<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Software Analyst Cyber Research]]></title><description><![CDATA[We deliver clear, concise, and in-depth analysis of the rapidly evolving cybersecurity landscape—built for cyber leaders, operators, and investors.
]]></description><link>https://softwareanalyst.substack.com</link><image><url>https://substackcdn.com/image/fetch/$s_!aVzH!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9b7f1c9-9f34-4227-9c42-0aa5b4b03587_512x512.png</url><title>Software Analyst Cyber Research</title><link>https://softwareanalyst.substack.com</link></image><generator>Substack</generator><lastBuildDate>Fri, 31 Jul 2026 23:20:56 GMT</lastBuildDate><atom:link href="https://softwareanalyst.substack.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[SACR]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[softwareanalyst@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[softwareanalyst@substack.com]]></itunes:email><itunes:name><![CDATA[SACR]]></itunes:name></itunes:owner><itunes:author><![CDATA[SACR]]></itunes:author><googleplay:owner><![CDATA[softwareanalyst@substack.com]]></googleplay:owner><googleplay:email><![CDATA[softwareanalyst@substack.com]]></googleplay:email><googleplay:author><![CDATA[SACR]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Fast Take: Cyera’s Acquisition of Oasis Security - Can Data and Identity Security Truly Converge?]]></title><description><![CDATA[Assessing the strategic rationale, execution risks, and enterprise realities behind the convergence of data, identity, and agentic security]]></description><link>https://softwareanalyst.substack.com/p/fast-take-cyeras-acquisition-of-oasis</link><guid isPermaLink="false">https://softwareanalyst.substack.com/p/fast-take-cyeras-acquisition-of-oasis</guid><dc:creator><![CDATA[Jamie Feder]]></dc:creator><pubDate>Fri, 31 Jul 2026 18:11:53 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!FRyE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe33583c-a79b-41bf-aba3-7c355daf318d_1920x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p></p><p><span>Earlier this week, </span><a href="https://www.cyera.com/"><span>Cyera</span></a><span> </span><a href="https://www.wsj.com/pro/cybersecurity/cyera-to-buy-oasis-security-in-1-billion-deal-af998439"><span>announced an intent to acquire</span></a><span> </span><a href="https://www.oasis.security/"><span>Oasis Security</span></a><span>. To understand the nature of this acquisition, it should be viewed as a strategic initiative designed to merge data security, non-human identity (NHI), and agentic security into a unified control-plane narrative.</span></p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!FRyE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe33583c-a79b-41bf-aba3-7c355daf318d_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!FRyE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe33583c-a79b-41bf-aba3-7c355daf318d_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!FRyE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe33583c-a79b-41bf-aba3-7c355daf318d_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!FRyE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe33583c-a79b-41bf-aba3-7c355daf318d_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!FRyE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe33583c-a79b-41bf-aba3-7c355daf318d_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!FRyE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe33583c-a79b-41bf-aba3-7c355daf318d_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fe33583c-a79b-41bf-aba3-7c355daf318d_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!FRyE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe33583c-a79b-41bf-aba3-7c355daf318d_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!FRyE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe33583c-a79b-41bf-aba3-7c355daf318d_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!FRyE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe33583c-a79b-41bf-aba3-7c355daf318d_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!FRyE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe33583c-a79b-41bf-aba3-7c355daf318d_1920x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Software Analyst Cyber Research! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h3>Executive Summary</h3><ul><li><p><strong>SACR&#8217;s assessment is that the acquisition is strategically coherent because of the rise of AI agents, but work lies ahead to make it successful.</strong> This acquisition gives Cyera a credible path into the identity market and agentic security, but the value of the deal will depend on whether the company can unify data and identity context at the policy and enforcement layers. </p></li><li><p>It is well-known news that Data has become a catalyst for agentic security transformation. Similarly, agentic identities are believed to now surpass humans 144:1 in cloud environments and are believed to be outnumbering human users by an average of 45 to 1.<a href="https://labs.cloudsecurityalliance.org/research/csa-whitepaper-nonhuman-identity-agentic-ai-governance-v1-cs/"><sup>1</sup></a>  </p></li><li><p><strong>Data and identity security</strong> have historically been managed by separate enterprise teams with different budgets, systems of record, workflows, and policy authorities. However, AI agents may become the catalyst that forces these domains closer together. Agents routinely operate through delegated human permissions, service accounts, APIs, workload identities, and automation frameworks while accessing and acting upon sensitive enterprise data. As a result, organizations can no longer evaluate identity risk independently from the sensitivity, purpose, and context of the data being accessed.</p></li><li><p>This creates an opportunity for Cyera and Oasis to bridge the historical divide between data-security and identity-security teams by providing a shared understanding of <strong>what data exists, which human or non-human identities can access it, what actions they are taking, and whether those actions should be permitted</strong>. Yet AI-driven convergence at the technology layer will not automatically resolve fragmented ownership at the organizational layer. Cyera must still prove that the combined platform can establish a clear economic buyer, enable workable cross-functional governance, and deliver credible runtime enforcement.</p></li><li><p>The market should therefore evaluate the acquisition through integration depth, customer adoption, enforcement authority, organizational alignment, and measurable security outcomes. AI agents may accelerate the need for data and identity convergence, but Cyera must demonstrate that it can turn that market pressure into an operationally unified and commercially viable control plane.</p></li><li><p><em>Disclosure: Cyera is a SACR advisory client. SACR&#8217;s analysis remains independent, and vendors do not receive editorial control.</em></p></li></ul><p></p><p></p><div><hr></div><h3>The Organizational Reality of Data &amp; Identity Teams</h3><p>Data security and identity security have historically developed as separate enterprise disciplines. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!awB4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7febd997-584f-40a3-a28f-332657c5c358_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!awB4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7febd997-584f-40a3-a28f-332657c5c358_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!awB4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7febd997-584f-40a3-a28f-332657c5c358_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!awB4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7febd997-584f-40a3-a28f-332657c5c358_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!awB4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7febd997-584f-40a3-a28f-332657c5c358_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!awB4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7febd997-584f-40a3-a28f-332657c5c358_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7febd997-584f-40a3-a28f-332657c5c358_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:162478,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://softwareanalyst.substack.com/i/209277749?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7febd997-584f-40a3-a28f-332657c5c358_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!awB4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7febd997-584f-40a3-a28f-332657c5c358_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!awB4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7febd997-584f-40a3-a28f-332657c5c358_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!awB4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7febd997-584f-40a3-a28f-332657c5c358_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!awB4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7febd997-584f-40a3-a28f-332657c5c358_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p><strong>Data-security teams typically concentrate on:</strong></p><ul><li><p>Data discovery and classification</p></li><li><p>DSPM</p></li><li><p>DLP</p></li><li><p>Privacy and regulatory requirements</p></li><li><p>Data lineage and residency</p></li><li><p>Data exposure and exfiltration</p></li><li><p>Collaboration with data owners and privacy teams</p></li></ul><p><strong>Identity teams typically concentrate on:</strong></p><ul><li><p>Identity lifecycle management</p></li><li><p>Authentication and federation</p></li><li><p>IGA</p></li><li><p>PAM</p></li><li><p>Entitlements and access reviews</p></li><li><p>Segregation of duties</p></li><li><p>Service accounts and workload identities</p></li><li><p>Integration with HR, directories, cloud IAM, and application owners</p></li></ul><p>These teams often use different systems of record, operate under different leaders, and have different definitions of risk. The argument is that AI agent security has converged these two together.</p><p>Cyera&#8217;s acquisition thesis attempts to connect these areas. However, the enterprise does not necessarily have an established function responsible for the combined answer. The collapse of the technical boundary between data and identity does not automatically collapse the organizational boundary between the teams responsible for them.</p><p>Cyera may therefore have to create not only a new product architecture, but also a new enterprise operating model involving:</p><ul><li><p>Shared policy ownership</p></li><li><p>Joint risk scoring</p></li><li><p>Escalation procedures</p></li><li><p>Cross-functional remediation</p></li><li><p>Data-owner participation</p></li><li><p>Identity-team approval</p></li><li><p>Security operations involvement</p></li><li><p>AI governance oversight</p></li></ul><p></p><h2><strong><span>Strategic Rationale: Data, Identity, and Agentic Security Converge</span></strong></h2><p><span>Cyera has been moving from a DSPM leader toward a broader trusted layer for AI: DSPM, DLP, identity-aware access governance, and agentic security. </span>Cyera maintains a solid data-security framework that includes Data Security Posture Management (DSPM) and Data Loss Prevention (DLP), AI Guardian, and data-context governance. By incorporating Oasis, Cyera gains specialized expertise in NHI, particularly in the posture (hygiene) and protection of service accounts, secrets, API keys, workload identities, and developing machine/agent identities.</p><p><span>Oasis gives Cyera a highly relevant entry point into this broader vision. 78% of organizations don&#8217;t have documented and formally adopted policies for creating or removing AI identities.</span><a href="https://digitalitnews.com/the-state-of-non-human-identity-and-ai-security-report-released/"><sup><span>2</span></sup></a><span> Agentic AI will intensify the threat of non-human identities, because agents frequently operate through delegated credentials, service accounts, APIs, MCP servers, and automation frameworks. 79% of IT Pros Feel Ill-Equipped to Prevent Attacks Via Non-Human Identities,</span><a href="https://cloudsecurityalliance.org/press-releases/2026/01/27/79-of-it-pros-feel-ill-equipped-to-prevent-attacks-via-nhi-csa-oasis-survey-finds"><sup><span>3</span></sup></a><span> which means there&#8217;s room for growth and adoption to deal with these critical agentic identity and AI agent issues.</span></p><p><span>The acquisition therefore links three control planes that are usually fragmented but require unity for the latest perimeter of protection with agents, including data context and identity visibility and control:</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!XIvo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68e1c4eb-b52f-49f6-9700-e01a7b711651_1657x925.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!XIvo!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68e1c4eb-b52f-49f6-9700-e01a7b711651_1657x925.png 424w, https://substackcdn.com/image/fetch/$s_!XIvo!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68e1c4eb-b52f-49f6-9700-e01a7b711651_1657x925.png 848w, https://substackcdn.com/image/fetch/$s_!XIvo!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68e1c4eb-b52f-49f6-9700-e01a7b711651_1657x925.png 1272w, https://substackcdn.com/image/fetch/$s_!XIvo!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68e1c4eb-b52f-49f6-9700-e01a7b711651_1657x925.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!XIvo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68e1c4eb-b52f-49f6-9700-e01a7b711651_1657x925.png" width="1456" height="813" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/68e1c4eb-b52f-49f6-9700-e01a7b711651_1657x925.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:813,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!XIvo!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68e1c4eb-b52f-49f6-9700-e01a7b711651_1657x925.png 424w, https://substackcdn.com/image/fetch/$s_!XIvo!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68e1c4eb-b52f-49f6-9700-e01a7b711651_1657x925.png 848w, https://substackcdn.com/image/fetch/$s_!XIvo!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68e1c4eb-b52f-49f6-9700-e01a7b711651_1657x925.png 1272w, https://substackcdn.com/image/fetch/$s_!XIvo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68e1c4eb-b52f-49f6-9700-e01a7b711651_1657x925.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Cyera analyst briefing materials (2026), adapted and reformatted by Software Analyst Cyber Research.</figcaption></figure></div><p><span>The strategic idea is not simply DSPM plus NHI. It is the arrival of Cyera as a platform player where data context will shape identity decisions, and identity context should shape data-access enforcement.</span></p><h2><strong><span>Oasis As A Logical Acquisition Target</span></strong></h2><p><span>Oasis is a focused NHI security specialist with relevance across service accounts, secrets, API keys, workload identities, and identity threat detection/response and posture. SACR workspace notes indicate that Cyera evaluated alternatives and selected Oasis after due diligence, with reported customer preference for Oasis over other alternatives because of perceived integration value.</span></p><p><span>That customer pull is important. The strongest strategic rationale is not that Cyera bought an adjacent category label, but rather that customers appear to want a combined view of sensitive data exposure and machine identity access. If Cyera customers are willing to replace standalone NHI tooling because the data integration creates higher value, the deal can improve long-term platform value.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!FRyE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe33583c-a79b-41bf-aba3-7c355daf318d_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!FRyE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe33583c-a79b-41bf-aba3-7c355daf318d_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!FRyE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe33583c-a79b-41bf-aba3-7c355daf318d_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!FRyE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe33583c-a79b-41bf-aba3-7c355daf318d_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!FRyE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe33583c-a79b-41bf-aba3-7c355daf318d_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!FRyE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe33583c-a79b-41bf-aba3-7c355daf318d_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fe33583c-a79b-41bf-aba3-7c355daf318d_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!FRyE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe33583c-a79b-41bf-aba3-7c355daf318d_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!FRyE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe33583c-a79b-41bf-aba3-7c355daf318d_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!FRyE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe33583c-a79b-41bf-aba3-7c355daf318d_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!FRyE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe33583c-a79b-41bf-aba3-7c355daf318d_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>Oasis also strengthens Cyera&#8217;s ability to talk credibly about agentic security; it had made prior visibility and control moves in data security, but entry of competitive identity offers would have created longer-term gaps in the Cyera portfolio and platform. In agentic environments, the boundary between identity, data, and action collapses. This is because agents are often inheriting human permissions, use service accounts, invoke tools, call APIs, or retrieve sensitive data through MCP-style integrations. That creates a need for identity governance that is both intent-aware and data-aware to connect data access and leak prevention with the identities that use and access them.</span></p><h2><strong><span>Strategic Strengths</span></strong></h2><ol><li><p><strong><span>Clearer market differentiation:</span></strong><span> Cyera moves beyond DSPM alone toward a broader data and identity security platform. NHI gives Cyera a credible wedge into the larger identity security market without starting with a frontal assault on human IAM incumbents.</span></p></li><li><p><strong><span>More complete security context:</span></strong><span> Combining data classification with NHI visibility can create a richer view of who or what has access to sensitive data, whether those permissions are excessive, and what actions should be allowed.</span></p></li><li><p><strong><span>Agentic security alignment:</span></strong><span> Oasis strengthens Cyera&#8217;s ability to address AI agents and machine identities, especially where agents operate through service accounts, delegated credentials, APIs, and human permissions.</span></p></li><li><p><strong><span>Customer-driven rationale:</span></strong><span> Cyera claims to have selected Oasis after due diligence and that customers preferred Oasis over alternatives because of the value of the integration.</span></p></li><li><p><strong><span>Platform expansion:</span></strong><span> The acquisition supports Cyera&#8217;s longer-term vision of becoming a control plane across data, identity, AI, and agentic activity.</span></p></li><li><p><strong><span>Behavior analytics potential:</span></strong><span> Oasis&#8217;s NHI behavioral baselining plus Cyera&#8217;s data-access baselining could enable higher-fidelity anomaly detection, especially around machine identities accessing sensitive data in unusual ways.</span></p></li><li><p><strong><span>Category timing:</span></strong><span> SACR&#8217;s broader research has been pointing toward convergence among identity, NHI, AI agents, MCP, runtime enforcement, and data governance and alternative platforms. This deal lands directly in that convergence zone.</span></p></li></ol><p></p><h2><strong><span>Potential Strategic Acquisition Challenges </span></strong></h2><ol><li><p><strong><span>Integration risk:</span></strong><span> The value depends on whether Cyera can deeply integrate Oasis into its data-centric workflow rather than simply attaching NHI features to the platform. Oasis is a focused NHI specialist; Cyera needs the acquisition to become part of a unified data-identity-action graph.</span></p></li><li><p><strong><span>Go-to-market complexity:</span></strong><span> DSPM, DLP, identity, NHI, and AI security can involve different buyers, budgets, and operating teams. Cyera will need a clear sales motion that explains who buys, what gets replaced, and what gets expanded.</span></p></li><li><p><strong><span>Pricing scrutiny:</span></strong><span> A high acquisition price for a focused NHI player may draw questions unless Cyera can demonstrate integration-driven value and customer pull.</span></p></li><li><p><strong><span>Category clarity:</span></strong><span> Cyera must explain whether this is a DSPM expansion, an identity move, an agentic security play, or all three. The answer can be &#8220;all three,&#8221; but the messaging must be simple enough for buyers.</span></p></li><li><p><strong><span>Proof burden:</span></strong><span> Cyera&#8217;s trust layer for AI and agentic-security positioning will require concrete evidence: GA vs. roadmap clarity, architecture diagrams, enforcement points, customer outcomes, and credible demos.</span></p></li><li><p><strong><span>Human identity boundary:</span></strong><span> Cyera&#8217;s best path is likely through NHI and agentic identities, but agents often borrow or operate under human permissions. That creates a head-to-head competition and overlap with Okta, SailPoint, CyberArk, Palo Alto, CrowdStrike, and other identity/security platforms.</span></p></li><li><p><strong><span>DLP and runtime maturity:</span></strong><span> Cyera&#8217;s Omni DLP and AI Guardian narratives are strategically compelling, but buyers will ask where enforcement happens, which channels are covered, and what is native versus new; customers will focus on integrated value.</span></p></li></ol><p></p><h3>How Cyera &amp; Oasis Makes This Acquisition Work</h3><h4><strong>GTM support since there is no natural enterprise owner for the combined platform</strong></h4><p>One of the biggest risks faced is that both teams are separated. The combined proposition spans data security, identity security, cloud security, and AI governance security. These functions commonly operate under different leaders, budgets, procurement cycles, systems of record, and success metrics.</p><p>A product that addresses several teams may appear strategically comprehensive while becoming commercially difficult to purchase because no single team owns the complete problem.</p><p>Cyera will therefore need to establish:</p><ul><li><p>Who owns the budget</p></li><li><p>Who administers the platform</p></li><li><p>Who approves policy changes</p></li><li><p>Who is responsible for remediation</p></li><li><p>Which existing platform is displaced</p></li><li><p>Which team is accountable when identity and data policies conflict</p></li></ul><p>Without clear answers, the platform could become an additional visibility layer rather than a consolidated control plane.</p><p></p><h4><strong>Integrate Cyera and Oasis into a cohesive product architecture</strong></h4><p>Integrating two security products requires more than correlating telemetry. Cyera will need to reconcile potentially different:</p><ul><li><p>Asset and identity models</p></li><li><p>Risk-scoring methodologies</p></li><li><p>Policy engines</p></li><li><p>Data architectures</p></li><li><p>Connector frameworks</p></li><li><p>Remediation workflows</p></li><li><p>Authorization models</p></li><li><p>Product release cycles</p></li></ul><p>If the two products continue operating as separate engines beneath a shared interface, customers may experience duplicated configuration, inconsistent risk findings, and fragmented remediation. Hence, Cyera will need to strongly integrate the Oasis product into a cohesive suite and UI experience for the users. </p><p></p><p></p><h2><strong><span>Integration Vision: Data-Identity-Action Graph</span></strong></h2><p><span>The bigger opportunity for Cyera is building a data-identity-action graph and strong intelligence layer to deliver risk signals across the agentic actions of users and autonomous harnesses. What&#8217;s crucial for buyers is a unified view of what data exists, which identities can access it, and what those identities are doing.</span></p><p><span>In that model, Cyera could move from passive visibility toward real-time decisions, including:</span></p><ul><li><p><span>Dynamically adjusting permissions when sensitive data is involved</span></p></li><li><p><span>Limiting agent actions based on intent, role, and data sensitivity</span></p></li><li><p><span>Detecting abnormal service-account or workload-identity behavior</span></p></li><li><p><span>Quarantining or disabling risky agents</span></p></li><li><p><span>Enforcing tighter controls when NHI activity touches regulated or high-value data</span></p></li><li><p><span>Mapping data lineage across human, AI, and agentic workflows</span></p></li><li><p><span>Providing audit-ready evidence of who or what accessed sensitive data and why</span></p></li></ul><p><span>This also connects to Cyera&#8217;s maturity-model work. SACR notes from the Cyera maturity-model discussion suggest a forward-looking thesis: </span><strong><span>agentics may make level-five data security maturity more achievable</span></strong><span> by reducing the human/process burden of continuous discovery, classification, remediation, and enforcement. Oasis could strengthen that story by adding the identity substrate needed for automated decisions.