Welcome to the KuppingerCole Analyst Chat. I'm your host. My name is Matthias Reinwarth. I'm analyst and advisor for KuppingerCole Analysts. And for today, it's more important that I'm analyst. It's that time of the year where analysts pull out their crystal ball and look into the future and make predictions for the next year, 2026. And exactly for this, I have invited Jonathan Care and Martin Kuppinger to discuss exactly that, predictions, expectations for 2025. And for today, we are looking at IAM. But first of all, I would like to welcome both of them.
Hi, Jonathan. Good to have you.
Hi, Matthias. Good to have you. Good to be here.
And hi, Martin. Good to have you.
Hi, Matthias. Pleasure to be again in one of our podcasts. Right. And we have two experts with hopefully two different perspectives on some of the topics. But when we start out, so this crystal ball, what do you expect as one key development for 2026 when we look at IAM, identity and access management evolving? Maybe starting with you, Jonathan, what is your key expectation?
Very, very briefly, I think the biggest threat isn't going to be ransomware. It's going to be organizations that have deployed AI agents with credentials and broad system access, which will overstep our traditional security frameworks. And they are acting on harvested identities that they get that from somewhere. I'm more thinking that the authorization systems we have weren't built for autonomous agents and most organizations weren't ready. But then that's our job.
OK, we need to get back to that. Yeah, absolutely.
Martin, what are your key expectations for 2026? Not giving too much away for the EIC keynote, but hey.
Yeah, honestly, I didn't really think about my EIC keynote, which is good. So I can talk about everything. I don't even know whether I will be the one who will be asked to do the EIC keynote. So I'm very free in what I can talk about from that perspective. So I'm absolutely with Jonathan. AI identity in every form will be super essential. So identity for AI, AI for identity.
And yes, AI empowering the identity-based attacks that are anyway running at scale for quite a while. It will be a huge topic. And so I think we are all still in a very honestly early learning phase around how do we handle identities in the IA world for AI, adding the complexity, the authorization challenges. This is clearly one of the big areas. But there are also, I would say, more down-to-earth things, because what I currently see is that a lot of organizations and identity management teams are a bit overwhelmed by all the innovative stuff popping up.
So new acronyms and maybe market segments, maybe not, appearing in a quite high frequency, while organizations still are struggling with sometimes really fundamental challenges in IAM or with modernization. And finding that balance and avoiding ending up in a there's a zoo of tools, a lot of really disparate non-integrated solutions, I think is another of the big challenges amongst many. So there are a lot of things going on and it will be a cool year 2026 at least for the ones who are looking at trends innovation. Right. And if I look at it from my perspective to add that as well.
So I'm looking at that more from the advisory perspective. So and I can really just confirm what you just said. So there are obviously too much tools around. And the question is maybe also to both of you. Why do organizations fall for them? Why do they actually think that just having this additional tool can solve a challenge without properly using that? I'm always thinking of that cargo cult term that Alex, our colleague, tries or likes to use. So is it necessary to have everything or why are organizations falling for that, Jonathan?
Well, I think I like the cargo cult piece because I think that applies very well to the ways we're thinking about AI in general. But I think as far as a tool suit goes, I think there's this pressure to consolidate. And the promise from I think many vendors is if you consolidate, then by using this tool, a manager of managers, you'll get your consolidation. And I think it's a myth. We're not actually escaping the tool suit. I think we're building bigger cages with fewer vendors in. And what happens is that complexity hasn't actually gone away.
It's just buried in vendor integration layers that we don't control. Yeah, so I think one of the aspects why people go for these new tools is they know they haven't solved everything, which is really hard to do in a fast-moving field like identity management and also cybersecurity. They are afraid of if they don't do something, they may become the victim of audit findings, of cyberattacks, whatever. So better do something fast, sometimes might be rational behind that. And clearly it's also this hype of things which is pushed, so you need this and this and that.
And I think there's a good reason that we came up a couple of years ago with this concept of the identity fabric, which if I remember right, had this sort of initial ideas in a joint advisory project where you, Matthias, and me were involved. So it emerged from there, from practice as well as from the research and the analyst side, something which is built to help organizations to structure what they are doing, to understand which are the gaps, which are the biggest gaps, which are the things they don't need yet.
