Thank you, Alexei, for that introduction. So, that's what I'm talking about, a little sort of word of warning that what I'm going to be talking about might give you some ideas about what's going to happen in the next five years, or it's just as likely to confuse you even more than I'm confused. But let's go.
So, why are we talking about all this? Well, what business needs in five years is pretty much what it needs now, but it's going to need it a lot more, like basically secure human and machine access across everything. We talk about AI a lot at this conference, and there's been some fairly scary stuff about what AI is going to be able to do in terms of deep fakes and cyber attacks.
But on the other side, I think that we will be seeing AI being used in a good way, and hopefully we will see that our privilege access systems, our entitlement systems will be able to use some form of AI to create a policy logic engine, as I've called it here. Basically, that means something that would automate policy management, policy generation, et cetera. And so we need adaptive, fast, and context-aware privilege controls. Context-aware means that it can look at exactly what's happening in that very moment, and identity is looking for access. So that's kind of where we are.
Oh, I just realized I was looking at the wrong slide. So anyway, there is actually something I want to get off my chest about the industry. So up until about 12 months ago, everybody just talked about machine identities and us, humans. Then all of a sudden, I noticed the industry started talking about NHI, and it's everywhere now. Everybody wants to talk about non-human identities as if they're something different.
Well, for me, there's only human identities and machine identities, and within machine identities, they can be all the stuff that people are now talking about by NHI. So I'm kind of saying to vendors, please, will you stop reinventing stuff so that it makes it look like you have some new capabilities?
So for me, we only have human identities and non-human. That bust about will cover everything from Alexei to a space rocket in terms of what is an identity. But there will be one thing coming along which comes under machine identities, which is our friend, agentic AI, which I'll talk a bit more about in a minute. But this is where we get into this world of chaos, which I think is about to come to pass. And I'm not talking about what President Donald Trump is doing right now, but I'm talking about in our world.
But all of these identities, including obviously human identities, can also have a human controller, but we'll get into a situation where identities may have another identity controlling it and so on. So that's just the start of the sort of environment that we have. But let's just keep our terminology a little bit clearer. Because the real issue isn't labels, really. It doesn't really matter in the end whether an identity is human, whether it's not. It's actually what it's doing, who owns that identity.
Is it a, you know, API token? Is it AI, virtual machine, etc.? And that's when you start thinking about the context of the identity and what it's doing, what it's trying to do. So identity hygiene is hugely important. So you need to understand about the traceability and ownership and accountability of those identities much more than what it is.
An IDA, which is basically, to use an old-fashioned term, which is still going to be relevant, because in the world of multiple identities, governance is going to become even more important than it is now. And governance is probably a thing that a lot of organizations kind of overlook more than anything because they're so focused on access and authentication in the moment. So just to go back to that, you can see that different vendors have different ideas. CyberArk sees NHI as simply a subset of machine identity. CrowdStrike differentiates all the NHIs by type and so on.
And SailPoint are the one actually thinking about NHI into IGA. And you can see that their focus areas slightly converge, which is what this presentation is about. But terminology is something, again, which I think we need to clear up before we can even start making sense of all this. So why does this matter?
Well, obviously it matters because of what's happening. Like cloud, although even right now it still isn't actually the dominant platform, it's certainly going that way. So in five years, 2030, cloud will undoubtedly be dominant. We also have the whole world of what we call DevOps. But DevOps is not just developers anymore. It's people using low-code, no-code tools. It's people downloading their own server. It's people using ChatGPT. All of that is complicating and making the whole issue much more urgent than I think it's ever been. And people are interested in zero trust.
But at the same time, trying to implement zero trust into this environment is harder than ever. And I think another bugbear of mine is that people often get hung up on zero trust, thinking they have to have a zero trust network.
Well, you don't actually have to have a zero trust network altogether. It's an important thing. But trust has to be prevalent somewhere in your architecture. The thing is, having zero trust in this coming world, I think is almost going to be impossible. We'll see. But at the same time, everything is fragmenting. There are more and more software tools. There are more and more things to download. Companies are using multiple service management tools. They're using multiple communication tools. And this creates more friction. It creates opportunities for people to create new identities.