</span></p><p><strong><span>Cyera and Oasis: Integration Outlook</span></strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!MRq3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54c461af-826c-4b56-bb3a-7c919afc43ae_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!MRq3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54c461af-826c-4b56-bb3a-7c919afc43ae_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!MRq3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54c461af-826c-4b56-bb3a-7c919afc43ae_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!MRq3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54c461af-826c-4b56-bb3a-7c919afc43ae_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!MRq3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54c461af-826c-4b56-bb3a-7c919afc43ae_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!MRq3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54c461af-826c-4b56-bb3a-7c919afc43ae_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/54c461af-826c-4b56-bb3a-7c919afc43ae_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!MRq3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54c461af-826c-4b56-bb3a-7c919afc43ae_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!MRq3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54c461af-826c-4b56-bb3a-7c919afc43ae_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!MRq3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54c461af-826c-4b56-bb3a-7c919afc43ae_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!MRq3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54c461af-826c-4b56-bb3a-7c919afc43ae_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong><span>Competitive Implications</span></strong></h2><p><span>The acquisition increases Cyera&#8217;s strategic surface area. It now competes or overlaps with several categories at once:</span></p><ul><li><p><strong><span>DSPM / data security vendors: </span></strong><span>Cyera can argue that sensitive-data context is more valuable when paired with identity and NHI behavior.</span></p></li><li><p><strong><span>Standalone NHI vendors: </span></strong><span>Oasis gains a broader platform and data context that NHI-only vendors may lack.</span></p></li><li><p><strong><span>Identity incumbents: </span></strong><span>Cyera gains a wedge into identity through NHI and agentic access rather than starting with traditional IAM.</span></p></li><li><p><strong><span>CNAPP / cloud platforms: </span></strong><span>Wiz, Palo Alto, CrowdStrike, and others may have cloud and identity context, but Cyera can differentiate on data precision and data-first governance.</span></p></li><li><p><strong><span>DLP / SSE vendors: </span></strong><span>Cyera&#8217;s Omni DLP story becomes more compelling if identity and data context can drive enforcement across channels.</span></p></li><li><p><strong><span>AI security / AI-SPM vendors: </span></strong><span>Cyera can position AI security as a data and identity governance problem rather than only model, prompt, or posture management.</span></p></li></ul><p><span>SACR&#8217;s broader identity and agentic-security research has repeatedly emphasized that identity security is shifting from managing human logins to governing autonomous and non-human actors operating at machine speed. This deal gives Cyera a credible way to participate in that shift.</span></p><p></p><h2><strong><span>What CISOs Should Watch For</span></strong></h2><ol><li><p><strong><span>Integration roadmap:</span></strong><span> How quickly Oasis capabilities become native to Cyera workflows, dashboards, policies, risk scoring, and remediation.</span></p></li><li><p><strong><span>GA vs. roadmap clarity:</span></strong><span> Which vendor capabilities are shipping now versus remaining in preview, Black Hat or conference demos, or longer-horizon strategy and vision.</span></p></li><li><p><strong><span>Enforcement model:</span></strong><span> Where Cyera can actually enforce policy: API, proxy/gateway, endpoint, SaaS, IdP, SSE, DLP partner, or native control.</span></p></li><li><p><strong><span>Customer proof:</span></strong><span> Whether customers replace standalone NHI tools, expand Cyera budgets, or adopt combined data + NHI use cases.</span></p></li><li><p><strong><span>Buyer alignment:</span></strong><span> Whether Cyera can sell this to data security, identity, cloud, and AI security leaders without creating confusion.</span></p></li><li><p><strong><span>Agentic identity positioning:</span></strong><span> Whether Cyera can define a crisp boundary between NHI, AI agents, human-delegated permissions, and traditional IAM.</span></p></li><li><p><strong><span>Competitive response:</span></strong><span> How Palo Alto, Wiz, CrowdStrike, SailPoint, CyberArk, Okta, and standalone NHI vendors respond.</span></p></li></ol><p></p><h2><strong><span>Bottom Line: SACR Perspectives</span></strong></h2><p>Cyera&#8217;s acquisition of Oasis is strategically coherent but structurally difficult. The deal connects two areas that increasingly influence one another: sensitive-data security and non-human identity governance. However, technical convergence does not eliminate the distinct teams, budgets, platforms, workflows, and authorities that have historically separated data and identity security.</p><p><span>If executed well, the acquisition positions Cyera as more than a data security platform, filling in some perceived gaps against key competitors. The merged company could become a central governance layer for sensitive data access, non-human identity risk, and agentic security. </span></p><p><span>The main caveat is execution, where Cyera must prove that this is a deeply integrated platform move, not just a category-expansion headline. This is one of the clearest examples of data security and identity security converging around agentic AI. Cyera has the right strategic ingredients, but the market will judge the deal on integration depth, enforcement proof, and buyer clarity.</span></p><p>SACR therefore views the acquisition as strategically promising but operationally unproven. The market should evaluate it based on integration depth, customer adoption, enforcement authority, organizational fit, and measurable security outcomes, not the breadth of the post-acquisition platform narrative alone.</p><div><hr></div><h3><span>Sources:</span></h3><ol><li><p><a href="https://techcrunch.com/2026/07/28/cyera-agrees-to-acquire-oasis-security-for-1b-to-safeguard-proliferating-ai-agents/">Cyera acquired Oasis </a></p></li><li><p><a href="https://www.cyera.com/">Cyera &amp; Oasis Blog Websites </a></p></li><li><p><a href="https://labs.cloudsecurityalliance.org/research/csa-whitepaper-nonhuman-identity-agentic-ai-governance-v1-cs/"><span>Cloud Security Alliance</span></a><span>: The Non-Human Identity Governance Vacuum</span></p></li><li><p><a href="https://digitalitnews.com/the-state-of-non-human-identity-and-ai-security-report-released/"><span>WEF</span></a><span> study from 2025: over half of enterprises lack defined responsibility for governing machine-based AI credentials </span></p></li><li><p><a href="http://(https://cloudsecurityalliance.org/press-releases/2026/01/27/79-of-it-pros-feel-ill-equipped-to-prevent-attacks-via-nhi-csa-oasis-survey-finds)"><span>Cloud Security Alliance</span></a><span> Official Press Release</span></p><p></p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Software Analyst Cyber Research! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&quot;,&quot;text&quot;:&quot;Share Software Analyst Cyber Research&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share Software Analyst Cyber Research</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/p/fast-take-cyeras-acquisition-of-oasis/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/p/fast-take-cyeras-acquisition-of-oasis/comments"><span>Leave a comment</span></a></p><p></p></li></ol>]]></content:encoded></item><item><title><![CDATA[AI SOC Technoscope Series: The AI SOC Market, 2026 (Part 2)]]></title><description><![CDATA[How Trusted SOC Rankings Vary by Different SOC Operating Environment]]></description><link>https://softwareanalyst.substack.com/p/ai-soc-technoscope-series-the-ai</link><guid isPermaLink="false">https://softwareanalyst.substack.com/p/ai-soc-technoscope-series-the-ai</guid><dc:creator><![CDATA[Sean Sosnowski]]></dc:creator><pubDate>Thu, 30 Jul 2026 20:02:25 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!6d2c!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdd7020e-d886-448f-a2d0-31cdf0c65aae_1720x1008.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>This is SACR&#8217;s third consecutive year of original research on the AI SOC market, following previous episodes: <a href="https://softwareanalyst.substack.com/p/revolutionizing-secuity-operations">The Path Toward AI-Augmented SOCs (2024)</a> and <a href="https://softwareanalyst.substack.com/p/sacr-ai-soc-market-landscape-for">SACR AI SOC Market Landscape for 2025</a>. This year&#8217;s research inaugurates a new franchise, the AI SOC Technoscope Series, which opened with <a href="https://softwareanalyst.substack.com/p/ai-soc-technoscope-series-building">Part 1, Building the Trusted SOC</a>.</p><p>Part 1 established that a Trusted SOC is not purchased as a platform or achieved through autonomous actions by AI agents. Security teams/leaders build it by granting AI agents authority for specific response actions only when the evidence, governance, reliability, and verified outcomes support that authority. </p><p>This Part 2 applies that model to the market itself. We evaluated 18 vendors across three operating environments and testing scenarios. </p><ol><li><p>The regulated SIEM-centric enterprise SOC</p></li><li><p>Hybrid mid-market SOC</p></li><li><p>Cloud native data-lake SOC</p></li></ol><p>The result shows which products are positioned to support which authority portfolios, and where.</p><p><em><strong>Caveats</strong></em><strong>:</strong> </p><p><em><sup>The AI SOC category is broad and still consolidating. Peer trackers count close to 140 vendors that use, market, or support AI within security operations, and SACR treats more than 60 of those as pure-play AI SOC platforms worth direct comparison. This report evaluates 18 of them in depth. This report is </sup><strong><sup>purely independent,</sup></strong><sup> with no vendor relationship influencing any rankings. Everything was weighted </sup></em></p><p><em><sup>That narrower set was not a matter of convenience. To qualify for ranking, a product had to materially shape the path from case understanding to response, through decisioning, action recommendation, governed execution, or verification, backed by enough generally available capability and production evidence to support a defensible comparison rather than a restated pitch deck. Inclusion in the ranked 18 is a statement about evaluability, not a statement about quality. A vendor&#8217;s absence from the ranked set is not a judgment against it. It typically means the evidence available to us during the research period did not yet support a comparison at the same depth as the vendors we ranked.</sup></em></p><p><em><sup>This analysis builds on the same primary research described in Part 1: structured interviews with [20] security leaders and practitioners, and briefings or live demonstrations across the broader vendor landscape.</sup></em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6d2c!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdd7020e-d886-448f-a2d0-31cdf0c65aae_1720x1008.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6d2c!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdd7020e-d886-448f-a2d0-31cdf0c65aae_1720x1008.png 424w, https://substackcdn.com/image/fetch/$s_!6d2c!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdd7020e-d886-448f-a2d0-31cdf0c65aae_1720x1008.png 848w, https://substackcdn.com/image/fetch/$s_!6d2c!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdd7020e-d886-448f-a2d0-31cdf0c65aae_1720x1008.png 1272w, https://substackcdn.com/image/fetch/$s_!6d2c!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdd7020e-d886-448f-a2d0-31cdf0c65aae_1720x1008.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6d2c!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdd7020e-d886-448f-a2d0-31cdf0c65aae_1720x1008.png" width="1456" height="853" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bdd7020e-d886-448f-a2d0-31cdf0c65aae_1720x1008.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:853,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1417572,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://softwareanalyst.substack.com/i/208862299?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdd7020e-d886-448f-a2d0-31cdf0c65aae_1720x1008.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6d2c!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdd7020e-d886-448f-a2d0-31cdf0c65aae_1720x1008.png 424w, https://substackcdn.com/image/fetch/$s_!6d2c!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdd7020e-d886-448f-a2d0-31cdf0c65aae_1720x1008.png 848w, https://substackcdn.com/image/fetch/$s_!6d2c!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdd7020e-d886-448f-a2d0-31cdf0c65aae_1720x1008.png 1272w, https://substackcdn.com/image/fetch/$s_!6d2c!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdd7020e-d886-448f-a2d0-31cdf0c65aae_1720x1008.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h1><span>Key Actionable Summary</span></h1><p><span>The first report identified the action gap between incident understanding and trusted response. Our market analysis finds that this gap remains the dividing line between broad capability and category leadership. Investigation, summarization, and enrichment have become common across the market. The systems that carry evidence into decisioning, governed action, execution, verification, and proof remain far less consistent. Products that appear similar in a demonstration can create substantially different operating models in production.</span></p><ul><li><p><strong><span>Evaluation model:</span></strong><span> We evaluated 18 vendors across Architectural Alignment and Production Delivery. Architectural Alignment measures how completely a product connects the lifecycle from evidence through verified outcome. Production Delivery measures how reliably it provides that capability in real operating environments today.</span></p></li><li><p><strong><span>Market finding:</span></strong><span> Leadership is architecture-neutral. AI-native, SOAR-derived, and platform-consolidated products can all support the Trusted SOC. Their strengths differ according to lifecycle ownership, governance, production maturity, integration requirements, and operational burden.</span></p></li><li><p><strong><span>Top-line results:</span></strong><span> No single vendor can be considered a universal AI SOC leader. Suitability materially changes based on evidence architecture, control-plane ownership, governance intensity, operating capacity, and the response actions organizations intend to delegate in their own environments.</span></p></li><li><p><strong><span>Environmental finding:</span></strong><span> Vendor fit changes across the regulated SIEM-centric enterprise SOC, hybrid mid-market SOC, and cloud native data-lake SOC. Each environment places different demands on governance, integration, data access, execution, and operational overhead.</span></p></li><li><p><strong><span>Buyer takeaway:</span></strong><span> Use the Trusted SOC as the destination and these rankings as a guide to the most credible path for your environment. Evaluate how much of the lifecycle the product can own today, what authority it can safely exercise, how it proves the outcome, and what your organization must supply around it.</span></p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/p/ai-soc-technoscope-series-the-ai?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading Software Analyst Cyber Research! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/p/ai-soc-technoscope-series-the-ai?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/p/ai-soc-technoscope-series-the-ai?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div></li></ul><h2><strong><span>What Buyers Are Purchasing</span></strong></h2><p><span>AI SOC purchases today take one of three primary forms. Each places control of evidence, case state, decisioning, and response in a different part of the security stack. The practical choice is where the buyer wants this operating layer to reside, which systems should remain authoritative, and how much integration, maintenance, and governance burden the organization is prepared to own.</span></p><h3><strong><span>Path 1: Add an AI-Native Layer Over the Existing Stack</span></strong></h3><p><span>Organizations choosing an independent AI-native platform generally want to preserve their current SIEM, EDR, identity, cloud, and workflow tools while adding a system that can assemble evidence, investigate incidents, develop cases, and coordinate response across them. This path offers cross-stack flexibility, modern reasoning, and faster deployment without requiring broad platform consolidation. Its effectiveness depends on integration depth, API access, credential design, customer context, and the platform&#8217;s ability to verify actions executed through external control systems.</span></p><p><span>This path is a natural fit for hybrid mid-market and cloud native teams that operate fragmented environments, need greater analyst leverage, or want to improve investigation and response without replacing the surrounding stack. Buyers assume responsibility for deciding which systems remain authoritative and how the AI-native layer receives enough context and permission to act safely.</span></p><h3><strong><span>Path 2: Modernize SOAR and Automation with AI</span></strong></h3><p><span>Organizations with established orchestration, case management, and response workflows may extend those systems with AI-assisted investigation and decisioning. This path builds on existing strengths in connector breadth, approvals, deterministic execution, auditability, retry logic, and failure handling. AI can improve prioritization, evidence gathering, case development, playbook selection, and the handling of incidents that require interpretation rather than a fixed sequence of steps.</span></p><p><span>This path is well suited to regulated enterprises and operationally mature SOCs that already rely on formal workflows and controlled execution. Buyers gain a familiar governance foundation and may face greater workflow administration, integration maintenance, and process complexity. They should determine how deeply AI reasoning is connected to the execution layer and whether the system can preserve evidence continuity from investigation through verified closure.</span></p><h3><strong><span>Path 3: Consolidate Into a Broader Security Platform</span></strong></h3><p><span>Organizations already standardized on a major security platform may extend that platform across telemetry, detection, investigation, case management, and response. Native access to endpoint, network, identity, cloud, and threat-intelligence data can reduce integration friction and connect decisions directly to enforcement. This path can provide strong production scale, established governance, and a more unified operating experience across the platform&#8217;s installed ecosystem.</span></p><p><span>This path is most natural for large or regulated enterprises that prioritize consolidation, native control, and operational consistency. Buyers should evaluate the breadth of third-party support, the amount of additional platform adoption required, and the degree to which the system can maintain case and evidence continuity outside its native ecosystem.</span></p><h3><strong><span>Choosing the Operating Model</span></strong></h3><p><span>Each path can support progress toward a Trusted SOC. The purchasing decision should begin with the authority portfolio the organization wants the product to assume: which evidence it can access, which investigations it can conduct, which actions it can recommend or execute, where approval is required, which credentials it can use, and how outcomes will be independently verified.</span></p><p><span>Sourcing and delivery choices cut across all three paths. Organizations may operate the product directly, deploy it with vendor assistance, use it through a co-managed or managed service, or combine vendor capabilities with internally built agents and automation. These choices shift the staffing, maintenance, accountability, and proof burden between the customer, the software provider, and the service operator.</span></p><p><span>This makes environment-specific evaluation essential. The buyer is selecting a product to assume defined responsibilities inside a particular security operating model, with evidence that it can perform those responsibilities safely, reliably, and at the maturity required by the organization.</span></p><h1><span>Research Methodology</span></h1><p><span>We developed this report through primary and secondary research conducted across the AI SOC market. We collected evidence through security-practitioner interviews, vendor briefings, live product demonstrations, targeted surveys, product documentation, and supporting market research. Practitioner research established the operating problems, architectural constraints, adoption requirements, and purchasing considerations shaping real deployments. Vendor research provided evidence on product architecture, integrations, investigation workflow, decision systems, response capability, governance, deployment maturity, and customer use.</span></p><p><span>We assessed capabilities according to what vendors could demonstrate or support with available evidence. Greater weight was given to generally available product functionality, live workflow, documented integrations, production use, and customer evidence. Beta, private-preview, and roadmap capabilities were separated from mature functionality and did not receive equivalent credit. Product positioning and general statements about automation were not treated as evidence of response authority or production maturity.</span></p><p><span>The market is developing quickly, and the available evidence remains uneven. Vendor participation, access to live deployments, customer references, and measurable production outcomes varied across the evaluated companies. The findings represent SACR&#8217;s assessment of the best evidence available during the research period and should be understood as a current view of a rapidly changing market.</span></p><h2><strong><span>Evaluated Vendors</span></strong></h2><p><span>The AI SOC market now includes over 100 companies that use, market, or support AI in security operations. The ranked cohort was limited to products whose relevant AI SOC offering was publicly identifiable by December 31, 2025, which materially addressed the path from case-level understanding to governed response, which fit one of the three customer-operated product paths evaluated, and had sufficient verifiable evidence of current capability and production maturity to support a defensible comparison. This report is not meant to serve as a census of every vendor in the market, it is a comparative analysis of platforms that buyers can reasonably evaluate as a path to operating a Trusted SOC.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!w-0O!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbb49b81-30e9-4dbb-876a-0a6c2d3b6183_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!w-0O!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbb49b81-30e9-4dbb-876a-0a6c2d3b6183_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!w-0O!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbb49b81-30e9-4dbb-876a-0a6c2d3b6183_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!w-0O!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbb49b81-30e9-4dbb-876a-0a6c2d3b6183_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!w-0O!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbb49b81-30e9-4dbb-876a-0a6c2d3b6183_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!w-0O!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbb49b81-30e9-4dbb-876a-0a6c2d3b6183_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cbb49b81-30e9-4dbb-876a-0a6c2d3b6183_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!w-0O!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbb49b81-30e9-4dbb-876a-0a6c2d3b6183_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!w-0O!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbb49b81-30e9-4dbb-876a-0a6c2d3b6183_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!w-0O!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbb49b81-30e9-4dbb-876a-0a6c2d3b6183_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!w-0O!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbb49b81-30e9-4dbb-876a-0a6c2d3b6183_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>To select the ranked cohort we began with the broader AI SOC ecosystem, including AI-native SOC platforms, SOAR and automation providers, security-data and analytics platforms, large security suites, builder tools, and service-led offerings. We then applied a scope screen to narrow the list.</span></p><p><span>To be included in the ranked set, a product had to materially shape the path from case-level understanding to response: through AI-assisted decisioning, action recommendation or preparation, approval and policy controls, execution, verification, or a demonstrable combination of those functions. Products whose primary role is telemetry collection, data management, investigation support, or managed service delivery remain relevant to the broader market, but are not automatically comparable to response-layer platforms.</span></p><p><span>We evaluated products rather than entire companies. For broad platform vendors, only the AI SOC, SOAR, or response capabilities relevant to this analysis were assessed. A vendor&#8217;s larger security portfolio, revenue, market capitalization, or general brand presence did not determine inclusion or placement.</span></p><p><span>The evaluated set also required enough evidence to support a defensible comparison. SACR considered live workflows, product documentation, integration depth, generally available functionality, deployment maturity, customer evidence, and the distinction between production capabilities and roadmap claims.</span></p><p><span>Finally, the 18 vendors were selected to represent the principal architectural and operating choices available to buyers: AI-native SOC platforms, SOAR-derived platforms with AI, and broader security providers with identifiable AI SOC capabilities. The set is broad enough to compare those approaches across regulated SIEM-centric enterprise, hybrid mid-market, and cloud native data-lake environments without treating every adjacent product as a like-for-like competitor.</span></p><p><span>Inclusion in this report does not mean that these are the only relevant vendors in the market, neither does absence constitute a judgment that another product lacks value. It means we had a sufficient basis to evaluate these products against the specific case-to-response criteria and operating environments used in this analysis.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_IUx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae9c78f3-1948-4669-bf3c-6abac0670ae0_1402x486.