And moving forward together as a reference architecture in a really structured manner towards something which becomes more and more integrated. I think that also leads to something which I still observe in many organizations. So we see a lot of organizations adopting paradigms like the identity fabric and really trying to consolidate initiatives. But we also see a lot of, and this is something I still hear way too frequent, we don't have the time to do proper architecture roadmap, et cetera, work.
This would be the same, I think, standard comparison, standard picture, the same like building a house without any architects and any engineers for the static stuff, et cetera, doesn't make sense. So don't do it for IAM.
No, I like identity fabric and I think that the architecture looks lovely. I guess my concern, if I'm going to play the devil's advocate here, is that we run the risk of going into a very brittle environment. So you have many, many connectors and everything works until it doesn't. And when you're then troubleshooting, you then have not one vendor, you have five vendor support teams, all of whom are pointing fingers at each other. And so that can be even more challenging.
But I think the concept of the identity fabric is lovely and I like the idea that identity, when it works, should be something that fades into the background. It should become part of the infrastructure. But to bring up a counter argument, in today's world of identity management, you always have multiple connectors.
So even if you go to the same vendor and say, okay, I buy a GA, so identity governance, administration, life cycles, et cetera, I buy access management, I buy PAM from that vendor, you most likely will end up with three tools from the same vendor with three different connectors, very likely. I think if we move to something which helps us, for instance, onboarding, and I think amongst the big problems we are facing at IAM is definitely application onboarding. That is something, by the way, where AI can help us in speeding up things and simplifying things and automating things.
We can handle that quite well. And then I think the orchestration clearly is the thing which is a bit sort of a new playing field for most organizations.
Right now, we mostly see custom bidirectional bespoke integrations versus building on orchestration layer that allows us a very flexible integration. So we see things clearly that are new, that are a new playing field, require a new experience. But overall, I personally believe that, especially with the flexibility of the identity fabric, where you can say I purchase most from my preferred supplier and just fill the gaps. Or you say I go for the best of breed. Both works in the paradigm of the identity fabric. So there's the choice still.
And it also reflects that virtually no organization starts identity management on a green field. Most have a lot of fields which are not used at all currently or not covered at all. And then they have some brown field and maybe some black field even. So all that legacy stuff that doesn't work anymore after 15 years. And still you can incorporate this into this picture and also think about how do you migrate at your own pace. But I don't want to dig too deep into the identity fabric because there's a ton of research, a ton of podcasts that are around it.
And I'm absolutely sure that Matthias will put a lot of links into or around this podcast to give you some hints. And by the way, good situation here to hint on their subscriptions. If you want to access everything, go for KC membership. But back to you, Matthias and Charles.
Yeah, okay. But I think maybe Jonathan mentioned that already, playing devil's advocate. I think some reason for this IAM tool zoo that we are seeing is that many organizations are still struggling with lots of not only technical debt but process debt. So that they really understand that they don't understand maybe that some of the issues where they are throwing new technologies at are problems that should have been solved earlier. Parts of NHI that we talk about are technical accounts.
Hey, this is Pam. That should have been done 10 years ago. If we look at let's throw AI and access intelligence on my IGA.
Yeah, this is access governance that should have been fixed 12 years ago. And on and on and on. So this is really something where new and really intelligent vendors come along, create a new great acronym, a new kind of new tooling. And that comes with the promise of solving everything. And that extends the platform landscape on and on, right? There's an interesting lagmas test you may apply. If most vendors in one of these new segments are in fact established old vendors, then most likely there's not that much fundamentally new in it.
For IWIB, this identity, visibility, and intelligence platforms, big quotas, I would say the vast majority of vendors that jumped on IWIB have been around for quite a while. I think, yeah, IGA is something that fascinates me, although I try to observe it from a distance. It's been a perennial problem.
I mean, I was auditing systems 20 years ago, and I was saying, what are you doing about your joiners, movers, and levers? And people go, I don't know. And we have improved on that. But nevertheless, I think this idea of one governance layer gives us one failure domain. And we get efficiency, but we also get fragility in equal measure. I think the problem with AI is the amount of data obviously an AI needs is quite significant. And the idea, I am an AI enthusiast, as indeed I think all of us are, the idea of real-time analytics on policy, on a governance, sounds wonderful.