And it creates risk. So to get back to more concrete discussions, where should organizations go to try and manage all this? Should they integrate more different applications? Should they platformize?
Well, platformize is another buzzword. Or should they rebuild everything? All of those things might happen. But a platform as well has two definitions. So there is a platform you can buy from, say, CyberArk. Or a platform you can buy from SailPoint. And they'll call it an identity platform.
But also, you can build your own platform. And you can develop a platform if you have the resources within the organization. But we are seeing in this space, so in the PAM, in the CIM space, and in secrets management, that technologies are starting to converge. Not technologically so much, but vendors are acquiring these technologies because they want to say that they have a platform that can do every kind of identity management.
Now, Identity Fibrex is something else which people talk about a lot. And again, I prefer to just talk about best of, like, joining together applications to create the outcome that you want. Not necessarily a fabric or a mesh. And then finally, people are still using individual software applications for particular cases. And in surveys of professionals in, for example, the finance sector, when they were asked if they wanted a platform given to them by a vendor, or whether they prefer to have best of breed for individual applications, they prefer best of breed.
So buyers are entering this new era with the same mindset that they've had right up until now. They don't necessarily want to be locked into one vendor or one platform. And this chart just quickly shows you what the technology, sorry, which professionals, the things that they are interested in procuring right now. And you can see that CIEM is down there at number four. So there are definitely some trends happening. And so it seems to me like there is definitely a demand for stuff, but they don't really know what it is they want, if that makes sense.
So it's kind of like this, a cone of uncertainty. A cone of uncertainty basically is a sort of a tunnel of time. So we have near term, long term. And so right now in the cone of uncertainty that we are currently in, so we have zero trust, just-in-time access, privilege, spoiler, all trends.
Long term, divergence in tools, definitions, governance, models, exactly what's happening. The beginning of that is happening right now. And then the takeaway from this tunnel is for a future of multiple technologies. So that is the cone of uncertainty as designed. And so basically we are now, and then as time, all the options start expanding, and then say, so this is 2030, then we might have a number of outcomes which are going to happen. So we have a wild card, we have a scenario, we have probable and preferable outcomes. So let's just look at some of those.
So probable, these are my predictions of what's going to happen in this space, is that CIEM, which up until now has been considered sort of like the poor relation of privileged access, CIEM will become like the new control plane, because cloud will be dominant. And secrets management, which at the moment is treated as a kind of a separate sector, or a separate product, will also be integrated into CIEM and privileged access management.
And PAM, traditional PAM will be re-engineered to be cloud native. So those things I think will definitely happen, particularly with SIEM, KIM and PAM. What will be preferable is unified access policy engines, which could be automated, so they run right across all of these applications, so KIM, PAM, etc. And then we have data-centric access policies.
We've forgotten a little bit about what it is we're accessing, but if we actually start thinking about the data that we're accessing, or trying to access, whether that's privileged or not, that will affect the policy, and it will affect how and when people can get access. And of course, DevOps and engineering is becoming, you know, so many organizations now are forever reinventing their software, they're reinventing applications on a daily basis.
So DevOps, engineering, whatever you want to call it, is becoming a huge, huge area for vendors to be looking at, and you'll see a lot more development in that area. But that will actually have knock-on effects for what you might call more pedestrian access for end users, etc.
We might see plausible, I think this is plausible, given the pace of development in AI, so you might see some kind of entitlement reasoning, so we have like an AI-driven brain, so as it were, that actually can analyze whether an access request is able to have it, and that would include all the policies, it would include all the context, etc., etc.