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_IUx!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae9c78f3-1948-4669-bf3c-6abac0670ae0_1402x486.png 424w, https://substackcdn.com/image/fetch/$s_!_IUx!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae9c78f3-1948-4669-bf3c-6abac0670ae0_1402x486.png 848w, https://substackcdn.com/image/fetch/$s_!_IUx!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae9c78f3-1948-4669-bf3c-6abac0670ae0_1402x486.png 1272w, https://substackcdn.com/image/fetch/$s_!_IUx!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae9c78f3-1948-4669-bf3c-6abac0670ae0_1402x486.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_IUx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae9c78f3-1948-4669-bf3c-6abac0670ae0_1402x486.png" width="1402" height="486" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae9c78f3-1948-4669-bf3c-6abac0670ae0_1402x486.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:486,&quot;width&quot;:1402,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!_IUx!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae9c78f3-1948-4669-bf3c-6abac0670ae0_1402x486.png 424w, https://substackcdn.com/image/fetch/$s_!_IUx!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae9c78f3-1948-4669-bf3c-6abac0670ae0_1402x486.png 848w, https://substackcdn.com/image/fetch/$s_!_IUx!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae9c78f3-1948-4669-bf3c-6abac0670ae0_1402x486.png 1272w, https://substackcdn.com/image/fetch/$s_!_IUx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae9c78f3-1948-4669-bf3c-6abac0670ae0_1402x486.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Software Analyst Cyber Research! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/p/ai-soc-technoscope-series-the-ai/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/p/ai-soc-technoscope-series-the-ai/comments"><span>Leave a comment</span></a></p><h1><strong><span>AI SOC Market Rankings</span></strong></h1><h2 style="text-align: center;"><strong><span>Cross-Environment Capability View</span></strong></h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!mOcn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d37da7d-97b3-4f57-b84b-c62985229642_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!mOcn!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d37da7d-97b3-4f57-b84b-c62985229642_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!mOcn!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d37da7d-97b3-4f57-b84b-c62985229642_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!mOcn!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d37da7d-97b3-4f57-b84b-c62985229642_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!mOcn!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d37da7d-97b3-4f57-b84b-c62985229642_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!mOcn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d37da7d-97b3-4f57-b84b-c62985229642_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2d37da7d-97b3-4f57-b84b-c62985229642_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!mOcn!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d37da7d-97b3-4f57-b84b-c62985229642_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!mOcn!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d37da7d-97b3-4f57-b84b-c62985229642_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!mOcn!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d37da7d-97b3-4f57-b84b-c62985229642_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!mOcn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d37da7d-97b3-4f57-b84b-c62985229642_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><strong>Bubble size directly correlates to the vendor&#8217;s final combined average score</strong></figcaption></figure></div><p><span>The comparative average consolidates performance across three operating environments. Vendor placement reflects two separate questions. Architectural Alignment measures how completely the product connects the AI SOC lifecycle from evidence through verified outcome. Production Delivery measures how reliably the product delivers those outcomes in real-world environments today. Together, the axes distinguish architectural completeness from demonstrated operational maturity.</span></p><p><span>Architectural Alignment does not reward a particular product heritage. AI-native, SOAR-derived, and platform-consolidated products can all score highly when they connect the complete lifecycle as a coherent system. Production Delivery is based on generally available capability, operational evidence, governance, scale, failure handling, and verified customer use.</span></p><h3><strong><span>Architectural Alignment</span></strong></h3><p><span>Architectural Alignment measures how completely the product&#8217;s core architecture supports the AI SOC lifecycle:</span></p><ul><li><p><span>Evidence assembly</span></p></li><li><p><span>Investigation</span></p></li><li><p><span>Decisioning</span></p></li><li><p><span>Bounded authority</span></p></li><li><p><span>Response execution</span></p></li><li><p><span>Outcome verification</span></p></li><li><p><span>Continuous improvement</span></p></li></ul><p><span>A high score means these capabilities operate as one connected evidence-to-outcome system. A lower score means ownership is distributed across the product and adjacent systems, requiring another platform, automation layer, investigation tool, or human team to complete one or more stages of the lifecycle.</span></p><p><span>Architectural Alignment measures the connectedness and ownership of the lifecycle. It is not a measure of overall product quality, company maturity, or architectural heritage.</span></p><h3><strong><span>Production Delivery</span></strong></h3><p><span>Production Delivery measures whether the product can reliably deliver AI SOC outcomes in real-world environments today. It considers:</span></p><ul><li><p><span>Production maturity</span></p></li><li><p><span>Integration depth</span></p></li><li><p><span>Deployment burden</span></p></li><li><p><span>Governed execution</span></p></li><li><p><span>Operational scale</span></p></li><li><p><span>Failure handling</span></p></li><li><p><span>Case continuity</span></p></li><li><p><span>Evidence that response actions achieve the intended result.</span></p></li></ul><p><span>A high score means the product can move supported incidents from investigation through controlled action and verified closure, with credible customer evidence. A lower score indicates narrower execution coverage, limited production proof, greater operational burden, or dependence on another system or human team to complete the workflow.</span></p><h3><strong><span>Innovators Category</span></strong></h3><p><span>Innovators combine strong Architectural Alignment with credible Production Delivery. They connect evidence, investigation, decisioning, bounded authority, response execution, and outcome verification within a continuous workflow, with sufficient production evidence to demonstrate that the model functions in real customer environments.</span></p><p><span>Vendors reach this position through different routes. Torq and BlinkOps emphasize automation and integration fabrics that make controlled action dependable across a wide stack. 7AI and Prophet Security emphasize AI-native case progression and graduated authority. Exaforce is differentiated by its data architecture and cloud native evidence assembly. </span><em><span>Swimlane reaches the category through a SOAR-derived architecture that combines federated evidence access, production AI reasoning, mature governance, and dependable cross-stack execution. </span></em><span>Their shared characteristic is demonstrated strength across both Architectural Alignment and Production Delivery.</span></p><h3><strong><span>Trailblazers Category</span></strong></h3><p><span>Trailblazers demonstrate strong Production Delivery with moderate Architectural Alignment. Their strengths include established integrations, durable workflows, governance, auditability, operational scale, and credible production use. Ownership of the complete AI SOC lifecycle is more distributed across the surrounding platform or automation architecture.</span></p><p><span>Palo Alto Networks reaches this position through platform consolidation, native telemetry and enforcement, and mature enterprise response controls. For buyers whose environment align with this operating model, it may provide the strongest practical fit.</span></p><h3><strong><span>Pioneers Category</span></strong></h3><p><span>Pioneers demonstrate strong Architectural Alignment with developing Production Delivery. Their products are closely organized around a connected AI SOC lifecycle, while the production record remains younger or less complete across execution breadth, deployment duration, governance depth, verification, integrations, or enterprise scale.</span></p><p><span>Mate Security and Simbian emphasize organizational context, agentic investigation, and staged authority. AIStrike connects detection improvement with investigation and response. Radiant Security and Dropzone AI emphasize analyst leverage and rapid case development. Intezer and Qevlar provide strong evidence assembly and reasoning with narrower governed-remediation depth. Broader verified execution and stronger production evidence can move these vendors toward the Innovator category.</span></p><h3><strong><span>Emerging Players Category</span></strong></h3><p><span>Emerging Players have relevant AI SOC capabilities and strong adjacent control planes, while complete lifecycle ownership and Production Delivery remain developing. Their capabilities may be concentrated in endpoint or XDR response, investigation, workflow automation, case management, or another portion of the AI SOC lifecycle.</span></p><p><span>CrowdStrike and SentinelOne bring mature native telemetry and enforcement platforms. Stellar Cyber brings an established Open XDR and case-management foundation. D3 Security brings deep SOAR, orchestration, and governance experience. Their placement reflects the current connectedness and demonstrated delivery of their evaluated AI SOC capabilities. It does not describe the maturity, market position, or overall quality of the companies.</span></p><h1><strong><span>Environment Specific Ranks</span></strong></h1><p><span>Each environment applies the same Trusted SOC destination under different operating conditions. What changes is the evidence, governance, integration, and operational burden a product must satisfy before it can credibly support response authority.</span></p><p><span>The depicted environments are meant to serve as examples of different types of SOCs. It is not an exhaustive list that captures every nuance an environment can have. Large enterprises may have fragmented security stacks, and a cloud native organization may be subject to strenuous industry regulation. We encourage buyers to leverage our analysis as a baseline of what a vendor can offer, and apply it to their own unique operating environment and regulations.</span></p><h2><strong><span>Environment 1: Regulated SIEM-Centric SOC</span></strong></h2><p><span>A mature SOC operating in a highly regulated industry where the SIEM remains the primary system of record for detection, alert correlation, investigation workflow, compliance reporting, and escalation. The mature SOC has established processes, tiered analysts, defined incident response procedures, and strict requirements for auditability, approval, and evidence retention.</span></p><p><strong><span>Generic architecture</span></strong></p><ul><li><p><span>Enterprise SIEM as the central detection and correlation layer</span></p></li><li><p><span>Mature telemetry coverage across endpoint, identity, cloud, network, email, SaaS, and threat intelligence sources</span></p></li><li><p><span>SOAR, ITSM, ticketing, and case management workflows</span></p></li><li><p><span>Response integrations across EDR, IAM, email security, firewall, cloud controls, PAM, and vulnerability management</span></p></li><li><p><span>Formal governance through RBAC, policy libraries, audit logs, approval gates, and evidence retention</span></p></li><li><p><span>24/7 or follow-the-sun SOC coverage with clear analyst tiers and incident command structure</span></p></li><li><p><span>High regulatory pressure from financial services, healthcare, government, critical infrastructure, or public company obligations</span></p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!fAFC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda06ffba-4e36-4bae-b5a5-f28591c25eb4_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!fAFC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda06ffba-4e36-4bae-b5a5-f28591c25eb4_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!fAFC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda06ffba-4e36-4bae-b5a5-f28591c25eb4_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!fAFC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda06ffba-4e36-4bae-b5a5-f28591c25eb4_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!fAFC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda06ffba-4e36-4bae-b5a5-f28591c25eb4_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!fAFC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda06ffba-4e36-4bae-b5a5-f28591c25eb4_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/da06ffba-4e36-4bae-b5a5-f28591c25eb4_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!fAFC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda06ffba-4e36-4bae-b5a5-f28591c25eb4_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!fAFC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda06ffba-4e36-4bae-b5a5-f28591c25eb4_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!fAFC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda06ffba-4e36-4bae-b5a5-f28591c25eb4_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!fAFC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda06ffba-4e36-4bae-b5a5-f28591c25eb4_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><strong>Bubble size directly correlates to the vendor&#8217;s final score in this environment.</strong></figcaption></figure></div><p><span>The regulated map rewards vendors that can prove both authority and accountability. Palo Alto Networks and Swimlane rise because mature platform or SOAR controls are highly valuable in this environment. Torq, 7AI, and BlinkOps remain strong because they combine modern reasoning with bounded execution. Vendors that are excellent at investigation but cannot yet show formal governance, durable case continuity, and verified post-action state are pushed toward the specialist or contender categories.</span></p><h3><strong><span>Enterprise Execution Axis</span></strong></h3><p><span>The horizontal axis measures whether the vendor can operate reliably as part of a large enterprise response system. It incorporates SIEM and workflow integration, breadth of response orchestration, deployment maturity, scale, failure handling, case continuity, and the practical ability to execute across a complex control stack.</span></p><p><span>A high score means the product can move beyond analysis into repeatable production action across enterprise systems. A lower score generally reflects narrower action breadth, less mature deployment evidence, a younger integration catalog, greater dependence on a particular architecture, or more limited proof that the product can carry enterprise operating load.</span></p><h3><strong><span>Governance and Decision Assurance Axis</span></strong></h3><p><span>The vertical axis measures whether the platform can make and govern consequential decisions in a way that a regulated enterprise can defend. It includes decision quality, evidence traceability, approval routing, policy controls, auditability, chain of custody, blast-radius limits, source-state verification, and outcome proof.</span></p><p><span>A high score means the platform can explain why an action was selected, constrain who or what can authorize it, preserve the decision record, and show what happened afterward. A lower score does not necessarily mean weak security efficacy; it often means the reasoning-to-action chain is fragmented, approval controls are incomplete, rollback is inconsistent, or post-action verification is not sufficiently mature.</span></p><h3><strong><span>Governed Leaders Category</span></strong></h3><p><span>This is the strongest position for a regulated enterprise buyer. Vendors in this quadrant combine substantial execution authority with the controls required to use that authority safely. They can support durable cases, policy-aware decisions, approvals, audit trails, and production response across meaningful parts of the enterprise stack.</span></p><p><span>The vendors are not identical. Some reach this quadrant through mature platform-native enforcement, some through SOAR and orchestration depth, and others through AI-native reasoning coupled to bounded action tools. Their common characteristic is that neither action breadth nor governance is an obvious disqualifier for a regulated deployment.</span></p><p><span>A regulated buyer should treat this quadrant as the primary shortlist, then separate vendors by operating model. Palo Alto Networks and CrowdStrike are strongest when platform consolidation is acceptable. Swimlane is strongest when mature SOAR governance and deployment optionality are central. Torq and BlinkOps are attractive when the buyer wants a more independent orchestration layer. 7AI is strongest when reasoning-led case progression and graduated autonomy matter more than long enterprise tenure.</span></p><h3><strong><span>Decision Assurance Specialists Category</span></strong></h3><p><span>These vendors show credible reasoning, transparency, policy control, or evidence assurance, but do not yet demonstrate the same breadth, scale, integration maturity, or production operating depth as the Governed Leaders. They are not weak products, their placement means that the buyer can more readily trust how they reach a decision than assume they can execute every enterprise action at scale.</span></p><p><span>This category contains several different product shapes. AI-native platforms such as Prophet, Simbian, and Mate score well because their control design is explicit. D3 Security reaches the quadrant through mature SOAR governance. Exaforce and Qevlar bring strong evidence models. AIStrike benefits from risk-tiered authority and detection feedback. Their common limitation is not necessarily reasoning quality; it is the maturity or breadth of enterprise execution proof.</span></p><p><span>This category is useful for enterprises that already possess a strong execution layer or are willing to keep consequential action under existing SOAR, platform, or human control. These products can materially improve decision quality and case confidence even when they are not selected as the universal remediation fabric. Buyers should test integration burden, approval handoffs, action coverage, and whether the product can preserve one continuous evidence record when execution moves to another system.</span></p><h3><strong><span>Enterprise Executors Category</span></strong></h3><p><span>Enterprise Executors can perform substantial security action and have credible deployment scale, but the full reasoning-to-case-to-action-to-proof chain is less mature than their enforcement capability. These vendors often have strong control-plane assets, installed bases, and deterministic response functions. Their lower assurance position reflects fragmentation, limited dynamic reasoning, connector-dependent verification, or incomplete evidence that the newest agentic layer operates with the same governance maturity as the underlying platform.</span></p><p><span>These vendors are credible when native platform action is more important than introducing a separate response layer. The diligence focus should be on whether the product can preserve one case record, explain why a dynamic action was selected, enforce approval and credential boundaries, and independently verify the resulting state. Buyers should not assume that mature deterministic response automatically proves mature agentic response.</span></p><h3><strong><span>Qualified Contenders Category</span></strong></h3><p><span>Qualified Contenders provide meaningful operational value but do not yet meet the regulated scenario&#8217;s highest bar on both dimensions. The placement often reflects a product whose strength is investigation, triage, or practical analyst acceleration rather than enterprise-wide governed remediation.</span></p><p><span>This category is not defined as an exclusion category. It identifies products that may be valuable in a narrower role, but which require additional controls, an external execution system, more human approval, or more evidence before they should become the primary autonomous response layer for a regulated enterprise.</span></p><h2><strong><span>Environment 2: Hybrid SOC</span></strong></h2><p><span>An organization</span><em><span> </span></em><span>with a mixed SIEM and data-lake architecture, a lean security team, uneven telemetry maturity, and a practical need to reduce analyst workload without rebuilding the SOC. The SIEM still exists, but it is no longer the only place where security data lives. The data lake or security data platform is used for broader telemetry, historical search, enrichment, and cost control.</span></p><p><strong><span>Generic architecture</span></strong></p><ul><li><p><span>SIEM for high-value alerts, mature detections, and compliance-relevant logs</span></p></li><li><p><span>Data lake, security data platform, or warehouse for broader telemetry and lower-cost retention</span></p></li><li><p><span>Telemetry from endpoint, identity, cloud, email, SaaS, network, vulnerability, and application sources</span></p></li><li><p><span>Mixed workflow across ticketing, case management, Slack or Teams, SOAR-lite, and manual analyst processes</span></p></li><li><p><span>Response integrations across EDR, IAM, cloud console, email security, firewall, SaaS admin tools, and ticketing</span></p></li><li><p><span>Small internal SOC, hybrid SecOps/IT team, or co-managed MDR support</span></p></li><li><p><span>Moderate compliance pressure, but less formal governance burden than a regulated enterprise SOC</span></p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!CLin!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18473f5d-e8e7-45f4-bc82-366de505ecdf_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!CLin!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18473f5d-e8e7-45f4-bc82-366de505ecdf_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!CLin!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18473f5d-e8e7-45f4-bc82-366de505ecdf_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!CLin!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18473f5d-e8e7-45f4-bc82-366de505ecdf_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!CLin!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18473f5d-e8e7-45f4-bc82-366de505ecdf_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!CLin!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18473f5d-e8e7-45f4-bc82-366de505ecdf_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/18473f5d-e8e7-45f4-bc82-366de505ecdf_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!CLin!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18473f5d-e8e7-45f4-bc82-366de505ecdf_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!CLin!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18473f5d-e8e7-45f4-bc82-366de505ecdf_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!CLin!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18473f5d-e8e7-45f4-bc82-366de505ecdf_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!CLin!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18473f5d-e8e7-45f4-bc82-366de505ecdf_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: center;"><strong><span>Bubble size directly correlates to the vendor&#8217;s final score in this environment.</span></strong></p><p><span>The hybrid map rewards vendors that can create a coherent case and act across a mixed stack without demanding a major transformation program. Torq and 7AI lead, with Swimlane close behind after demonstrating production operation across hybrid and federated environments. BlinkOps and Prophet Security also clear both thresholds, with different implementation, reasoning, and maturity tradeoffs. Platform-native vendors fall when their strengths require the buyer to consolidate around their ecosystem, while investigation-first vendors fall when they cannot carry the workflow through governed closure.</span></p><h3><strong><span>Operational Integration and Response Axis</span></strong></h3><p><span>The horizontal axis measures how easily the platform can connect to a mixed environment, assemble actions across systems, and deliver useful response without forcing a major platform replacement. It incorporates integration flexibility, response breadth, deployment simplicity, time-to-value, cross-stack orchestration, and the practical burden placed on a smaller team.</span></p><p><span>A high score means the vendor can sit above a fragmented stack and turn alerts or cases into a coordinated action. A lower score may reflect platform dependence, heavier implementation, narrower response authority, a requirement for substantial workflow engineering, or insufficient evidence that the product can work efficiently in a hybrid mid-market environment.</span></p><h3><strong><span>Evidence and Analyst Effectiveness Axis</span></strong></h3><p><span>The vertical axis measures whether the product improves the analyst&#8217;s ability to reach a defensible decision quickly. It includes cross-system evidence assembly, case quality, transparency, contextual reasoning, productivity gains, useful recommendation, and the ability to reduce console switching and repetitive manual work.</span></p><p><span>A high score means the product creates a coherent case rather than compiling information to a queue or interface. A lower score may reflect fragmented case objects, weak cross-source correlation, limited reasoning transparency, or an operating model that still leaves substantial review and coordination work for a human analyst.