I think in practice, what we're trying to do is what we used to try and do with SIEMS 15 years ago. We're trying to grab everything, every signal we can, and stuff it into an AI, into an analytics engine. But the signal-to-noise ratio, I think, is going to be terrible, and is what defeats us. Which I think brings up some interesting thoughts about where do we see evolution. I think one is thinking about more integrated governance layers. So you said there's a challenge with that. I think there are two layers. The one is early governance from a process perspective.
The other is more dealing with the amount of signals and making sense out of the signals. I see some tendency towards saying, okay, we need, first we need governance for areas where we hadn't governance, like what we call non-human identities, or part of that agendic AI, where we just have a lack of governance. We need it. And we should work, and I see some players in the market working on avoiding that we end up with a lot of governance silos and moving more towards a holistic perspective.
And a lot of things like ownership, et cetera, and risk exposure, risk information can be handled quite well here. The other element you brought up, and I think both are worth to further discuss right now, the other element really is how can we make, or what do we need to do to make AI results better? I think we hear every day, we read every day about alert fatigue of SOC analysts, for instance, about burnouts even. I think we are learning that AI is pretty good in spotting anomalies, but pretty bad in understanding the context, the reason of that.
Is this a real anomaly, or is this something which a human can easily spot and say, oh, yes, it's the first time we run this AI, and it hits the end of year bookings in our ERP system, and yes, there is something different by the end of the fiscal year than it is for the rest of the fiscal year. Very obvious anomaly for a human, not necessarily for an untrained or just supervised, trained and learned AI.
So I think we will see evolutions, but I personally believe, and this would be another theme which I see as a trend, that we will see a massive use of shared signals for many use cases with quite some learning curve. Right, and I think that is exactly providing that additional amount of data that we need so that we can better understand what's actually going on. What do you think, Jonathan, could that be an area where AI really can add value?
I think one of the challenges of shared signals is we're asking vendors to share the wealth, and there's no doubt that this is the right thing to do for their customers. It's something that Martin, myself and Smallway, we've all been calling for vendors to be more open.
However, of course, vendors don't want to lose what they see as an opportunity to corner the market. They don't want to lose the opportunity to obviously embrace the customer, and so that incentive to share signals I think is broken. I think IDTR is a great thing, but it's showing that correlation is hard. Correlation is not easy, and the same things we saw with SIEM 15 years ago.
We don't, as far as I see, have very strong and rigorous standards for identity telemetry, and I think the reason that these don't exist is because vendors, I think, benefit from lock-in. So, we need to encourage everybody, our clients, and as Martin said, this is one of the things we talk about in our memberships. We encourage vendors. We encourage end users towards what we believe are beneficial best practices, and we need to encourage all of us to move to this shared part of shared signals, not just marketing, but reality.
Martin, do you agree? I think, first, the good thing is we have, right now, standards out like shared signals framework and other standards around it, which is great.
So, we are finally moving to a world where we have standards to share signals, share telemetry information. I think it depends very much on the domain, whether there's a willingness also of end-user organizations to share information, and there's also, it's in the organizations, clearly, the challenge of how do you make sense of signals from different domains?
So, we are not horribly bad when we look at whatever network level and system level events in our SOC tools. We are not far from perfect reductions already. Identity is, in tendency, a bit more complex because there's the business process behind. We have continuous controls monitoring.
So, when it comes really to the business systems, business transactions, and clearly for an attack, it would make a ton of sense to look at everything from a deep fake detection signal to what is going on in the network. Is this user actually somewhere authenticated?
So, if there's something happening in a session, two, or whatever, and the user is nowhere authenticated in your own domain, then probably there's something wrong. And then looking at what transactions are happening, is there money sent somewhere? If you join all that, it makes perfect sense. But the challenge is you then need to, so to speak, or you need to have, I try to avoid the term train, you need to have systems that are capable of making sense of way more different types of signals than before.
So, solving a certain problem domain and optimizing is relatively simple. The more problem domains you bring together, the more complex it is, even for AI. Right. And just if we strike out the shared in the signals, not shared signals, but just signals using them for authentication, for continuous authentication, we want to talk also about technological trends or trends that are finally manifesting within enterprises and organizations in general.
Will we see in 2026, really the advent of continuous authentication based on a lot of internal signals, not necessarily shared, so that we better understand what our end users are doing because we collect more information and can decide more frequently and more accurately what's going on. Jonathan, do you agree? I do.
And I'm, again, obviously very interested in Martin Jew here. I love the concept of security. I love the concept of continuous authentication.