And we'll see PAM, post-PAM models, so that people no longer just talk about privileged access management as, you know, standing privileges and privileged accounts, but where everybody like, and to quote Andy Warhol, everybody in the future will have privileged access, maybe, you know, for 15 minutes. And zero standing privileges, or zeroing standard privilege policy has got to surely happen, so we'll talk about pre-execution, so that everything is, nothing ever has a standing privilege whatsoever, which means the old model of privileged access management should disappear, should.
And then, I don't know, this is possible, so this is like real crystal ball, that IGA will be replaced by some kind of identity broker that works across everything. We will have continuous contextual pre-authorization, I should say, based on behavior drift, privilege creep, and again, what has happened to that identity since the last time it tried to gain access.
So they, we will see that kind of stuff possibly emerging in these new Converge, Kim and Pam solutions. Privilege enforcement embedded in runtime, that might happen. Kind of repeating myself slightly here, AI access intent, replacing any kind of something based access control. I think the merger of all identity types is kind of what I was trying to say right at the start, that what an identity is should matter less than what it's trying to do.
So, because we simply, I don't think in the future that you'll be able to manage identities like we do with, you know, Active Directory and things like that. So the old models of IGA are going to disappear when you've got AI creating new identities all the time. And then this is something else which I think is quite significant, is that companies like ServiceNow are already starting to experiment with privilege access and Kim. And if you just look at this, you can see that the workflow from Kim and ITSM are almost identical.
So, this then is my prediction of what will happen. This is a marketing graph and interest from buyers. So I'm saying that towards 2030, IGA will be less marketed by vendors and less sought after by buyers. And the same will happen to what we now call privilege access management. And Kim and ITSM will become much more important. And I think all this, what's happening here is that you're seeing these platforms being developed within the industry and you're seeing M&A activity so that different companies are buying smaller startups.
But I predict, and obviously it's easy to predict something that's five years out, but I think we'll still see identity and access management systems being marketed. But within that, I think that some form of Kim or ITSM will be a lot more dominant.
So, we shall see. So, some quick takeaways then.
So, a likely future is a kind of unified privilege access control. So, organizations now have to think about whether to integrate more applications, more platforms. Do they need to converge or look at convergence or rebuild? The Pam and Kim convergence will hopefully deliver a hybrid access control framework for all identities. But there may still be, and this is when you suddenly sort of tread backwards from 2030 and look at actually what's happening in the real world right now.
Still, some companies will still want traditional Pam. They'll still want and happy to have people with standing privileges, but probably for low risk or highly secure on-premise resources, rather than what's in the cloud and what is being built all the time and what they can't actually control because it's so nebulous.
So, that's a likely future. So, what would I say to buyers right now?
I'd say, well, I would start to really think about Kim. Prioritize some form of cloud management and enticement. And don't forget that a lot of Kim providers don't just do a governance or a admin job. They actually do privileged access as well, which is why the established big privilege access providers are worried.
So, you should, if you have a hybrid infrastructure, then look for Pam vendors that are now building good Kim features and legacy IT. So, basically, if you really, really have absolutely no cloud at the moment, well, you're probably okay with traditional Pam, but you probably should start thinking about the next steps. Because don't forget, even if you have everything on premise, you're still going to have all those people developing stuff. You're still going to have all those people experimenting with chat GPT and other stuff.
So, I know I'm out of time. So, don't get locked in. Choose your own convergence. And think about the wild cards that I talked about earlier.
So, very quickly, the end game. I'll just read them out. Pam and Kim and NHI machines, the market and the tech is converging from that chart I showed you. Autonomous Pam will assign and rewrote privileges in real time. That's kind of like the dream we talked about just in time, but it isn't real time. Agentic AI machine management becomes a core focus. I was going to talk more about that, but I can't.
The winners in all this will be the vendors, which I believe come up with more than the identity platforms, which they talk about right now, but they're kind of unified, AI-powered, identity-focused platforms, but aren't just things cobbled together. The winners, again, will also be those innovative Kim providers, which are already shaking up the market at the other end, and you, buyers, if you keep an open, agile mind and inform yourself about what's happening. And that's it. Thank you very much.
Thank you, Paul.