</span></p><h3><strong><span>Balanced Leaders Category</span></strong></h3><p><span>Balanced leaders are the strongest fit for a hybrid environment because they combine practical cross-stack action with strong case assembly and analyst leverage. They do not require the buyer to choose between better reasoning and useful response. The differences among them are primarily in operating model, implementation weight, and maturity.</span></p><p><span>Torq, 7AI, and Swimlane form the leading hybrid shortlist. Torq and 7AI emphasize speed, flexibility, and reasoning-led operation, while Swimlane offers greater governance and automation maturity with additional administrative weight. BlinkOps remains attractive where workflow flexibility and rapid automation dominate</span><em><span>.</span></em><span> Prophet Security is attractive when backtesting and controlled progression into action are especially important to buyers.</span></p><h3><strong><span>Analyst-Value Specialists Category</span></strong></h3><p><span>This is the largest category in the hybrid scenario. The vendors ranked here generally improve investigation, evidence quality, or analyst productivity, but have a visible constraint in cross-stack deployment, response breadth, time-to-value, or operating-model neutrality.</span></p><p><span>The category captures several distinct reasons for falling below the Operational Integration and Response Axis threshold. Palo Alto Networks is highly capable but heavier and more platform consolidation-oriented than an independent mid-market layer. Exaforce is the most powerful when its data architecture can be used to the fullest extent. Mate, Simbian, and AIStrike are promising but have thinner production proof or integration maturity. Radiant, Intezer Qevlar, and Dropzone provide strong analyst value but narrower governed response.</span></p><p><span>These vendors can be excellent purchases when the buyer&#8217;s primary problem is investigation quality or analyst capacity rather than universal automated remediation. The question of diligence buyers should ask is where the workflow stops. Buyers should identify whether the platform directly executes, provides recommendations, triggers existing SOAR playbooks, or relies on a managed service. That handoff determines whether analyst value turns into measurable time-to-closure improvement.</span></p><h3><strong><span>Qualified Contenders Category</span></strong></h3><p><span>The vendors in this category are not low in quality compared to the others. They are less aligned to the hybrid mid-market operating model. They each carry a form of platform weight, workflow dependence, or product fragmentation that reduces both immediate analyst leverage and cross-stack simplicity for a lean team.</span></p><h2><strong><span>Environment 3: Cloud Native Data-Lake SOC</span></strong></h2><p><span>A cloud native organization that does not operate a traditional SIEM and relies on a data lake, warehouse, cloud native log store, or security data platform as the main evidence layer. The company has a small security team, an engineering-heavy operating model, and limited formal regulatory burden. Security work often happens through Slack, Jira, GitHub, cloud consoles, identity tools, and infrastructure workflows rather than a traditional SOC queue.</span></p><p><strong><span>Generic architecture</span></strong></p><ul><li><p><span>Data lake, warehouse, cloud native log store, or security data platform as the main evidence layer</span></p></li><li><p><span>Telemetry from cloud logs, identity logs, endpoint tools, SaaS platforms, application telemetry, CI/CD systems, and infrastructure events</span></p></li><li><p><span>Detection from native cloud rules, open-source detections, EDR alerts, CSPM/CNAPP findings, identity alerts, and custom queries</span></p></li><li><p><span>Workflow through Slack or Teams, Jira or Linear, GitHub or GitLab, incident channels, and lightweight ticketing</span></p></li><li><p><span>Response through cloud IAM, IdP, EDR, email security, infrastructure-as-code, secrets management, SaaS admin tools, and cloud consoles</span></p></li><li><p><span>Small security team with engineering-led response</span></p></li><li><p><span>Low to moderate regulatory pressure, but meaningful customer trust, uptime, and breach-risk pressure</span></p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!z9bz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa40eb50-8d6f-4c93-8470-986d2140d027_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!z9bz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa40eb50-8d6f-4c93-8470-986d2140d027_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!z9bz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa40eb50-8d6f-4c93-8470-986d2140d027_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!z9bz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa40eb50-8d6f-4c93-8470-986d2140d027_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!z9bz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa40eb50-8d6f-4c93-8470-986d2140d027_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!z9bz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa40eb50-8d6f-4c93-8470-986d2140d027_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fa40eb50-8d6f-4c93-8470-986d2140d027_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!z9bz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa40eb50-8d6f-4c93-8470-986d2140d027_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!z9bz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa40eb50-8d6f-4c93-8470-986d2140d027_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!z9bz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa40eb50-8d6f-4c93-8470-986d2140d027_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!z9bz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa40eb50-8d6f-4c93-8470-986d2140d027_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: center;"><strong><span>Bubble size directly correlates to the vendor&#8217;s final score in this environment.</span></strong></p><p><span>The cloud native map rewards products that can work directly with modern data and engineering context without sacrificing case construction or governed response. 7AI and Exaforce lead through evidence and data architecture, while Torq and BlinkOps lead through API-driven action and workflow flexibility. Swimlane clears both leadership thresholds by combining direct and federated telemetry access with mature case management and governed execution. Platform and other SOAR vendors remain credible, but their administrative and consolidation burden pushes them into the Autonomy Specialist category. Investigation first vendors remain contenders until they can prove broader governed execution and outcome verification.</span></p><h3><strong><span>Cloud Native Execution Axis</span></strong></h3><p><span>The horizontal axis measures the vendor&#8217;s ability to operate in a no-SIEM or data lake centric architecture. It includes direct data lake access, raw cloud and identity context, engineering-native workflow integration, deployment speed, low administrative overhead, and the ability to function without requiring a traditional SOC process.</span></p><p><span>A high score means the product can become part of an engineering-led security operating model rather than merely connect to one. A lower score often reflects enterprise platform weight, SOAR-centric administration, dependence on upstream alerts, a requirement for a conventional SIEM or case process, or insufficient evidence that the product can work effectively against federated cloud native data.</span></p><h3><strong><span>Autonomous Case and Response Axis</span></strong></h3><p><span>The vertical axis measures whether the product can autonomously assemble a case, reach a defensible conclusion, and move into useful governed response. It includes no-SIEM case creation, evidence continuity, dynamic reasoning, response usefulness, authority controls, auditability, and outcome verification.</span></p><p><span>A high score means the platform can do more than query cloud data. It can turn that data into an actionable case and support or execute remediation. A lower score generally means the product is strong at data access or investigation but has narrower response authority, less mature governance, fragmented case continuity, or weaker post-action proof.</span></p><h3><strong><span>Cloud Native Leaders Category</span></strong></h3><p><span>Cloud native Leaders can operate without a traditional SIEM while still providing meaningful case reasoning and response. They are not simply cloud-hosted products. Their architectures support direct or federated access to cloud native data, engineering workflows, and dynamic evidence assembly, while preserving enough authority and governance to move toward closure.</span></p><p><span>This category is the primary shortlist for teams building a modern no-SIEM operating model. 7AI offers the strongest combined case and autonomy proposition. Exaforce is strongest when data architecture and raw cloud context dominate. Torq and BlinkOps are strongest when API-driven action and workflow flexibility dominate. Mate is differentiated by context quality and control design but requires more production diligence, while Swimlane is differentiated by its ability to apply mature response governance and case continuity to federated, and no-SIEM environments. Although its administrative model remains heavier than the leanest AI-native products.</span></p><h3><strong><span>Autonomy Specialists Category</span></strong></h3><p><span>Autonomy Specialists can provide strong reasoning, case management, governed action, or platform-native response, but are less naturally aligned to a lightweight data-lake-centric operating model. The limitation is usually architectural weight rather than a lack of security capability.</span></p><p><span>Some vendors in this category can technically replace a SIEM or provide their own data layer, but doing so may require broader platform adoption, higher cost, or more administration than a small engineering-led team wants. Others are strong AI-native products whose integration or production proof is not yet sufficient to clear the cloud-execution threshold.</span></p><p><span>These vendors are viable when the team is willing to adopt a broader platform or already owns the relevant ecosystem. Palo Alto Networks and CrowdStrike can be excellent choices when consolidation is intentional. Prophet, Simbian, and AIStrike fit teams willing to accept younger production evidence for a more modern reasoning model.</span></p><h3><strong><span>Execution Specialists Category</span></strong></h3><p><span>Radiant Security is the only vendor in this category. It performs well on fast cloud-oriented deployment, native log handling, practical triage, and useful response, but its autonomy-governance model remains less mature than the cloud native Leaders.</span></p><p><span>Radiant&#8217;s placement shows the difference between being operationally convenient in a cloud environment and serving as a fully governed autonomous response control plane. The product can create real analyst leverage and support one-click or selected zero-click actions, but deeper risk-tier policy, multi-stage approval logic, and independent verification of final risk reduction remain less complete.</span></p><p><span>Radiant can be a strong fit for a small team that prioritizes speed, broad triage, and practical containment over immediate delegation of high-impact actions. The buyer should define which actions can run unattended, how policies change by asset criticality and confidence, how failures are handled, and how the platform proves that the intended risk was actually reduced.</span></p><h3><strong><span>Qualified Contenders</span></strong></h3><p><span>These vendors provide useful capabilities but are less aligned to the complete no-SIEM operating model. Their strengths tend to be concentrated in endpoint response, investigation, forensic analysis, or governed SOAR workflows rather than in the combination of cloud native data access, lightweight deployment, autonomous case construction, and broad response.</span></p><h2><strong><span>Vendor Analysis Findings</span></strong></h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ai_7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd45b6a02-85a2-4ee1-a149-676192242720_1672x941.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ai_7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd45b6a02-85a2-4ee1-a149-676192242720_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!ai_7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd45b6a02-85a2-4ee1-a149-676192242720_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!ai_7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd45b6a02-85a2-4ee1-a149-676192242720_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!ai_7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd45b6a02-85a2-4ee1-a149-676192242720_1672x941.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ai_7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd45b6a02-85a2-4ee1-a149-676192242720_1672x941.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d45b6a02-85a2-4ee1-a149-676192242720_1672x941.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ai_7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd45b6a02-85a2-4ee1-a149-676192242720_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!ai_7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd45b6a02-85a2-4ee1-a149-676192242720_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!ai_7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd45b6a02-85a2-4ee1-a149-676192242720_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!ai_7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd45b6a02-85a2-4ee1-a149-676192242720_1672x941.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>The broader market findings describe the common direction of AI SOC development. The comparative vendor analysis reveals how differently products reach that destination and why those differences matter across operating environments. Architecture, integration model, governance heritage, deployment burden, and control-plane ownership consistently influenced vendor placement, often making a product highly suitable for one SOC model and less natural for another.</span></p><p><span>Architecture has a significant influence on vendor placement and adoption. Palo Alto Networks, CrowdStrike, and SentinelOne benefit in regulated environments where buyers want a unified platform to provide telemetry, decisioning, policy, and enforcement. That same platform dependence creates more friction in hybrid environments where buyers prioritize an independent layer across a fragmented stack. SOAR heritage can introduce administrative and process weight, but it does not inherently limit hybrid or cloud native applicability. Swimlane demonstrates that a SOAR-derived platform can support those environments when it provides direct telemetry access, federated evidence assembly, independent case construction, and production AI reasoning. D3 Security retains more of the traditional SOAR tradeoff because comparable portability and production evidence for its newer AI layer remain less developed.</span></p><p><span>Modern reasoning and investigation capabilities also need to be separated from enterprise response maturity. Vendors such as 7AI, Torq, BlinkOps, Prophet, Simbian, and Mate demonstrate that AI-native systems can assemble strong cases and support graduated autonomy, but enterprise readiness still depends on production duration, integration breadth, rollback, source-state verification, and deployment evidence. Dropzone, Qevlar, Intezer, and Radiant similarly create substantial analyst value through investigation and evidence assembly, while narrower authority and less mature governance limit their ability to serve as the primary remediation layer. Buyers therefore need to determine whether they are purchasing an autonomous investigator, a governed response operator, or a platform capable of performing both roles.</span></p><p><span>Outcome verification remains the clearest dividing line across the market. Many vendors can demonstrate that an action was initiated or that an API request was accepted. Far fewer can re-query the source system, prove that the intended state changed, confirm persistence, and connect the result to a measurable reduction in risk. This gap explains why products with strong investigation and action capabilities can remain outside the leading categories. Automated response ultimately requires evidence the execution action worked.</span></p><p><span>Viewed through the TSRO lens, the market is not divided simply between autonomous and non-autonomous products, or between trusted and untrusted vendors. Vendors differ in the type of authority they can support, the environments in which that authority is credible, and the evidence available to sustain it. AI-native vendors often lead in dynamic investigation and case progression, SOAR-derived vendors often lead in orchestration and governance, and platform vendors often lead where native enforcement and consolidation are acceptable. The strategic question is which architecture can govern the buyer&#8217;s required authority portfolio without breaking evidence continuity, accountability, or operational fit. The Trusted SOC is built through that portfolio, not purchased as a designated platform.</span></p><h2><strong><span>Vendor Profiles</span></strong></h2><p><span>The following profiles explain the product architecture, operating strengths, tradeoffs, and market implications behind each vendor&#8217;s placement. The evaluation applies only to the AI SOC capabilities and product scope examined in this report. It should not be interpreted as a judgment of the vendor&#8217;s overall corporate maturity, financial position, installed base, or broader security portfolio.</span></p><p><span>Each profile assesses the role a product can play within a Trusted SOC authority portfolio: the actions it can support, the controls surrounding those actions, and the operating environments in which that authority is most credible.</span></p><p><span>Vendor placement may change across environments because the rankings reward different forms of operational fit. A platform may benefit from native telemetry and enforcement in a consolidated enterprise while imposing greater friction in a heterogeneous or engineering-led environment. A younger AI-native product may provide stronger investigation and analyst experience while carrying less production evidence, narrower execution breadth, or less mature governance.</span></p><h3><strong><span>Torq - Innovator</span></strong></h3><h4><span>Vendor Overview</span></h4><p><span>Torq provides an AI SOC platform built around Auto Triage, Case Management, Socrates, Torq HyperAgents&#8482;, and security hyperautomation. The company is best understood less as a conventional SOAR vendor with AI features and more as an AI SOC operating layer that can ingest alerts, classify triage outcomes, construct cases, assign work to Socrates, and route remediation through deterministic or agentic workflows depending on the use case.</span></p><p><span>Torq&#8217;s center of gravity is response/action, but the platform has a stronger triage and investigation story than its automation layer alone would suggest. The company reports a 60x increase in triage velocity, a 94% decrease in mean time to respond, and at least one customer where Tier 1 alerts are fully autonomously handled, with a stated path toward automating a larger share of Tier 1 and Tier 2 alert handling by the end of 2026. Those are vendor-provided performance claims and should be treated as validation targets, but they support the core positioning: Torq is trying to own high-volume alert triage and response closure, not simply accelerate analyst review.</span></p><p><span>Torq&#8217;s strongest buyer fit is a mature SOC, MSSP/MDR provider, or large enterprise security team with a heterogeneous security stack and enough historical alert data, integrations, permissions, and workflow maturity to benefit from customer-specific learning, automation routing, and governed action execution.</span></p><h4><span>Product and Architecture</span></h4><p><span>Torq&#8217;s architecture is a layered AI SOC and automation system. Auto Triage classifies alerts into false positive, benign, and malicious outcomes. False positives can feed a detection-engineering improvement lifecycle, while malicious alerts escalate into cases. The platform supports more than 50 opinionated triage investigations across common security vendors, as well as a generalist investigator designed to handle a broader range of alert types.</span></p><p><span>The case object is the operating unit. Torq demonstrated an investigation pattern where entity and business context materially changed the verdict. In the example, a finance analyst contractor using PowerShell to download a file became more suspicious after the system connected endpoint activity to Salesforce evidence showing bulk data export and a report named &#8220;All Accounts Spring export.&#8221; The important point is that Torq is not treating alerts as isolated artifacts. It is building a context pipeline around entities, access history, business role, device state, SaaS activity, and related evidence before determining whether an alert should be closed, escalated, or remediated.</span></p><p><span>Socrates is the AI analyst and orchestrator layer. It can be used interactively by analysts, embedded in predefined investigation templates, or assigned cases directly. Once assigned, Socrates can pivot the investigation based on discovered context. Socrates is also positioned as system-wide rather than only case-scoped, with applicability to threat hunts, cross-case analysis, and process planning. This makes Socrates more than a chat interface on top of a case. It is the reasoning and planning layer that decides how much work should be agentic, how much should be deterministic, and where the human should approve or intervene.</span></p><p><span>The deterministic-versus-agentic split is one of Torq&#8217;s sharper architectural claims. Socrates can analyze available integrations and build an EDR triage workflow with one AI step and multiple deterministic steps, explaining why each choice belongs in the workflow. The system asks human-in-the-loop questions at key decision points, including containment aggressiveness and whether actions should be fully automated or human-approved. This makes Torq&#8217;s model more precise than generic agentic automation: it is governed composition, where AI plans or reasons when useful, while deterministic workflow logic executes repeatable steps when reliability, cost, and auditability matter.</span></p><p><span>Torq also emphasizes model-selection discipline and learning architecture. The company uses a weekly model research process across model foundries such as AWS Bedrock, Azure AI Foundry, and Google, with task-level model selection based on human-tagged alert datasets and a metric that balances missed malicious detections against false-positive reduction. The platform also uses two learning systems: a customer-specific encoder/classifier model trained on historical alerts, and an opinionated memory store that preserves alert and case history in a similarity-searchable vector store. Customers can import historical alert records before go-live, which means the system can start with customer-specific context rather than beginning from a blank slate.</span></p><h4><span>Market Context and Positioning</span></h4><p><span>Torq receives an Innovator placement because its architecture connects dynamic evidence gathering, case reasoning, policy-aware authority, and deterministic execution, while mature deployments and broad integrations support strong Production Delivery. Torq is one of the clearest examples of the SOAR-to-AI SOC transition. Its automation heritage gives it execution depth and integration reach, while the current product posture is more substantively AI SOC-oriented around autonomous triage, Socrates-driven investigation, model governance, customer-specific learning, and case-to-action continuity. Compared with AI SOC point solutions, Torq&#8217;s advantage is the ability to connect AI decisioning to actual workflow execution. Compared with legacy SOAR, its advantage is that Socrates can reason over cases, plan workflows, and decide which portions of an investigation should be agentic versus deterministic.</span></p><p><span>The market tradeoff is proof and dependency. Torq&#8217;s strongest claims depend on the quality of customer integrations, historical alert data, available APIs, configured permissions, and clearly defined autonomy policies. Torq addresses this concern through auto-routing options such as do nothing, create case, or trigger workflow, and by positioning agentic reasoning and actions as documented, immutable, auditable, and exportable. Buyers should test whether the system can preserve traceability from alert intake to reasoning, workflow decision, approval, action, and outcome.</span></p><p><span>Torq&#8217;s buyer fit is strongest where the organization wants to operationalize autonomy gradually. The idea that autonomy is a dial, not a binary switch, aligns Torq with enterprise adoption patterns. A SOC can begin with triage and recommendation, move into human-approved action, and eventually automate narrower or higher-confidence alert classes. That makes Torq relevant for large enterprises and service providers that need measurable automation without losing control of high-impact response decisions.</span></p><h4><span>Narrative Implication</span></h4><p><span>Torq strengthens the AI SOC report&#8217;s argument that autonomous SOC value will be measured by closed-loop operating capability rather than AI summarization. Its product story ties together alert classification, case construction, context-aware investigation, Socrates-led reasoning, deterministic workflow execution, human approval, model selection, organizational learning, and auditable action records.</span></p><p><span>Torq is an action-centric AI SOC platform with unusually strong automation depth and a more developed learning architecture than a simple AI copilot. Its differentiation is not only that it can automate workflows. It is that it can learn from customer-specific alert history, decide when to use AI versus deterministic logic, assign cases to an AI analyst agent, and preserve proof as work moves from triage to response. Torq is neither legacy SOAR nor pure AI-native analyst replacement. It is better understood as a governed autonomy layer for SOCs that want to turn repeatable analyst judgment into system-owned triage, remediation, and closure.