However, when I talked to one of the big web provider security managers, they said, you know, our concern is tokens have lifetimes of hours or even days. And so we get really, really panicky when we hear any kind of endpoint event where tokens are at risk, where tokens are exposed. Because the UX is continuous for continuous authentication, but the security is still point in time, point in time. And the idea of behavioral baselines, I think, is still not there because normal behavior does change. We do evolve our behavioral habits.
And so, again, you end up with what Martin quite rightly referred to earlier. We have false positives leading to alert fatigue or they just get tuned out. But I guess I used to be a huge fan of the whole piece around privacy and surveillance and employee monitoring and so on, how that can combat insider risk. But it is still surveillance. Transparent monitoring is still monitoring.
And I think that we are starting to see resistance in many privacy aware communities, such as many of the countries in the EU, to this idea of continuously being monitored, whether it's behavior monitoring, whether it's activity monitoring. The backlash, I think, is starting to grow. The resistance against it is starting to grow. I have another question that's negative.
So, first, I think, yes, we will see quite some major evolution around continuous authentication, maybe also leading the path this way into passive authentication where we don't actively authenticate anymore. That may take a bit longer.
So, we will see things there. Some I know, some I can't talk about yet, but there will be some interesting announcements from some players in the market, for sure.
So, that is something which will happen. Will there be too much resistance? I think it depends on what you're looking at.
And, you know, when you look at how you handle it, I think this is the point. So, if you say, okay, for this transaction, you need another sort of approval or just verify that it's really a transaction you want to do, and it's in the business context, I think this will work relatively well. And I think we also must not underestimate that people even here or in Europe become more and more used to it.
So, when I take my car, which I bought earlier this year, that car is basically constantly watching me as a driver. And when I appear to fall to sleep, it will do an emergency stop, which is, at the end of the day, positive, which is probably something you need to get used to. But I think it's always a matter of what do you do, how do you do it, what is the purpose? And this is well understood and felt as being something which is sort of intrusive and going beyond what is acceptable.
And I think there are enough scenarios where this continuous authentication can really make a lot of sense and deliver a lot of value. So, I think we will see a significant uptake here. And when we go back, I remember if we would have done this podcast 10, maybe 15 years ago, we may have talked about biometrics that make a lot of sense but are not accepted until Apple introduced fingerprint sensors on the iPhone. And then later on moved to face ID, perfectly accepted nowadays. And we had a lot of discussions there.
So, I think it's also a bit of getting acquainted to that and understanding for what is it used, how is it used. And at the end of the day, the benefit must be bigger than the sort of the negative side of the fear and the risks and stuff like that. But honestly, every one of us, I think nowadays, or a lot of at least, a lot, not everyone probably, but a lot of us are scared by the cybersecurity risks we have. We don't want to be the entry door for the attacker.
So, if something happens, hopefully it's not our system, our endpoint to come in. So, at the end of the day, doing these things well also takes a burden from every user. Do you think that this model then of, as you say, consumerization of technology, do you think that will happen that we will become so used to, as you say, I mean, my car, yeah, I don't drive a nice car like yours, I just have a cheap Hyundai. But I love it anyway.
But yes, it also has this behavioral monitoring. So, we get used to that. And I guess my TV says, are you still watching this Netflix series or whatever?
So, yeah, we are getting used to our consumer devices are watching our behavior. So, as you say, that does tend to get societal acceptance. Do you think then that we'll get to the stage where, as you say, this will just be part of the workplace that we expect that our mouse movements, our application usage will be routinely monitored? Isn't it that we always want to have a workplace being as smooth as the stuff we use in our personal life?
There are some capabilities built into M365, for example, where I would say, okay, is this really not a bit too much to say, okay, there's an interesting document that you could be interested that your colleague is working on. So, this is this recommendation that you usually see really from social media platforms. And now it says, okay, yeah, there's somebody working on a similar topic with a document that you can open up here. And we are used to that. This is already there, this recommendation system.
So, the question is, is it helpful? Is it cheesy? Is it too intrusive? Or does it just help me in my daily work, Martin? I would say yes, yes, yes, and yes. It's helpful, it's cheesy, it's too intrusive, and it's really good for the daily work.
So, at the end of the day, I think it's yes to everything. But on the other hand, everyone working in an organization, probably bigger than one or two people, knows that there are scenarios where you, at some time, learn that someone already has been looking at whatever this and this and this.
