at least partially, but analysts and advisors, we are heavily relying on communicating with people. So I want to highlight this again. If you want to learn more and get in touch with us, find us on LinkedIn, you can find Matthew and you will find me on LinkedIn. That's easy.
Connect with us, ask questions, liaise with us. We're really interested in that. If you're a vendor, if you're an end user organization, if you're a consulting company, just reach out to us and learn and ask questions and provide your feedback. That's really important. If you have questions and feedback, I've mentioned that. Leave your comment below this episode on YouTube or send us a mail. It's mgrmr at kupingercall.com. It's not too difficult to guess what the other mail addresses are from our other colleagues with that schema. So we'd like to get in touch with you.
Of course, we'd like to have you as our subscribers, but we want to convince you that we are worth it. This was one attempt to do so.
Matthew, thank you very much for being my guest today. Thank you very much for that diligent reporting that you do, the research that you do. I know this is a ton of work and I know it's a great day for you to say, okay, it's out. So we will cover that again, but we don't give away any secrets today what it will be. Thank you again, Matthew, and I'm looking forward to having you soon in another episode. I look forward to it as well. Thank you. Thank you. Bye-bye.