</span></p><h3><strong><span>7AI - Innovator</span></strong></h3><h4><span>Vendor Overview</span></h4><p><span>7AI is an AI SOC platform and managed service provider focused on automating investigation, decision support, and response workflows across customer environments. The same technology stack supports multiple consumption models: customers can operate the platform with their own SOC team, consume 7AI as a managed service through PLAID ELITE, or use the platform with MSSP and MDR partners.</span></p><p><span>The company&#8217;s positioning is strongest around the final mile of SOC work. 7AI&#8217;s argument is that the hardest operational question often comes after the case is assembled: what happens next, who approves it, and how much authority the system receives. The platform moves from evidence to action through customer-defined authority levels, including recommendation, approval-required execution, supervised execution, and policy-gated automation for lower-blast-radius actions. Action plans are generated from assembled case evidence and organizational context, while confidence and policy controls determine whether an action is recommended, queued for approval, or executed. Failed or higher-impact actions can follow defined retry, escalation, and action-specific recovery paths.</span></p><h4><span>Product and Architecture</span></h4><p><span>7AI&#8217;s architecture spans detection optimization, agentic investigation, threat hunting, organizational context, workflow automation, and optional managed service delivery. Detection Optimization analyzes rules across connected sources, identifies noisy or incomplete coverage, recommends tuning, and maps detection coverage to MITRE ATT&amp;CK. The platform connects to security tools, consumes alerts and evidence, runs investigations through task-specific agents, and exposes agent reasoning. The product shows the mission assigned to each agent, the inputs used, tools called, requests made, responses received, and conclusions reached.</span></p><p><span>Enterprise Insights is the most important context feature. It allows customer-specific knowledge, including user roles, accepted tools, disallowed software, business processes, and known behavior patterns, to influence investigation and response decisions. That matters because the same signal can have different meaning across organizations or business units.</span></p><p><span>Threat Hunting supports analyst-directed, natural-language hunts and threat-intelligence-driven hunts across connected customer telemetry. Analysts can start with a hypothesis, behavior, or ATT&amp;CK technique, while incoming intelligence can initiate hunts as new indicators become available. Separately, the Skills framework lets customers create, test, and reuse investigation, hunting, and automation routines tailored to their environment.</span></p><p><span>The integration story is broad, with the platform designed to connect across security and IT systems. Integration depth determines response value because actions depend on API quality, permissions, telemetry freshness, identity mapping, and available write scope. After an action executes, 7AI can re-query the source system to confirm the resulting state and record submission, execution, and verified completion separately in the case. Federated search is an important direction because it lets the platform search connected tools without requiring all data to be copied into a central SIEM.</span></p><h4><span>Market Context and Positioning</span></h4><p><span>7AI receives an Innovator placement because its architecture connects unified case construction, transparent reasoning, graduated authority, and conclusion-driven response, while named production outcomes support strong Production Delivery despite a younger response catalog than the mature orchestration leaders. 7AI fits the AI SOC market as a hybrid platform and service model for organizations that want investigation automation tied to action. Its competitors include AI SOC point solutions, MDR modernization providers, SOAR and automation platforms adding AI, and security platform vendors embedding autonomous response into their own control planes.</span></p><p><span>7AI&#8217;s market position combines cross-stack neutrality, organizational context, transparent agent reasoning, and flexible delivery across software, managed service, and partner-led models. Its architecture begins with agentic investigation and extends into governed response, while detection optimization and threat hunting create feedback loops that can improve future case quality. Hunting findings can inform detection coverage, and investigation or response outcomes can support subsequent rule tuning. The value of this model depends on integration depth, customer-specific context, and how consistently those feedback loops operate in production.</span></p><h4><span>Narrative Implication</span></h4><p><span>7AI sharpens an important point for the AI SOC report: the final mile of SOC automation is organizational judgment encoded into a repeatable workflow. The platform is designed around the idea that the SOC needs a system that can learn customer context, gather evidence, explain reasoning, suggest or execute next steps, verify the resulting state, and let humans decide where automation should stop.</span></p><p><span>The product&#8217;s publication story is delivery flexibility. 7AI can be consumed as software, service, or partner-enabled capability, making it relevant to buyers that want agentic SOC outcomes but differ in how much operational responsibility they want to retain internally.</span></p><h3><strong><span>Palo Alto Networks - Trailblazer</span></strong></h3><p><span>Palo Alto Networks is assessed in this profile only against the AI SOC capabilities available within the Cortex platform. Its placement does not reflect Palo Alto Networks&#8217; overall cybersecurity market position or the breadth and maturity of its broader product portfolio.</span></p><h4><span>Vendor Overview</span></h4><p><span>Palo Alto Networks&#8217; AI SOC proposition is centered on Cortex XSIAM and is informed by the company&#8217;s long history of building enterprise security tools and platforms. Palo Alto Networks frames AI as an important new capability within a 20-year security history of engineering security platforms. That maturity matters: the platform is not presented as a standalone AI assistant, but as an operational SOC environment shaped by enterprise security controls, scalability requirements, governance, playbooks, case management, and analyst workflow design.</span></p><p><span>The relevant product scope for this report includes XSIAM, Cortex XDR heritage, Demisto-derived SOAR and playbook capabilities, case management, automation, and data ingestion across Palo Alto and third-party sources. Palo Alto Networks&#8217; core narrative is that the AI SOC must be a full-stack operating platform rather than a thin AI overlay. In practice, this means collection, normalization, enrichment, detection, grouping, risk scoring, case investigation, root-cause analysis, and remediation workflows are intended to sit in a common console and decision loop.</span></p><p><span>Palo Alto Networks is deliberately introducing automation gently rather than forcing an abrupt move to full autonomous response. The XSIAM command center highlights cases that &#8220;could have been automated,&#8221; which is designed to show SOC teams where they could have benefited from more automation and automatic response without immediately removing human control. This experience supports the twin objectives: reducing confirmed MTTD toward less than 10 minutes and reducing MTTR toward a similar single-digit-minute target, with the latter acknowledged as aspirational for many SOC teams because it depends on trusted playbooks and AI agents, permissions, approvals, and operational confidence.</span></p><h4><span>Product and Architecture</span></h4><p><span>XSIAM can be described as a three-layer operating model. The data layer ingests and normalizes evidence from endpoints, firewalls, network flows, identity systems, cloud sources, Cortex telemetry, and selected third-party EDR and telemetry providers, as well as any other data source. The decision layer correlates and clusters that evidence into cases, applies analytics, performs risk scoring, and provides AI-supported investigation. The execution layer uses playbooks, SOAR actions, case management, and agentic workflows to move from understanding an incident to taking approved action.</span></p><p><span>A key architectural differentiator is Palo Alto Networks&#8217; emphasis on the complete SOC pipeline. The company positions XSIAM Command Center as a unified view across ingestion, normalization, detection, grouping, scoring, and case management. The case investigation view then adds AI-generated summaries, attack-chain visualization, next-step recommendations, agentic Q&amp;A, and transparent explanation of why alerts have been grouped. This reinforces XSIAM&#8217;s role as a full-stack platform for collection, normalization, investigation, root-cause analysis, and remediation rather than a disconnected AI layer bolted onto existing SOC tooling.</span></p><p><span>Palo Alto Networks also states that AI SOC and the data platform must converge. Its position is that detection, investigation, and response quality depend on normalized, enriched, contextualized data before an incident occurs. The company supports federated search where appropriate, but its stated belief is that a core baseline dataset is necessary for high-fidelity detection and response. It also emphasizes that anomalous behavior alone is not proof of malicious activity; security research expertise and data science need to be combined to determine whether deviations from baseline are actually meaningful.</span></p><p><span>Palo Alto Networks&#8217; platform is best suited for large enterprises and advanced mid-market organizations with mature SOC operations, high telemetry volumes, and complex, globally distributed environments. Its SaaS-only model is designed to handle large-scale data processing, analytics, and AI-driven automation, making it less suitable for organizations without dedicated security teams. With 26 global hosting regions, including federal and sovereign options, it is particularly well aligned to Fortune-scale and regulated customers that require strong data residency support and the ability to operate across multiple jurisdictions and distributed SOC teams.</span></p><p><span>Palo Alto Networks positions automation as a spectrum ranging from deterministic workflows to hybrid AI-assisted playbooks and fully agentic operations, emphasizing gradual adoption rather than immediate full autonomy. The platform defaults to human approval for sensitive actions and uses guardrails such as RBAC/SBAC and cost controls, while features like the &#8220;could have been automated&#8221; view help SOC teams build trust through repeated validation of automation outcomes. This staged, evidence-based approach aligns with customer hesitation around fully autonomous response and is reinforced by support for customer-built agents and external AI tools, enabling organizations to start with familiar processes and progressively expand automation as confidence grows</span></p><h4><span>Market Context and Positioning</span></h4><p><span>Palo Alto Networks receives a Trailblazer placement because Cortex demonstrates mature governance, native enforcement, source-state verification, and enterprise-scale Production Delivery, while complete lifecycle ownership remains distributed across the broader platform and its newest agentic capabilities are still maturing. Palo Alto Networks is positioned as a major platform vendor applying AI-enabled operations to the historical SOC stack. The competitive frame includes SIEM modernization, XDR expansion, SOAR consolidation, AI copilots, MDR-led operating models, and AI-native SOC entrants. XSIAM&#8217;s market relevance is strongest where the buyer wants a consolidated security-operations platform that can absorb more of the SOC decision loop rather than a narrow AI assistant or investigation overlay.</span></p><p><span>The Cortex XSOAR foundations remain an important part of this positioning because response orchestration is the point at which AI SOC capabilities move from investigation support into operational execution. In the XSIAM model, SOAR becomes less of a separate automation tier and more of an embedded execution mechanism within the SOC workflow. The demo&#8217;s emphasis on shift-change automation, AI-enabled playbook steps, and case handoff illustrates how Palo Alto Networks is using automation not only for response actions, but also for routine operational burden reduction.</span></p><p><span>The strongest differentiation is therefore not simply &#8220;AI in the SOC,&#8221; but the combination of enterprise platform depth, data normalization, integrated investigation, human-governed automation, and scaled deployment options. Palo Alto Networks is also making the analyst experience transparent: AI-generated summaries, attack-chain graphs, recommendations, and explanations are used to orient analysts and accelerate action without hiding the reasoning behind case construction.</span></p><h4><span>Narrative Implication</span></h4><p><span>Palo Alto Networks illustrates how the AI SOC category can be shaped by consolidated security platforms as well as AI-native vendors. XSIAM aligns with SACR&#8217;s category definition where AI SOC is understood as an operating model for the SOC decision loop rather than a chat interface. The solution applies AI across detection, investigation, explanation, automation, and response, while preserving enterprise guardrails and gradual human-in-the-loop adoption.</span></p><p><span>Palo Alto Networks&#8217; platform is most suitable for very large, geographically dispersed customers with high data volumes; its 26-region hosting footprint including federal and sovereign options; and its full-stack approach to collection, normalization, investigation, root-cause analysis, and remediation are significant here. The distinctive approach to automation adoption: guiding teams toward more automation over time, building confidence through repeated iterations of specific SOC use cases, and allowing customers to use their own AI tools or agents are sure to improve trust and acceptance.</span></p><h3><strong><span>BlinkOps - Innovator</span></strong></h3><h4><span>Vendor Overview</span></h4><p><span>BlinkOps is an Agentic Security Operations Platform that packages AI SOC and SOAR capabilities as part of a broader security automation environment. The platform is organized around Workflow Studio, Agent Studio, and Solution Studio. Workflow Studio is the deterministic workflow layer, Agentix Studio is the agent-builder layer, and Solution Studio is the user-facing application, dashboard, and case-management layer.</span></p><p><span>BlinkOps is best understood as an AI-enabled security automation platform rather than a single-purpose AI SOC product. AI SOC is one capability area within a broader platform that also addresses SOAR, vulnerability management, cloud security, and other security program workflows. The strongest buyer fit is a team that wants to automate across an existing stack rather than replace core detection, SIEM, EDR, or case-management systems.</span></p><h4><span>Product and Architecture</span></h4><p><span>BlinkOps uses a layered operating design. Deterministic workflows handle ETL-style tasks, structured checks, and initial triage. A hybrid layer uses classic statistics, machine learning, and smaller models for enrichment, routing, and context assembly. Larger reasoning models are reserved for complex synthesis or novel situations.</span></p><p><span>The platform&#8217;s operating loop can be summarized as See, Understand, Decide, and Act, with a feedback arc that can revisit investigations as new evidence appears. BlinkOps separates decisioning from execution. A verdict can be challenged before an action proceeds, and agents operate with scoped abilities defined by customer roles, responsibilities, and policy constraints.</span></p><p><span>Human review is the default operating posture. Autonomy is earned over time as agent performance is observed and trusted. The platform starts with deterministic behavior and can increase autonomy as workflows mature. For situations outside known patterns, a novelty branch routes the work through a different reasoning path and updates future investigation artifacts.</span></p><p><span>BlinkOps&#8217; scale claims, including integration counts and microagent counts, reinforce the platform&#8217;s breadth, but the key architectural issue is practical action depth: which connectors can gather evidence, which can change state, and how each action is governed, logged, retried, or reversed.</span></p><h4><span>Market Context and Positioning</span></h4><p><span>BlinkOps receives an Innovator placement because its architecture connects specialized agents, deterministic workflows, configurable authority controls, and broad action reach, while mature automation use supports strong Production Delivery despite less specific deployment evidence for the Agentic SOC layer. BlinkOps fits the SOAR + AI and security automation branch of the AI SOC market. It is relevant where buyers want AI SOC capabilities embedded in a workflow, automation, and orchestration platform rather than in a standalone AI analyst product. Its competitive set includes SOAR automation vendors, AI SOC point solutions, MDR-adjacent AI SOC vendors, and broad security platforms adding AI-powered SOC features.</span></p><p><span>BlinkOps&#8217; go-to-market theme is augmentation of existing tools. The company helps customers identify, orchestrate, and improve workflows across the tools they already use. That makes BlinkOps strongest where a buyer has many fragmented tools, established workflows, and a desire to increase automation without rip-and-replace.</span></p><h4><span>Narrative Implication</span></h4><p><span>BlinkOps shows that AI SOC may become an automation capability embedded inside broader security operations platforms. Its strongest narrative is layered automation: deterministic workflow, scoped agents, human review, novelty handling, and progressive autonomy.</span></p><p><span>The product&#8217;s long-term relevance depends on proof at the action layer. The most important question is not whether BlinkOps can build workflows, but whether those workflows preserve evidence, challenge decisions before execution, handle failure, verify state change, and give teams enough control to trust automation in production.</span></p><h3><strong><span>Swimlane - Innovator</span></strong></h3><h4><span>Vendor Overview</span></h4><p><span>Swimlane Turbine is an agentic AI automation platform that sits above existing security stacks. It ingests alerts and context from customer-owned tools, converts them into durable case state, drives governed response actions, and preserves proof for analysts, managers, and auditors. Depending on the buyer&#8217;s starting point, Swimlane can serve as an AI SOC operating layer or as a path to modernize an existing SOAR program with AI.</span></p><p><span>This matters because many buyers will adopt AI SOC by upgrading the orchestration and action layer they already trust. Swimlane&#8217;s strongest fit is the enterprise, federal, regulated, and MSSP/MDR buyer that needs cross-tool execution, repeatable workflow control, progressive autonomy, and audit-grade reconstruction.</span></p><h4><span>Product and Architecture</span></h4><p><span>Swimlane Turbine&#8217;s architecture is best understood as three connected layers: a federated data fabric for querying customer-owned sources, Hero AI agents for investigation and workflow generation, and the case management and orchestration layer for execution and proof. The platform depends on customer telemetry for detection input, while Turbine can become the system of record for investigation, decision, action, and closure.</span></p><p><span>The case object is the most important architectural primitive. Swimlane describes the case as the durable work unit from evidence intake through enrichment, investigation, recommendation, approval, execution, verification, and closure. Each state transition is intended to remain visible in the case record, including agent decisions, human review, approval, execution, failure, retry, rollback, and final outcome.</span></p><p><span>The action surface is broad by AI SOC standards and mature by SOAR standards. Swimlane reports response coverage across endpoint, identity, cloud/runtime, email/collaboration, ITSM/workflow, network, and custom APIs. The buyer implication is straightforward: Swimlane can reach many control points where the customer has integrations, credentials, policies, and permissions configured.</span></p><p><span>Governance is central to Swimlane&#8217;s credibility. Agent identities are governed through RBAC, with agents authorized only for specific data and tools. Policy decisions can consider confidence, evidence completeness, asset criticality, user role, privilege level, business unit, action type, blast radius, incident severity, time window, and exception state. Analysts can edit, pause, reject, override, or escalate AI-generated action plans before or during execution.</span></p><h4><span>Market Context and Positioning</span></h4><p><span>Swimlane receives an Innovator placement because it combines mature orchestration, governance, case continuity, rollback, and enterprise-scale execution with demonstrated production AI reasoning and the ability to operate across SIEM-centric, hybrid, and no-SIEM environments. Its federated data architecture allows Turbine to assemble evidence directly from customer security and cloud systems, while Hero AI connects that evidence to investigation, recommendation, governed action, and durable case records. Swimlane reaches the Innovator category through a SOAR-derived architecture, demonstrating that architectural heritage does not determine leadership when the product can connect the AI SOC lifecycle and deliver it credibly in production.</span></p><p><span>The tradeoff is proof. Buyers should not reward AI labeling on top of conventional SOAR without case-to-action evidence. The strongest evaluation asks what evidence the agent used, what action it recommended, what policy applied, who approved it, what executed, what state changed, what failed, what rolled back, and what remained open.</span></p><h4><span>Narrative Implication</span></h4><p><span>Swimlane broadens the AI SOC narrative. The market will be built by AI-native startups and by automation platforms that already own response plumbing and can use AI to reduce the distance between evidence, decision, action, and proof.</span></p><p><span>The product&#8217;s strongest publication story is trustworthy execution. Swimlane can bring AI into operational workflows without abandoning deterministic controls, approval paths, analyst override, or auditability. That makes it an important reference point for buyers that want autonomous security operations to evolve from governed automation rather than from open-ended reasoning alone.</span></p><h3><strong><span>Exaforce - Innovator</span></strong></h3><h4><span>Vendor Overview</span></h4><p><span>Exaforce&#8217;s core bet is that autonomous SOC response requires a real-time model of the environment rather than an LLM layered over alerts. The platform is built around a knowledge graph that combines alert data, configuration state, identity behavior, session context, and connected system activity. The broader platform spans detection, triage, investigation, and response, with Exabot Respond serving as the action-oriented component that carries the context assembled earlier in the lifecycle into governed execution.</span></p><p><span>Exaforce is best positioned as a context-driven AI SOC platform with response capability, not as a generic AI assistant. Its differentiation comes from connecting evidence, context, policy, and scoped action inside a single operating model.</span></p><h4><span>Product and Architecture</span></h4><p><span>Exaforce&#8217;s operating model is built on a knowledge graph that combines alert data with configuration, identity, session, and behavioral context. The graph feeds a multi-phase reasoning workflow covering classification, planning, analysis, generation, and validation. The output is a structured verdict with plain-English rationale and action plans. Business context rules allow customers to encode constraints such as protected user groups or business units at the planning stage.</span></p><p><span>Exabot Respond is the response-oriented task agent within the broader Exaforce platform. It uses the evidence, entity relationships, behavioral context, and verdict developed during detection and investigation to generate and execute response actions. The response model includes stateful workflows, retry policies, escalation when connectors are unavailable, timeout and escalation chains for unavailable approvers, and case records that remain open until actions resolve.</span></p><p><span>Common automation use cases include user confirmation workflows, session revocation, password resets, ticketing, and email actions. Exabot Respond can execute across endpoint containment, identity session revocation, cloud isolation, email purge, and custom API actions where configured. Customers can tailor response behavior through configurable workflows, action catalogs, business-context rules, approval points, and custom API actions. Approval requirements are governed by policy.</span></p><p><span>Exaforce&#8217;s response strength comes from applying investigation context and policy to configurable actions across multiple control domains. Granular session control is a concrete example of that precision: the platform can terminate higher-risk sessions while preserving lower-risk activity where appropriate. This reduces exposure while limiting unnecessary business disruption. Source-system state confirmation strengthens the model by checking whether the expected change occurred before a risk finding is closed. Automated rollback is less mature than forward execution, leaving manual inverse actions and compensating controls important for recovery.