And so, that also can be extremely helpful. I think it's even maybe from a management perspective, sometimes positive, because it tends to drive a culture of more openness and less silos in organizations.
So, I think you can find a lot of positive things. And interestingly, when I learned about that feature at the beginning, I felt, oh, this is a bit weird. In my daily work so far, I never felt it being really problematic to me. Sometimes it's helpful, sometimes I just ignore it. But at the end of the day, the positive things clearly outweigh, by far, the negative things. I think you make a great point that security, identity, all these things exist to serve the organization. They don't exist to rule the organization.
And as you say, what's important is that we enable people to collaborate and communicate easily and quickly. And I think, as I say, without the tools that enable that, you end up, as you say, with vastly reduced productivity. If it's an effort for me to communicate with Matthias or with Martin, then I'll just figure it out myself. If it's something I can do easily and quickly, I can just say, hey, put a little note in Docky and say, hey, Martin, what do you think about this point? Martin will see that and go, oh, this is what I think. That is transformative.
And especially for companies like CuppaCocoa is a, as you know, is a remote first company. Many of our end user organizations are now finding that balance between in-office and remote first to get the best out of their talent. And tools that enable that and support that, I think, yes, absolutely valuable. Okay.
Well, almost apart from the 30 minutes, which we planned for, there is a ton of topics we haven't covered yet. We have not talked about PAM. We have not really talked about NHI. We have not really talked about all this decentralized identity, EUDI, ecosystems, et cetera, et cetera. So I assume there will be a follow-up episode anyway. And I also think we should have an episode on cybersecurity, which we have not yet touched at all, unless it's part of IAM, which it is, of course. But maybe as a final question, just a quick round for all three of us.
When you think of IAM in 2026, what do you think is the one capability that is new in 2026 in real life, in an identity fabric, a new capability that hasn't been there last year or two years ago? What is really new in IAM? What do you expect to be really there in IAM? Jonathan? I have one that I love, and it actually springs from what Martin was talking about, the consumerization of technology. Passwordless authentication touches everything. And passwordless simplifies and indeed improves greatly the security authentication process.
I am quite the fan of it, and I expect to see that being more and more prevalent in 2026. Hopefully beyond just the workforce world into the consumer world, because you still have way too many passwords there. I was setting up a new computer and then a different platform, installing a couple of apps, adding some apps. I needed so many passwords. And we are in 2025, and it's still like in the 1990s. Sorry. I think a lot of developers need to really learn about that there is passwordless.
So the one thing I hope we will see gaining quite some traction, also another thing we didn't touch today, that is, I would say, new forms of authorization, externalized authorization, policy-based, attribute-based, whatever, access control, all that stuff. I think there's a huge need to make progress on that. And by the way, without that, we will never solve the challenge of security and identity for agendic AI. No way to do it without. Right. And if I may add something, I think it's not really a capability in its own, but it's built into so many, I think, automation and orchestration.
We've mentioned that at the very beginning to really understand what should not or no longer be done by a person, but which can be put into a policy that can be implemented and then automated and more or less forgotten because it does things right in the background. I think this is something that we need to learn even more than to bring this into real life automation authorization. And when you say NHI and agentic and all of these new identities that we have around, you cannot deal with them without proper automation and orchestration. We need just to make sure that it's done right.
Otherwise, it's garbage in, garbage out. But proper automation, I think that will be a good starting point as well to have that finally working in 2026. We're at the end of our time.
Jonathan, Martin, thank you very much for being here. We did not make half of what we thought of. We didn't really plan. We just had a list of ideas. I think there's room for working on that list again. That might well be the theme of 2026. That might be true. Final thoughts, Martin, before we close down? A lot of stuff going on. I think at the end of the day, we should keep in mind most identity management is still evolutionary, not revolutionary. At the end, most organizations really will need to look at building a solid, solid baseline, a solid sort of basic hygiene across everything.
And as you said, also think about not only technology, organization about processes, policies, all that stuff, because the best tool won't help you if you don't do the other things right. Thank you again, Jonathan, Martin. For those who are watching this, if you have questions, if you have comments, please leave them on YouTube in the comment section. Reach out to us and send a mail to Jonathan, to Martin, to me. We promise we will reply. Watch this space for part two of AM predictions for 2026. Thanks again, and looking forward to talking to you soon. Thank you. Bye.