</span></p><h4><span>Market Context and Positioning</span></h4><p><span>Exaforce receives an Innovator placement because its architecture connects a real-time evidence model, defensible reasoning, policy constraints, and source-aware response, while credible production use supports delivery and action-dependent rollback remains the principal maturity constraint. Exaforce sits between SIEM incumbents applying AI to log data, AI SOC specialists focused on triage and investigation, and SOAR platforms extending playbook automation with AI reasoning. Its market argument is that response reliability depends on context depth, policy constraints, and scoped action precision rather than reasoning quality alone.</span></p><p><span>The platform works with existing tools, including SIEM environments, and can pass verdicts and context back to originating systems. Customers can retain their current detection investments while using Exaforce to add contextual detection, triage, investigation, and governed response across the existing stack. The strongest buyer fit is a security team that wants broader case-to-resolution automation without replacing its established control and telemetry layers.</span></p><h4><span>Narrative Implication</span></h4><p><span>Exaforce reinforces a broader AI SOC pattern: reliable response depends on the quality and continuity of the work performed before an action is selected. Detection, triage, investigation, organizational context, policy, and execution operate as parts of one case-to-resolution system. Exaforce&#8217;s contribution is the connection between that broader operational coverage and governed response, with granular session control, scoped blast-radius controls, and graduated deployment providing concrete examples of how autonomy can be constrained.</span></p><p><span>Exaforce&#8217;s publication story is strongest when framed around comprehensive case context, configurable execution, precision, and governance. The platform has a credible path to owning the last mile of response where customers can supply the integrations, permissions, policies, and audit requirements needed to support controlled execution.</span></p><h3><strong><span>Prophet Security - Innovator</span></strong></h3><h4><span>Vendor Overview</span></h4><p><span>Prophet Security provides an agentic SOC platform centered on Prophet AI SOC Analyst, with adjacent capabilities for AI Threat Hunter, Watchtower human oversight generally available, and Detection Engineer functionality on the product roadmap. The platform is designed for enterprise SOC teams that want to increase investigation coverage, reduce manual triage, and introduce governed remediation without replacing their existing SIEM, EDR, identity, email, cloud, ITSM, or collaboration systems.</span></p><p><span>Prophet&#8217;s primary AI SOC control point is detection and decision with response extensions. The platform meets customers where their telemetry and workflows already live. It is not positioned as a SIEM migration platform, data lake product, MSSP operating console, or full SOAR replacement.</span></p><h4><span>Product and Architecture</span></h4><p><span>Prophet AI SOC Analyst ingests alerts, builds and executes investigative plans, queries connected tools, groups related findings into investigations or cases, dispositions activity, and recommends or executes Agent Actions. Prophet uses frontier models rather than training a proprietary foundation model. The product differentiation is investigative depth, evidence transparency, and an analyst-oriented user experience.</span></p><p><span>The platform does not require customers to replicate or migrate data into a new SIEM. It queries evidence where it resides, including SIEM, Databricks, Snowflake, S3, EDR, identity, email, SaaS, cloud, network, and ITSM sources. Prophet emphasizes API-based integration, arbitrary webhook ingestion for custom alert sources, and Prophet-built retrieval agents where raw API-query traceability and auditability are required. MCP can support some technology classes, while Prophet&#8217;s own retrieval layer is more relevant where transparency and accuracy are critical.</span></p><p><span>Agent Actions are the response layer. The product supports natural-language workflow creation, translation into deterministic branches and REST API calls, autonomy settings across autonomous, approval-required, and recommend-only modes, and rate limits to restrict action frequency. Backtesting allows customers to see which historical investigations would have triggered an action before enabling it in production. Actions can cover identity, endpoint, cloud, email, and ITSM or workflow domains, with enforcement executed through customer-owned tools.</span></p><p><span>Prophet AI Threat Hunter extends the platform into autonomous hunting with prebuilt MITRE ATT&amp;CK hunts, custom natural-language hunt creation, scheduled reporting, remediation actions, and a threat-researcher agent that monitors emerging threats. Watchtower is an optional 24x7 human oversight service that can review selected investigations, add analysis, tune agents, orchestrate remediation, and provide daily rollups.</span></p><h4><span>Market Context and Positioning</span></h4><p><span>Prophet Security receives an Innovator placement because its architecture connects contextual investigation, governed action, backtesting, rate limits, and source-aware verification, while current product evidence supports Production Delivery and broader independent deployment proof remains the primary diligence item. Prophet sits in the AI SOC segment as an investigation and governed response layer around existing SOC tooling. Its most natural buyer is an enterprise SOC with existing telemetry, established workflows, and a desire to improve coverage and response consistency without replacing the current operating model.</span></p><p><span>The company&#8217;s go-to-market focus is the enterprise segment, particularly large organizations that want to control outcomes directly. Prophet is not primarily positioned around MSSP partnerships. Watchtower provides a managed oversight option, but the product&#8217;s primary market posture remains enterprise-direct.</span></p><h4><span>Narrative Implication</span></h4><p><span>Prophet represents a case- and evidence-centered AI operating layer that connects alert intake, investigation, decisioning, governed action, and proof. Its strongest claims are durable investigation objects, chain of custody from evidence to action, source-system action verification, rollback where supported, policy constraints, approval handling, and operational metrics.</span></p><p><span>The product&#8217;s publication story is case-to-action discipline. Prophet&#8217;s decisioning and orchestration are native, while enforcement occurs in customer-owned tools. Completeness therefore depends on connector availability, API permissions, source-system capabilities, and the customer&#8217;s willingness to define autonomy boundaries.</span></p><h3><strong><span>Mate Security - Pioneer</span></strong></h3><h4><span>Vendor Overview</span></h4><p><span>Mate Security&#8217;s core bet is that AI SOC outcomes degrade when environment understanding is treated as an afterthought. The platform is built around a Security Context Graph that captures architecture, ownership, SOPs, investigation history, and operational nuance, then uses that graph as the substrate for investigation and decision support.</span></p><p><span>Mate positions itself on the augmentation path. The vendor expects SOC roles to evolve toward a more engineering-led operating model, where detections and agents are iterated and benchmarked over time. The platform aims to increase analyst throughput and decision quality while keeping humans in the loop for business-impacting response decisions.</span></p><h4><span>Product and Architecture</span></h4><p><span>Mate&#8217;s platform is anchored in a Security Context Graph designed to learn a customer environment the way a new analyst would, but faster and more systematically. It ingests and continuously updates context from SIEM and data lake schemas, ticketing system case history, Slack incident channels, onboarding guides, SOPs, architecture diagrams, and cloud segmentation configurations.</span></p><p><span>The output is not just a static knowledge base. Mate organizes context into structured primitives such as memories, playbooks, architecture maps, and policies. Investigation is graph-first and transparency-forward. The platform includes an investigation queue and case-management interface with AI-generated summaries, prioritization, and suggested response actions. A browser extension can overlay context and task guidance inside third-party tools, allowing analysts to review collection steps, user profiling, and tool queries without switching platforms.</span></p><p><span>Mate has expanded into detection engineering and threat hunting. The product centralizes detections spread across tools, tracks coverage and quality, and supports federated execution where detections and hunts run against data at the source rather than requiring full SIEM ingestion. Analysts can initiate a hunt by providing a threat-intelligence report or a free-text hypothesis. Mate extracts relevant indicators and techniques, searches connected tools, correlates the results, and can translate the findings into detection content. Mate frames this as a hybrid stance that recognizes compliance and near-real-time requirements still require hot storage for some use cases.</span></p><p><span>Mate provides governed remediation capabilities such as session revocation, password reset, email purging, false-positive closure, and emerging device isolation. Response actions are governed by the CPR model: Confidence, Precision, and Rollback. Production use is staged, with lower-impact actions more broadly suited to automation and user-account or device-level actions adopted more cautiously.</span></p><h4><span>Market Context and Positioning</span></h4><p><span>Mate Security receives a Pioneer placement because its Security Context Graph, constrained tools, judge agents, and execution-time validation create strong Architectural Alignment, while limited deployment history and downstream-dependent rollback keep Production Delivery in a developing stage. Mate sits in the detection and decision band of the AI SOC landscape, competing with vendors that pair investigation quality with governed remediation. Its differentiation is the context substrate. Mate argues that many vendors are beginning to talk about context, but that context must be foundational and continuously refreshed to support defensible AI decisions.</span></p><p><span>The platform also intersects with detection engineering, investigation automation, response guidance, and supervised remediation. Its comparison set includes AI SOC point solutions, context-first investigation platforms, and SOAR + AI vendors that rely more heavily on deterministic workflow automation.</span></p><h4><span>Narrative Implication</span></h4><p><span>Mate reinforces a core AI SOC pattern: the limiting factor is often whether the system can reliably acquire and apply environmental context without burdening teams with manual knowledge engineering. The strongest AI SOC approaches are converging on an explicit context substrate as the prerequisite for trustworthy decisions.</span></p><p><span>The product&#8217;s publication story is context-led trust. Mate is strongest where buyers believe AI SOC requires a durable model of the environment, not just faster alert investigation. Its remediation path remains governed, staged, and aligned to customer SOPs rather than framed as broad fully autonomous execution.</span></p><h3><strong><span>Simbian - Pioneer</span></strong></h3><h4><span>Vendor Overview</span></h4><p><span>Simbian positions itself as an AI-native first responder for security operations. The platform sits alongside the existing stack rather than replacing the SIEM, with the goal of compressing the alert lifecycle from triage into decision and action without forcing teams through a heavy playbook-authoring exercise.</span></p><p><span>The company&#8217;s center of gravity is an agent family tied to a shared reasoning engine and context lake. Simbian&#8217;s pitch is that the SOC functions better as a connected decision system that learns from analyst feedback and repeated patterns than as a collection of disconnected automations.</span></p><h4><span>Product and Architecture</span></h4><p><span>Simbian uses a reasoning engine that runs investigations end to end, selects and cross-checks models to reduce hallucination risk, and uses contextual knowledge to reach a defensible conclusion. The platform is organized around multiple agents that share the same underlying reasoning engine and context substrate. The AI SOC agent is the common anchor, while peer agents such as threat hunting and pen testing can feed and consume shared context.</span></p><p><span>The product performs alert-to-case normalization across a heterogeneous tool layer. It aggregates alerts across common sources such as SIEM, EDR, identity, and cloud, with the goal of completing many investigations before an analyst begins work. For MDR-style delivery, the value is partly translation and normalization across heterogeneous customer stacks.</span></p><p><span>Simbian&#8217;s autonomy model is staged and selectable. The vendor distinguishes &#8220;human in control&#8221; from strict human-in-the-loop gating. Autonomy can be configured by environment, alert type, user group, and confidence threshold. The adoption path starts with read-only operation, moves into auto-close for false positives, then notifications, then containment. Containment is intentionally scoped toward reversible actions as the default safety posture.</span></p><p><span>The Context Lake is the self-improvement substrate. It stores supplementary organizational knowledge and feedback rather than raw logs. It can incorporate SOPs, travel schedules, organizational constraints, and agent-discovered patterns, then reuse those patterns to reduce repeated work and improve decision consistency.</span></p><h4><span>Market Context and Positioning</span></h4><p><span>Simbian receives a Pioneer placement because its architecture connects AI-native reasoning, durable cases, customer-controlled authority, and bounded execution, while independent production evidence and source-system validation remain less mature than the breadth of its capability claims. Simbian sits between triage relief, governed containment, and MDR-compatible AI SOC delivery. It is strongest for environments where humans cannot investigate everything, where outcomes are measured by closure rate and time to disposition, and where buyers want a staged path from investigation into containment.</span></p><p><span>Simbian is structurally compatible with MDR delivery through RBAC based multi-tenate architecture, and normalized heterogeneous tool stacks and autonomy tuning by customer. Its market role depends on whether buyers want AI SOC as a first-responder system that works across existing tools, learns from local context, and gradually assumes more operational authority.</span></p><h4><span>Narrative Implication</span></h4><p><span>Simbian is a strong example of the AI SOC market moving from investigation assistance into an execution-oriented operating layer. The important signal is the operating model: a unified reasoning engine and durable context substrate, paired with an autonomy progression that starts in read-only and can move toward containment under customer policy.</span></p><p><span>The product&#8217;s publication story is staged operational trust. Simbian does not need to claim immediate full autonomy to be relevant. Its value comes from converting repeated investigative work into context-aware response patterns while keeping containment scoped, reversible, and adjustable by customer policy.</span></p><h3><strong><span>CrowdStrike - Emerging Player</span></strong></h3><p><span>CrowdStrike is assessed in this profile only against the AI SOC capabilities available within the Falcon platform. Its placement does not reflect CrowdStrike&#8217;s overall cybersecurity market position or the breadth and maturity of its broader product portfolio.</span></p><h4><span>Vendor Overview</span></h4><p><span>CrowdStrike positions the Falcon platform as the foundation for its AI SOC strategy, integrating AI, telemetry, SIEM, automation, and response into a single security operations platform. The relevant product scope includes Falcon Next-Gen SIEM, Charlotte AI (including Charlotte AI AgentWorks, and Charlotte AI Agentic SOAR), managed detection and response services, strategic advisory services, and adjacent Falcon controls across endpoint, identity, cloud, browser, data protection, exposure management, and threat intelligence.</span></p><p><span>CrowdStrike represents the platform-consolidation path for AI-enabled security operations. Falcon combines native telemetry with data and controls from the customer&#8217;s broader security stack, providing a common environment for visibility, detection, unified case management, investigation, workflow coordination, and response. This extends Falcon&#8217;s SIEM, AI, automation, and response capabilities into a broader operating model for SOC modernization, although the degree of continuity across the environment depends on integration depth, licensing, and customer configuration.</span></p><h4><span>Product and Architecture</span></h4><p><span>The Falcon architecture can be understood as a three-layer operating model. The onboarding layer collects and prepares data through the Falcon sensor integrations and data-pipeline capabilities. The operational layer uses Falcon Next-Gen SIEM and Charlotte AI capabilities, as well as customer-defined knowledge sources to support triage, investigation, recommendation, and workflow construction. The orchestration layer uses Charlotte Agentic SOAR capabilities, and integrations to coordinate actions across first-party modules and third-party systems.</span></p><p><span>CrowdStrike&#8217;s strongest AI SOC relevance is in cross-layer telemetry, case-centered investigation, governed automation, human-in-the-loop approval, traceable agent execution, managed detection, and integration breadth. The platform benefits most where Falcon already serves as a major control plane, because endpoint, identity, cloud, threat intelligence, SIEM, MDR, and response context can be brought into a common operating environment.</span></p><p><span>Data-pipeline and acquisition-driven capabilities strengthen the broader architecture when they are integrated into Falcon workflows. Falcon Onum and related data movement, enrichment, transformation, routing, monitoring, and reduction capabilities are relevant to the AISOC data foundation. Other adjacent modules can expand identity, cloud, browser, AI security, exposure management and data protection coverage. The degree of operational continuity depends on module licensing, integration maturity, deployment scope, and customer configuration.</span></p><p><span>CrowdStrike can support recommendation, governance, coordination, and execution with operator-defined autonomy. The operator may be the customer or CrowdStrike&#8217;s managed service, depending on the deployment model. Closed-loop risk-reduction verification, multi-tier approval chains, and cross-module action depth vary by use case, licensed capabilities, deployed Falcon modules, integration depth, and customer policy.</span></p><h4><span>Market Context and Positioning</span></h4><p><span>CrowdStrike receives an Emerging Player placement because Falcon provides mature native enforcement, governance, and production reach, while the complete cross-stack reasoning, case-continuity, verification, and rollback chain remains less fully connected across the broader AI SOC lifecycle. CrowdStrike is the platform-native consolidation path in the AI SOC market. Its competitive frame includes SIEM vendors adding AI, XDR vendors expanding into cross-domain operations, SOAR platforms adding generative workflows, MDR providers using AI to scale service delivery, and AI SOC point solutions. Its differentiation lies in the breadth of Falcon-native telemetry, threat intelligence, managed detection, unified case handling, response control points, data-pipeline capabilities, and ecosystem integrations.</span></p><p><span>The strongest fit is an organization that already uses Falcon extensively or wants to consolidate security operations around a common data and response platform. Large and technically mature enterprises are best positioned to operate the broader architecture directly, while smaller or resource-constrained teams can access portions of the model through Falcon Complete MDR and strategic services. Broad internal AI SOC adoption still requires maturity around data-source onboarding, policy design, workflow governance, connector management, standard operating procedure maintenance, and agent-trace review.</span></p><h4><span>Narrative Implication</span></h4><p><span>CrowdStrike shows how the AI SOC category will be shaped by major platform vendors as well as AI-native startups. A platform-native approach can connect telemetry, threat intelligence, unified case management, AI-assisted reasoning, orchestration, managed services, and response controls inside a broader security operating environment. This gives AI agents access to more consistent context than they would receive when operating independently across fragmented tools.</span></p><p><span>The tradeoff remains dependence on platform footprint and integration maturity. CrowdStrike&#8217;s strongest AI SOC value emerges when Falcon is central to the customer&#8217;s SOC architecture. In more fragmented environments, realized value depends increasingly on data onboarding, integration depth, workflow design, licensing, and governance discipline.</span></p><h3><strong><span>AIStrike - Pioneer</span></strong></h3><h4><span>Vendor Overview</span></h4><p><span>AIStrike positions itself as an AI-native security operations control plane that sits above existing SIEM, EDR, cloud, identity, and ITSM systems. The company&#8217;s core argument is that the SOC bottleneck has shifted from detection and summarization toward triage, investigation, and action. AIStrike therefore frames AI SOC as a closed-loop operating model: operationalize threat intelligence and environment context, produce defensible case decisions, drive governed response actions, and feed outcomes back into continuous improvement.</span></p><p><span>AIStrike&#8217;s center of gravity is a hybrid of detection engineering, AI-powered investigation, and response automation. Autonomous response becomes more trustworthy when upstream detection posture is improved: coverage gaps are identified, noisy rules are tuned, and investigation context becomes consistent enough that action recommendations are repeatable.</span></p><h4><span>Product and Architecture</span></h4><p><span>AIStrike uses an AI orchestrator that generates a runbook across enrichment, prioritization, investigation, and response, with each step visible and auditable. The platform combines external threat intelligence with customer context such as assets, identities, vulnerabilities, misconfigurations, and historical case data. That context supports case grouping and pattern recognition rather than treating alerts as isolated units.</span></p><p><span>The product story is strongest around case-to-action orchestration. AIStrike generates response plans from investigation context rather than relying only on static, pre-authored playbooks. The action surface includes notification and workflow systems, ticketing systems with bidirectional updates, and state-changing containment or identity actions such as endpoint isolation, process termination, password reset, token revocation, and IP or hash blocking where configured.</span></p><p><span>AIStrike&#8217;s autonomy model is tiered by action impact. Low-risk or clear-cut actions can move toward human-on-loop operation, while high-impact actions require explicit approval. Timer-based autonomy allows AIStrike to schedule an action, notify the analyst, and proceed if no one intervenes within a defined window. This creates a governed response mechanic rather than blanket hands-off remediation.</span></p><p><span>Detection posture improvement is part of the architecture. AIStrike produces detection health outputs that identify coverage gaps, silent rules, noisy rules, and ready-to-deploy fixes. This improves the upstream conditions that make downstream automation safer.</span></p><h4><span>Market Context and Positioning</span></h4><p><span>AIStrike receives a Pioneer placement because its architecture connects knowledge-graph context, detection feedback, risk-tiered authority, and broad response claims, while uneven live evidence across representative action families keeps Production Delivery in a developing stage. AIStrike sits between AI triage and investigation vendors, SOAR and workflow vendors, and platform-native SIEM/XDR suites. Its differentiation is the claim that action becomes defensible when the system understands threat intelligence, customer context, and detection posture together.</span></p><p><span>The market fit includes enterprise SOCs that want efficiency and consistency without replacing the existing stack, and MSSP/MDR providers that want higher operational throughput. The enterprise buyer will likely focus on policy, approval, auditability, rollback, and governance. Service-provider buyers may emphasize throughput and repeatability.</span></p><h4><span>Narrative Implication</span></h4><p><span>AIStrike pushes the AI SOC narrative toward action-capable AI SOC rather than better summarization. Its product story is built around case management, case-to-action continuity, and visible orchestration across enrichment, prioritization, investigation, and response.</span></p><p><span>The product&#8217;s publication story is that closed-loop response depends on the quality of the upstream decision system. AIStrike is strongest where it can connect threat intelligence, customer context, detection health, investigation evidence, and governed response into a single operating path.</span></p><h3><strong><span>Stellar Cyber - Emerging Player</span></strong></h3><p><span>Stellar Cyber is assessed in this profile only against its AI SOC capabilities available within its platform. Its placement does not reflect Stellar Cyber&#8217;s overall cybersecurity market position or the breadth and maturity of its broader portfolio.</span></p><h4><span>Vendor Overview</span></h4><p><span>Stellar Cyber provides a cross-layer security operations platform for enterprise SOCs, co-managed environments, MDR providers, and MSSPs. The product combines data collection, normalization, enrichment, native NDR, SIEM-like data handling, threat intelligence, case correlation, analyst workflow, AI-driven investigation, and response orchestration in a single operating environment.</span></p><p><span>Stellar Cyber is broader than a pure AI SOC point solution. Its historical Open XDR posture remains relevant to the architecture, but the current AI SOC fit comes from case-centered investigation, AI-driven triage, governed response, and auditability. Stellar Cyber&#8217;s customer base spans direct enterprise use and service-provider scale, including co-managed and fully outsourced delivery models.</span></p><h4><span>Product and Architecture</span></h4><p><span>The platform can be deployed as SaaS, on-premises, hybrid, or air-gapped, which makes it relevant for regulated, government, service-provider, and enterprise environments with different hosting requirements. The architecture begins with data collection through modular sensors, server sensors, log forwarding, API connectors, webhooks, and cloud storage inputs. Data is normalized, enriched with threat intelligence, placed into storage tiers, analyzed by detection pipelines, and correlated into cases.</span></p><p><span>The case is the primary work object. It carries evidence from intake through investigation, AI analysis, recommended actions, response workflow, and audit history. Stellar Cyber&#8217;s modular sensor is a key architectural element and can support functions such as deep packet inspection, IDS, malware analysis, vulnerability scanning, response actions, and log forwarding depending on configuration. The platform also integrates with endpoint, identity, vulnerability management, firewall, SaaS, cloud, and other sources.</span></p><p><span>Stellar Cyber does not provide a proprietary EDR and instead integrates with endpoint products such as CrowdStrike, SentinelOne, and Microsoft Defender. Action depth depends on configured connectors, permissions, deployment model, observables, and customer policy. The AI layer is multi-layered, using rules, machine learning, graph ML, LLM-supported case analysis, and task-specific AI agents. AI Case Analysis provides natural-language case summaries, while Alert Auto Triage / VSC performs deeper investigation of observables and produces verdicts with supporting findings.</span></p><h4><span>Market Context and Positioning</span></h4><p><span>Stellar Cyber receives an Emerging Player placement because its established Open XDR platform provides mature deployment, broad telemetry, cases, playbooks, and response reach, while its agentic decision layer and connector-level outcome verification remain early. Stellar Cyber occupies a position between SIEM/XDR, NDR, SOAR, and AI SOC categories. It is best evaluated as a broad security operations platform that includes AI SOC capabilities rather than as a narrowly scoped AI investigation assistant. The most relevant comparisons are SIEM platforms adding AI and automation, EDR/XDR platforms extending into cross-layer case management, SOAR products adding generative AI, MDR/MSSP platforms using AI to improve analyst capacity, and newer AI SOC point solutions.</span></p><p><span>Its differentiation is the combination of native NDR, SIEM-like data handling, graph correlation, AI triage, multi-tenancy, and case-to-action workflow in one platform. The service-provider route is important because MSSPs and MDR providers can use the platform to increase analyst capacity without linear headcount growth.</span></p><h4><span>Narrative Implication</span></h4><p><span>Stellar Cyber represents a platform-oriented approach to AI-driven security operations. The product starts with broad telemetry collection and correlation, then uses AI to summarize cases, investigate observables, explain entity relationships, recommend actions, and support analyst decisions.</span></p><p><span>The strongest publication framing is governed progression toward autonomy. Analysts validate AI verdicts, review findings and raw evidence, approve or execute actions, and feed overrides into institutional knowledge. Stellar Cyber&#8217;s strength is not narrow agent purity; it is the breadth of the operating platform and its ability to connect data, case, investigation, workflow, and service-provider delivery.</span></p><h3><strong><span>Radiant Security - Pioneer</span></strong></h3><h4><span>Vendor Overview</span></h4><p><span>Radiant Security is a pure-play AI SOC vendor focused on autonomous alert triage, AI-generated case intelligence, and human-governed response. Its strongest claim is broad alert coverage combined with accurate triage across both recurring and less familiar security signals. The platform is designed to handle common alert categories such as identity and email alongside less standardized signals from areas including WAF, DLP, IT, supply-chain, and external-threat sources.</span></p><p><span>Radiant differentiates through customer-specific Context Memory, generative triage that can construct investigation plans for unfamiliar alerts, persistent case management, integrated response actions, and native log management. These capabilities give the platform a broader operational role than an alert-summarization assistant, although the depth of response remains dependent on connected systems, permissions, and customer-defined authority.</span></p><p><span>Radiant&#8217;s current fit is strongest as a triage-to-case-to-governed-response platform. The product supports one-click actions and limited zero-click automation for approved scenarios. Where connected tools expose the necessary APIs and permissions, analysts can execute response actions directly from Radiant&#8217;s case environment. The platform records those actions in an audit trail, while reversibility depends on the underlying source system and action type. Broader context-aware autonomous response remains an area of product expansion rather than the default operating model today.</span></p><h4><span>Product and Architecture</span></h4><p><span>Radiant&#8217;s architecture has three main components: AI triage, integrated response actions, and log management. The triage pipeline classifies alerts, enriches them with endpoint, identity, threat-intelligence, and other relevant telemetry, constructs a triage plan, executes the required queries, and produces a malicious or benign conclusion. It can reuse plans for familiar alert types and generate new plans for unfamiliar signals.</span></p><p><span>The evidence model is a strength. Findings in the interface can be traced to the queries and evidence used to reach the conclusion, while cases serve as the durable operational work unit. Related alerts can be grouped automatically around shared users, devices, IP addresses, indicators, or other significant artifacts. The case view includes the summary, grouping anchors, verdict and confidence, recommended response actions, assignment, notes, and a full action history. Supported actions can be initiated directly from the case when the connected source system exposes the appropriate controls.</span></p><p><span>Integrations span endpoint, identity, email, cloud, network, SIEM, threat intelligence, ITSM, collaboration, custom API actions, and native log management. Response execution depends on active connectors, source-system APIs, and granted permissions. Radiant Log Manager can use customer-owned S3 buckets through a bring-your-own-bucket model, providing a lower-cost evidence store for AI-driven triage queries.</span></p><p><span>Radiant differs from traditional playbook-first SOAR by generating investigation plans and response recommendations from case context rather than requiring every scenario to be predefined. Execution remains governed by integrations, permissions, customer policy, and the authority assigned to the system. The platform can support one-click actions and limited zero-click automation, while higher-impact remediation depends on operational confidence and customer-defined controls.</span></p><h4><span>Market Context and Positioning</span></h4><p><span>Radiant Security receives a Pioneer placement because its architecture connects coherent investigation, case continuity, analyst feedback, and reversible one-click response, while zero-click governance and verified autonomous-response breadth remain developing. Radiant&#8217;s go-to-market is shaped around SOC insourcing rather than wholesale MSSP replacement. Many direct customers are organizations dissatisfied with previous MSSP or MDR outcomes and seeking greater context, broader alert coverage, and more consistent operations without adding headcount at the same rate. Radiant offers after-hours coverage as an add-on, but its primary positioning is to support an internally operated SOC rather than become a full-service 24/7 provider.</span></p><p><span>Radiant competes most naturally with AI SOC point solutions, MDR-modernization providers, and automation vendors adding AI. Its differentiators are alert-triage coverage, practical case management, evidence-linked AI reasoning, predictable pricing, integrated Log Manager capabilities, and a staged path from human-approved actions toward more automated response.</span></p><h4><span>Narrative Implication</span></h4><p><span>Radiant shows the AI SOC category moving from alert triage into case-level operational systems. Its strongest narrative is that AI can compress investigation, preserve evidence, group alerts into cases, and give customers a controlled way to determine how much response authority the system receives.</span></p><p><span>The product&#8217;s publication story is practical SOC insourcing. Radiant can help smaller teams increase investigative coverage and operational consistency without scaling analyst headcount at the same rate, while keeping response governed, visible, and bounded by customer-defined autonomy thresholds.</span></p><h3><strong><span>Intezer - Pioneer</span></strong></h3><h4><span>Vendor Overview</span></h4><p><span>Intezer is an AI SOC platform focused on autonomous alert triage, investigation, case management, detection engineering, and governed response across existing enterprise security stacks. The company has expanded from its roots in malware analysis, endpoint forensics, live-memory analysis, and reverse engineering into a broader SOC operating layer that works across SIEM, EDR, identity, cloud, email, network, and ITSM environments.</span></p><p><span>Intezer&#8217;s strongest differentiation is the combination of AI-led SOC automation with deep forensic analysis. Its genetic code and binary-similarity capabilities analyze assembly-level code fragments to identify relationships among unknown, modified, polymorphic, and previously observed malware. That evidence is combined with process trees, endpoint and network forensics, live-memory analysis, phishing analysis, threat intelligence, and MITRE ATT&amp;CK mapping to support verdict generation and escalation.</span></p><p><span>The platform is best suited to enterprises and MDR or MSSP providers with established SIEM and EDR investments, significant alert volumes, and a need to expand SOC coverage without replacing their core detection estate. It is also relevant to organizations that value predictable licensing, evidence retention, regional data tenancy, expert escalation, and approval-gated response for higher-impact actions.</span></p><h4><span>Product and Architecture</span></h4><p><span>Intezer operates as a cross-layer SOC control plane that ingests alerts, gathers evidence, groups related activity into cases, performs forensic investigation, assigns verdicts, and recommends or initiates response actions according to customer policy. The platform can work with telemetry held in SIEMs, data lakes, or both, allowing customers to retain existing detection investments while adding a common investigation and response layer.</span></p><p><span>The forensic engine is central to the architecture. Intezer uses its proprietary genetic-code analysis alongside endpoint, network, process-tree, memory, phishing, and threat-intelligence evidence to support investigation. LLMs contribute to analysis, but Intezer describes a compartmentalized design in which model outputs are separated by triage component so a single anomalous response does not directly determine the final verdict.</span></p><p><span>The integration model includes standard connectors, custom APIs, customer-built extensions, and an MCP server that exposes the Intezer engine to external AI platforms, agents, and analyst interfaces. Customers can also build custom agents for reporting, threat hunting, and environment-specific workflows. Detection-engineering services extend the platform through posture reviews, MITRE ATT&amp;CK gap analysis, ongoing rule assessment, and customer-owned detection content.</span></p><p><span>Intezer&#8217;s autonomy model centers on autonomous triage and investigation, with response authority governed by customer policy, action type, asset criticality, user privilege, and incident severity. The platform can support a spectrum from read-only recommendation through supervised execution, narrow automation, and broader automated response. Human escalation remains part of the operating model, supported by feedback mechanisms and access to forensic experts.</span></p><h4><span>Market Context and Positioning</span></h4><p><span>Intezer receives a Pioneer placement because its architecture connects deep forensic reasoning, cross-source investigation, and routine-case automation, while approvals, policy hierarchy, rollback, audit export, and broad outcome verification remain under-evidenced for Production Delivery. Intezer competes with AI SOC point solutions, MDR and MSSP automation platforms, AI-enabled SOAR vendors, and platform-native autonomy from SIEM, EDR, XDR, identity, and cloud-security providers. Its strongest positioning is where buyers value evidence-backed verdicts, low-severity alert coverage, malware and endpoint depth, and the ability to operate across heterogeneous security tooling.</span></p><p><span>Its commercial model is also a differentiator. Intezer describes pricing based on EDR license count rather than alert volume, tokens, agents, or consumption credits, with unlimited triage included. That model may be attractive to organizations with high alert volumes or those seeking to expand coverage gradually across multiple security domains without introducing usage-based constraints.</span></p><p><span>The strongest fit is an organization that already operates a SOC and has enough process maturity to define approval policies, automation thresholds, and escalation pathways. More mature teams may place greater value on MCP access, API extensibility, and customer-owned workflows, while resource-constrained organizations may rely more heavily on detection-engineering services, case grouping, and expert escalation. MDR and MSSP providers may benefit where multi-tenancy, alert scale, and consistent triage across customer environments are priorities.</span></p><h4><span>Narrative Implication</span></h4><p><span>Intezer reinforces the AI SOC market shift from alert summarization toward case-to-action continuity. Its category contribution is the combination of autonomous triage and investigation with forensic evidence designed to raise confidence before response actions are taken. This gives the platform a credible role as an operating layer across existing SOC infrastructure rather than as an isolated AI assistant.</span></p><p><span>The product appears broad across endpoint, malware, phishing, SIEM-connected alerts, detection engineering, case management, and customer-configured response. Buyers should validate the depth of required integrations, the approval model for high-impact identity and cloud actions, confirmation of response outcomes in source systems, rollback procedures, and the maturity of real-time organizational context in their environment.</span></p><h3><strong><span>SentinelOne - Emerging Player</span></strong></h3><p><span>SentinelOne is assessed in this profile only against the AI SOC capabilities available within its platform. Its placement does not reflect SentinelOne&#8217;s overall cybersecurity market position or the breadth and maturity of its broader portfolio.</span></p><h4><span>Vendor Overview</span></h4><p><span>SentinelOne is a platform-native security operations vendor with origins in endpoint protection and XDR. Its relevance to the AI SOC market comes from the Singularity Platform, which brings endpoint, cloud, identity, AI security, data, and security operations capabilities into a common operating layer. SentinelOne is not best understood as a pure-play AI SOC vendor. It is better understood as a large security platform attempting to make AI-assisted investigation, AI SIEM, automation, and response work from the same control plane.</span></p><p><span>The company&#8217;s AI SOC fit is strongest where the buyer already treats SentinelOne as a core security operations platform. In those environments, SentinelOne can connect investigation and response more directly than vendors that sit only above the stack. The platform has native control points in endpoint and adjacent identity, cloud, and workload security, and those control points give SentinelOne a credible path from detection and investigation into containment.</span></p><p><span>SentinelOne&#8217;s positioning reflects a broader market shift. AI SOC value is moving away from summarization alone and toward systems that assemble evidence, reason across security context, recommend or execute actions, and preserve proof of what happened. SentinelOne&#8217;s public platform messaging emphasizes a shared data foundation, one AI engine, one console, and real-time context across endpoint, AI SIEM, Purple AI, and Hyperautomation.</span></p><h4><span>Product and Architecture</span></h4><p><span>The AI SOC-relevant product set is centered on the Singularity Platform, Singularity AI SIEM, Purple AI, Hyperautomation, endpoint protection, cloud security, identity security, and emerging AI security capabilities. The architecture is platform-first. SentinelOne brings telemetry, detections, investigations, and response actions into a shared operating model rather than treating AI SOC as a separate assistant bolted onto an existing alert queue.</span></p><p><span>Purple AI is the most visible analyst-facing AI layer. It supports investigation, search, reasoning, and workflow acceleration across SentinelOne-native and integrated third-party security data. Singularity AI SIEM extends the platform into broader telemetry ingestion and analytics, while Hyperautomation provides the response and workflow layer across SentinelOne-native controls and third-party systems through integrations and APIs. Hyperautomation currently delivers broad deterministic workflow execution; more dynamic, reasoning-driven paths using LLM Actions and Dynamic Snippets remain in development.</span></p><p><span>SentinelOne&#8217;s control-plane advantage is also its architectural constraint. The product story is strongest when response actions run through native SentinelOne surfaces or well-integrated systems. In heterogeneous environments, the buyer still needs to understand which actions are native, which depend on third-party integrations, which require human approval, and how consistently the platform verifies closure after action. Those are normal deployment questions for any platform-native AI SOC approach, not signs that SentinelOne lacks relevance to the category.</span></p><p><span>SentinelOne has also expanded the platform through AI and data acquisitions. Prompt Security adds runtime visibility and protection for enterprise GenAI and agentic AI usage, including controls for sensitive data leakage and AI-specific threats. Observo AI, now offered as Singularity AI Data Pipelines, adds a native telemetry-management layer that filters, enriches, and normalizes security data before it enters AI SIEM or the Singularity Data Lake. These moves reinforce SentinelOne&#8217;s strategy to own more of the AI SOC stack: data intake, investigation, AI reasoning, response, and AI application security.</span></p><h4><span>Market Context and Positioning</span></h4><p><span>SentinelOne receives an Emerging Player placement because Singularity provides strong native response authority and proven production maturity, while unified incident cases, deeper reasoning-driven workflows, and end-to-end agentic continuity remain incomplete or on the roadmap. SentinelOne occupies the platform-native autonomy path in the AI SOC market. It competes less like a narrow autonomous investigation vendor and more like a security operations platform that can embed AI SOC capabilities across a large installed base. That gives the company a different buyer motion from pure-play AI SOC vendors. SentinelOne can appeal to teams that want to consolidate security operations around endpoint, XDR, AI SIEM, and automation rather than introduce a separate AI SOC control layer.</span></p><p><span>The strongest buyer fit is an enterprise that already relies on SentinelOne for endpoint or XDR and wants to expand into AI-assisted investigation, AI SIEM, and governed response without rebuilding the SOC architecture from scratch. For these buyers, SentinelOne&#8217;s value is continuity. The same platform that sees and controls a large part of the environment can increasingly assist with investigation and response. That can reduce handoffs, improve action speed, and make AI SOC adoption feel like an extension of current operations.</span></p><p><span>The fit requires a different evaluation for buyers committed to a mixed, best-of-breed stack. SentinelOne can ingest and normalize third-party telemetry, including through OCSF-aligned schemas, allowing Purple AI to investigate across a heterogeneous environment while Hyperautomation executes through integrated systems. Its differentiation remains anchored in the Singularity data and control foundation. For these buyers, the decision is not only about tool consolidation; it is also about how much telemetry, investigation context, and response workflow they are willing to consolidate onto SentinelOne&#8217;s platform.</span></p><p><span>SentinelOne also benefits from scale. The company has crossed the $1 billion annualized recurring revenue threshold, giving it a large customer base and commercial foundation for expanding AI SOC adoption. That scale matters because platform adoption, telemetry breadth, and customer trust shape how quickly autonomy can move from assisted investigation into governed response.</span></p><h4><span>Narrative Implication</span></h4><p><span>SentinelOne&#8217;s AI SOC narrative is that autonomous security operations will be easier to trust when AI is embedded inside the platform that already observes, investigates, and acts. The company does not need to argue that every SOC action should be handed to a standalone autonomous analyst. Its stronger argument is that response autonomy should grow from a security operations platform with native telemetry, native controls, AI-assisted investigation, and automation.</span></p><p><span>SentinelOne is one of the more credible platform-native candidates in the AI SOC market. Its strength is the ability to connect AI SOC capabilities to real control points, especially endpoint and related platform surfaces, while extending investigation and automation across third-party data and tools. Its constraint is that the current reasoning-to-action chain remains distributed across linked but separate records, and broader cross-stack autonomy depends on integration depth, governance design, and deployment maturity.</span></p><p><span>The implication for buyers is that SentinelOne supports more than a closed, native-only estate, but it does not operate as a neutral overlay. Its mixed-stack value comes from consolidating third-party telemetry and investigation context into Singularity, then extending response through Hyperautomation. The current platform is strongest where buyers want an increasingly converged data, investigation, and response foundation. A single unified incident case, deeper reasoning-driven workflows, and fuller agentic continuity remain important maturity markers rather than completed capabilities.</span></p><h3><strong><span>Qevlar - Pioneer</span></strong></h3><h4><span>Vendor Overview</span></h4><p><span>Qevlar AI is a pure-play AI SOC investigation and response platform for large enterprises and MSSP/MDR providers that want autonomous, repeatable case-building with governed containment. The company positions itself as an intelligence and investigation layer rather than a chat-first copilot, traditional SOAR clone, or narrow alert-triage assistant.</span></p><p><span>The product&#8217;s strongest claim is a deterministic, graph-based investigation engine that converts alerts into evidence graphs, explains how it reached a verdict, and then drives bounded actions across endpoint, identity, email, and other control planes. Qevlar&#8217;s buyer profile tends toward organizations with heterogeneous stacks, high alert volume, and a desire to amplify existing SIEM, XDR, and SOAR investments rather than replace them.</span></p><h4><span>Product and Architecture</span></h4><p><span>The product covered in this profile is Qevlar AI for SOC Teams. It is offered as an AI SOC investigation and response platform with packaged tiers spanning entry triage, L2-level investigation automation, advanced response, and proactive hunting. The platform autonomously investigates alerts, builds an evidence graph, reaches an explainable verdict, and recommends or executes next-step actions under policy. Deployment options include SaaS, bring-your-own-cloud on supported hyperscalers, and self-hosted or sovereign configurations for customers with data-residency and compliance requirements.</span></p><p><span>Qevlar&#8217;s architecture centers on a deterministic graph-based engine rather than an LLM-first copilot. Each investigation is modeled as a graph of observables, actions, evidence, and relationships. Qevlar combines deterministic tool and action selection with more adaptive reasoning for semantic interpretation, unfamiliar detections, and changing data models. LLMs can interpret context and synthesize findings, while executable tools and critical actions remain constrained by controlled workflows and customer policy. This boundary supports consistency, auditability, and resilience against prompt injection.</span></p><p><span>The platform is stack-agnostic and integrates across SIEM, EDR/XDR, identity, email and collaboration, ITSM, threat intelligence, SOAR, and custom APIs. A context module combines structured inputs such as VIP lists, trusted domains, and file hashes with unstructured organizational knowledge and context inferred through investigations and analyst feedback. Proposed context changes can be tested against historical investigations before they are promoted into production.</span></p><p><span>Response is governed and containment-oriented. Qevlar can move from investigation into response, with unattended automation best suited to low-risk or highly trusted use cases. Higher-impact containment remains better suited to approval-gated operation. Beyond individual alerts, Qevlar can correlate activity across sources and group related alerts into incident or campaign narratives spanning multiple users, timeframes, and security surfaces.</span></p><h4><span>Market Context and Positioning</span></h4><p><span>Qevlar receives a Pioneer placement because its graph-based reasoning, exposed evidence, persistent case construction, and bounded containment create strong Architectural Alignment, while consequential actions remain predominantly supervised and broader response delivery is still developing. Qevlar fits the AI SOC category as a detection and decision layer with response extensions. It spans autonomous investigation, multi-source evidence collection, case continuity, guardrailed action, and SOC performance insight. Its structured investigation history can also support detection-engineering recommendations, ingestion-gap analysis, and asset-risk context without positioning the platform as a full vulnerability or exposure-management system. Its go-to-market is both direct and MSSP-led, with a strong fit for providers operating across heterogeneous customer estates.</span></p><p><span>Competitive reference points include AI SOC point solutions, MDR modernization providers, SOAR and automation vendors adding AI, and platform-native autonomous response from endpoint, identity, SIEM, or cloud vendors. Qevlar&#8217;s differentiation is its graph/evidence architecture, traceability, governance claims, heterogeneous-stack fit, and intentional non-copilot posture.</span></p><h4><span>Narrative Implication</span></h4><p><span>Qevlar shows how the AI SOC category can move beyond recommendation text and chat interfaces into case-to-action continuity with strong governance. Its role is best understood as an autonomous security investigation and response system designed to turn alerts into evidence-backed decisions and bounded actions.</span></p><p><span>The clearest differentiator is persistent case construction. Qevlar preserves evidence, reconstructs activity across related alerts, applies context, and connects investigation to containment and targeted posture improvements. Its market relevance depends on whether customers want AI SOC as an independent investigation layer across heterogeneous security stacks rather than as a feature inside a single platform vendor&#8217;s control plane.</span></p><h3><strong><span>Dropzone AI - Pioneer</span></strong></h3><h4><span>Vendor Overview</span></h4><p><span>Dropzone is an AI-native SOC platform focused on agentic investigation, threat hunting, threat intelligence analysis, detection improvement, and governed response support. The product functions as an augmentation layer for security teams: human analysts retain responsibility for strategic direction and high-impact decisions, while specialized agents take on repeatable investigation, enrichment, hunting, and operational follow-through.</span></p><p><span>Dropzone&#8217;s strongest fit in the AI SOC market is the agentic SOC pattern. Multiple specialized agents work across SOC functions rather than limiting the product to alert summarization. The platform covers analyst, threat hunter, threat intelligence, detection engineering, incident response, and resilience workflows. Its customer posture spans direct enterprise use and MSSP/MDR environments.</span></p><h4><span>Product and Architecture</span></h4><p><span>Dropzone&#8217;s architecture is organized around specialized agents that operate across the existing security stack. Each agent replicates the techniques of expert human analysts. For example, the core AI SOC Analyst follows the OSCAR methodology: Obtain, Strategize, Collect, Analyze, and Report. Not bound by strict playbook rules, the system reasons through an investigation dynamically and adapts the investigation path as new evidence appears.</span></p><p><span>Transparency is central to the product architecture. The platform exposes the agent&#8217;s action graph, findings, raw API queries, SIEM queries, reasoning steps, and conclusions. This gives analysts a way to inspect how a conclusion was reached and turns the investigation record into a reviewable evidence trail.</span></p><p><span>Dropzone integrates with existing customer infrastructure rather than replacing the SIEM, EDR, ticketing, SOAR, or case-management layer. Customer-specific context can be ingested through APIs, entered manually, or learned from investigation feedback. The Context Graph and custom strategy features allow customers to encode environment-specific facts, exceptions, VIP accounts, known-safe configurations, and operational rules.</span></p><p><span>Response is governed rather than unrestricted. Dropzone supports response actions, notifications, and workflow-based response support, while high-impact remediation remains bounded by customer policy and analyst judgment. Native case-management demand is increasing, with many workflows continuing to rely on existing ticketing and case-management systems.</span></p><h4><span>Market Context and Positioning</span></h4><p><span>Dropzone AI receives a Pioneer placement because its multi-agent investigation model, evidence transparency, and contextual case progression align strongly with the AI SOC lifecycle, while unattended action breadth, risk policy, approval chains, retry behavior, and independent outcome verification remain developing. Dropzone sits in the AI SOC-native category, with particular strength around agentic investigation, evidence transparency, and role-based SOC augmentation. It is not a SIEM replacement, MDR provider, or traditional SOAR platform. Its market role is an agent layer that works across existing security investments and increases investigation, hunting, and response-preparation capacity.</span></p><p><span>Competitive comparisons include other AI SOC-first platforms, SOAR vendors adding generative AI, MDR/MSSP platforms using AI to increase analyst capacity, and SIEM/XDR vendors embedding AI into investigation workflows. Dropzone&#8217;s differentiation is its multi-agent operating model, visible investigation graph, OSCAR-based reasoning pattern, custom strategies, context memory, hunt-pack library, and support for SOC functions beyond alert triage.</span></p><h4><span>Narrative Implication</span></h4><p><span>Dropzone shows how the AI SOC category is moving from alert investigation into broader agent-led security operations work. The product&#8217;s strongest narrative is human-augmented agentic operations: agents take on structured investigation, evidence gathering, threat hunting, context application, and response support, while analysts retain judgment over trust, policy, and high-impact actions.</span></p><p><span>The result is a model of AI SOC that expands operational capacity without requiring buyers to replace the core security stack or surrender control over material response decisions.</span></p><h3><strong><span>D3 Security - Emerging Player</span></strong></h3><p><span>D3 Security is assessed in this profile only against its AI SOC capabilities available within its platform. Its placement does not reflect D3 Security&#8217;s overall cybersecurity market position or the breadth and maturity of its broader portfolio.</span></p><h4><span>Vendor Overview</span></h4><p><span>D3 Security is an established SOAR and automation platform vendor whose Morpheus platform combines AI-driven triage and investigation with native SOAR, case management, and governed response. Its go-to-market focus includes large enterprises and managed security service providers, with multi-tenant support and per-tenant controls supporting service-provider environments.</span></p><p><span>Morpheus gives D3 a SOAR-native path to AI SOC rather than operating as a standalone AI layer. The platform spans alert triage, investigation, decision support, response, case management, and audit on one system, while retaining a human-controlled and policy-governed response posture.</span></p><h4><span>Product and Architecture</span></h4><p><span>Morpheus is integrated into the D3 SOAR platform and runs on what D3 describes as a purpose-built Cybersecurity Triage Reasoning Graph. The architecture is designed to preserve security investigation logic independently of any single language model. Morpheus triages incoming alerts, gathers context, and assembles an incident workspace. Analysts can use natural-language adaptive tasking to launch broad or targeted investigations. Attack Path Discovery gathers evidence across connected security domains, maps affected entities and blast radius, and feeds a two-stage plan-and-build process that generates an incident-specific remediation playbook for analyst review before executable steps are created.</span></p><p><span>Morpheus exposes four configurable autonomy modes: Deterministic, AI-Assisted, AI-Led, and Autonomous. These modes can be set by workflow and tenant, allowing customers to vary approval requirements by action risk and operating environment. D3&#8217;s strongest current operating model remains deterministic or approval-gated execution. Broader autonomous operation is available on a more limited basis and should be evaluated by workflow, action type, and customer evidence.</span></p><p><span>The workflow begins with alert intake from SIEM, EDR, or other integrated tools. Morpheus performs triage and context gathering, collecting evidence, enrichment data, and relevant telemetry into an incident workspace with a case narrative, supporting artifacts, and recommended next steps. Analysts can inspect, edit, reject, pause, or approve the proposed plan. Approved actions execute through D3&#8217;s integrations across containment, identity, network, email, ticketing, and messaging where the customer has configured the required connectors, permissions, and approval policy. A durable incident case and unified audit trail preserve evidence, reasoning, approvals, integration calls, action outcomes, and closure history, although explicit policy-decision records and execution-identity attribution are less complete.</span></p><p><span>D3 highlights local knowledge injection as a differentiator. Morpheus can incorporate how a specific team handles incidents, including its tools, preferred steps, and established workflows, to align investigations and response plans with customer-specific practice. D3 also constrains agentic tasks through tool-scope limits, iteration caps, output validation, and approval gates.</span></p><h4><span>Market Context and Positioning</span></h4><p><span>D3 Security receives an Emerging Player placement because its SOAR foundation provides mature governance, integrations, case records, and auditability, while broad AI-led autonomous response and production proof for the newer Morpheus execution layer remain limited. D3&#8217;s primary positioning is a SOAR-native AI SOC platform that connects autonomous investigation to governed execution on a common case-management and audit foundation. The intended user is generally a Tier 2 or more senior analyst with enough experience to evaluate AI-suggested steps. Market fit is strongest for teams that value graduated autonomy, broad integration leverage, multi-tenant controls, and configurable oversight before consequential actions.</span></p><p><span>D3 competes with SOAR and automation platforms adding AI, AI SOC point solutions, and other vendors that connect investigation to response. Its differentiation is the combination of a model-independent reasoning architecture, native SOAR and case management, evidence-driven playbook generation, integration leverage, local knowledge injection, and multi-tenant support for service-provider environments.</span></p><h4><span>Narrative Implication</span></h4><p><span>D3 demonstrates a pragmatic, governed version of AI SOC. Many buyers are not ready to grant broad autonomous authority, especially for high-impact containment or identity actions. D3 addresses that constraint through graduated autonomy, evidence-driven playbook generation, and a shared case-to-action audit trail, while allowing customers to keep consequential execution approval-gated.</span></p><p><span>The strongest narrative is disciplined automation rather than unrestricted autonomy. The Reasoning Graph and Attack Path Discovery accelerate triage, investigation, and playbook construction, while D3&#8217;s SOAR, case-management, and integration foundation provides the governance and execution substrate for response at the buyer&#8217;s chosen autonomy level. The principal maturity question is how broadly customers are using the AI-Led and Autonomous modes beyond supervised, policy-gated workflows.</span></p><h2><strong><span>Critical Enablers: Upstream Architecture Behind AI SOC</span></strong></h2><p><span>The quality of automated response is bounded by the systems upstream of it. Endpoint, identity, cloud, network, email, application, and SaaS platforms determine what the AI SOC can see and what it can change. Endpoint isolation, token revocation, email quarantine, and cloud containment depend on reliable telemetry, safe write APIs, and correctly scoped credentials in the underlying tools.</span></p><p><span>Data fabric and ingest platforms determine whether the response system can reason across the environment from multiple signals. Collection, routing, normalization, enrichment, filtering, and cost-aware data movement affect the completeness and freshness of the case. Cleaner events and stronger entity context reduce avoidable uncertainty. Poor routing, inconsistent schemas, and missing history can make a sophisticated investigation engine reach the wrong conclusion quickly.</span></p><p><span>Storage, detection, and analytics platforms shape the evidence state before action begins. Correlation, entity resolution, anomaly detection, behavioral analysis, and case construction determine whether the response platform receives the right incident at the right confidence. These capabilities sit upstream of remediation authority and remain essential to response quality.</span></p><p><span>Control-plane design is equally important. Buyers should test whether integrations can distinguish read permissions from write permissions, enforce least privilege, report partial failure, support non-repetitive actions, and verify state after execution. AI SOC functions as the governing layer of an evidence and control chain, and the weakest dependency can limit the safety of the entire loop.</span></p><h3><strong><span>Vega - Post-SIEM Security Analytics Mesh</span></strong></h3><h4><span>Vendor Overview</span></h4><p><span>Vega is an upstream, AI-native detection, evidence, and security analytics vendor for AI SOC. Its center of gravity is not autonomous remediation in the narrow sense. The company is focused on the detection fabric and case-state foundation that makes higher-confidence action possible across fragmented security data. That distinction matters because automated response is not only a remediation market. It is also an evidence and detection quality market. Before a SOC can trust an AI system to recommend or execute a state-changing action, it needs a reliable way to detect relevant behavior, assemble the evidence, explain the case, and preserve the facts behind the decision.</span></p><p><span>Vega&#8217;s core product is the Security Analytics Mesh (SAM), a platform designed to federate analytics across heterogeneous security data sources without forcing all telemetry into one SIEM, data lake, or storage architecture. The platform is built for environments where relevant evidence lives across Splunk, Microsoft Sentinel, object storage, endpoint tools, identity systems, cloud logs, and other operational data stores. Vega abstracts that fragmentation so analysts, detection engineers, and AI agents can search, detect, correlate, and reason across data that would otherwise remain difficult to operationalize during an investigation.</span></p><p><span>This gives Vega a distinct role in AI SOC. It is best understood as a detection and decision-confidence layer. It helps the SOC determine what should be detected, whether the organization has the data required to detect it, what happened when a signal fires, why it matters, and whether the case is strong enough to act. In that sense, Vega supports the market&#8217;s move from alert handling to evidence-backed case work.</span></p><h4><span>Product and Architecture</span></h4><p><span>Vega&#8217;s architecture is anchored in federated security analytics and detection engineering. The platform connects to distributed telemetry sources and lets analysts query across them without needing to centralize every dataset first. This is especially relevant for modern SOCs because cost, data volume, schema variation, and retention strategy often leave important security evidence outside the primary SIEM. Vega&#8217;s premise is that the SOC should be able to use that evidence during detection, hunting, triage, and investigation even when it lives in different systems or storage tiers.</span></p><p><span>The detection engineering capability is a central part of the product. Vega is designed to let teams write detection logic once and apply it across relevant connected data sources. In the March demo, Vega demonstrated detections written against OCSF-normalized event types and fields rather than against a single vendor&#8217;s schema. A detection written for an EDR event type, for example, can apply across multiple EDR products when the connected tools report the required normalized fields. This allows detection logic to become more portable across tools and reduces the need to maintain separate versions of the same behavioral detection for each backend.</span></p><p><span>Vega also supports detection coverage and blind-spot analysis. The platform can show which detections apply to connected data sources, map coverage against techniques, and identify places where a technique is theoretically important but the organization lacks the right telemetry or active detection coverage. That shifts detection engineering from a content-library problem toward a detectability problem. The useful question is not only whether a detection exists, but whether the customer has the data, fields, and connected sources required to make that detection meaningful in its environment.</span></p><p><span>The platform&#8217;s natural language capabilities extend into both search and detection creation. Vega can translate analyst intent into KQL and distribute the query across connected environments. It can also use natural-language-to-KQL workflows to help generate detections, breaking down tactics and sub-techniques into candidate detection logic. This lowers the barrier for analysts who understand the behavior they want to find but do not want to hand-code each query variant across multiple backend systems.</span></p><p><span>Vega&#8217;s AI Triage Agent extends the platform from federated search and detection into autonomous investigation. The agent can generate investigative queries, correlate findings, build a timeline, identify relevant assets and observables, and produce a conclusion or verdict. The case output includes the data sources used, key findings, attack sequence, assets, IOCs, and enrichment context. This is the part of Vega that most directly aligns with the AI SOC thesis: the platform is not merely retrieving data or emitting alerts, it is turning detection output and fragmented evidence into a structured case state that can support downstream decisions.</span></p><p><span>Vega also has response adjacency. Actions such as blocking IPs or revoking identity sessions can be initiated from the same analytics framework, and customers can push recommended actions into existing SOAR platforms or other workflow systems. The product posture is hybrid rather than purely autonomous. High-impact or destructive actions remain subject to confirmation, while Vega&#8217;s stronger near-term role is to produce the detection, evidence package, and decision context that make those actions more defensible.</span></p><h4><span>Market Context and Positioning</span></h4><p><span>Vega sits upstream of many remediation-first AI SOC vendors. Its strongest alignment is with the part of the workflow where telemetry becomes detections, detections become case-ready evidence, and case-ready evidence becomes a decision that the SOC can defend. That makes it structurally different from vendors whose primary differentiation is governed execution, action approval, or closed-loop remediation. Vega is closer to the analytical substrate that those systems need before they can act responsibly.</span></p><p><span>This positioning is important because many SOCs do not fail at response only because they lack playbooks. They fail because their detection and evidence layers are fragmented. Detection logic is often tied to specific backends, telemetry lives in multiple storage locations, schemas drift, and analysts must reconstruct timelines across tools before they can decide whether an action is justified. In that environment, response automation can only go so far. A system that acts quickly on incomplete, non-portable, or poorly explained evidence increases operational risk. Vega&#8217;s value is that it improves the quality of the detection-to-case path before the action decision is made.</span></p><p><span>Vega&#8217;s cyber defense engineering story also connects to a broader market shift away from static detection-as-code as the end state. The next phase of detection engineering is not just writing better rules. It is building systems that understand what data exists, where it lives, which behaviors are detectable, how coverage changes across connected tools, and how detections should be promoted into investigation-ready cases. Vega&#8217;s federated model gives it a strong position in that shift because detection logic can be applied across the customer&#8217;s distributed data estate rather than being trapped inside one SIEM or one vendor&#8217;s control plane.</span></p><p><span>The buyer fit is strongest in mature, large enterprise, or data-fragmented SOCs where telemetry is distributed across multiple SIEMs, data lakes, object stores, endpoint platforms, cloud systems, and identity tools. These organizations often have enough data to detect and investigate more effectively, but they lack a practical way to access and operationalize it at investigation speed. Vega gives those teams a way to make more of their existing data estate useful without requiring full re-platforming into a single analytics backend.</span></p><p><span>Vega also fits organizations that want to improve AI SOC readiness before expanding autonomous action. The platform can support detection engineering, human-led investigation, AI-assisted triage, and downstream response recommendations while preserving human control over high-impact actions. That makes it relevant for enterprises that are not yet ready to grant broad autonomous response authority but still want to reduce the manual burden of detection development, evidence gathering, and case construction.</span></p><h4><span>Narrative Implication</span></h4><p><span>Vega shows that the AI SOC market should not be defined only by who executes the final remediation step. Action authority depends on detection authority and evidence authority. The vendors that earn the right to recommend or execute state-changing actions will need a reliable way to detect the right behaviors, assemble the right evidence, explain the case, and preserve case state across fragmented security data. Vega&#8217;s role is to make the SOC confident enough to act, even when the final action is executed through another control plane.</span></p><p><span>The company&#8217;s narrative strengthens the core AI SOC thesis by exposing a dependency that can otherwise be underweighted. Autonomous response is not trustworthy because a workflow can technically disable an account, block an IP, isolate a host, or create a ticket. It becomes trustworthy when the system can show why the signal mattered, which detection fired, what data supported the conclusion, what context changed the interpretation, and what uncertainty remains. Vega&#8217;s detection-first and evidence-first architecture aligns directly with that requirement.</span></p><p><span>Vega is therefore best positioned as a detection fabric and decision-confidence platform for AI SOC. It need not be the primary system of action in every customer environment, but it is a system of detection portability, investigation record, and case-state assembly. That role matters because the future SOC will need more than faster remediation. It will need higher-quality detections, stronger detectability awareness, better provenance, and a more durable link between fragmented telemetry and the actions taken in response.</span></p><h3><strong><span>Panther - Detection-as-Code and Security Data Foundation</span></strong></h3><h4><span>Vendor Overview</span></h4><p><span>Panther is a cloud native security operations platform centered on security data, detection-as-code, and AI-assisted detection engineering. Its relevance to AI SOC is primarily as an upstream architectural enabler: it improves the telemetry, detection logic, evidence quality, and investigation readiness on which reliable automated response depends. The platform combines centralized log ingestion, a customer-oriented data lakehouse, Python-based detection engineering, AI-assisted detection creation, AI triage, scheduled prompt-based hunting, and an emerging path toward agentic runbooks and approval workflows.</span></p><p><span>Panther has remediation capabilities through agentic runbooks, approval workflows, and response actions executed through connected tools. These capabilities allow the platform to move selected investigations into human-approved or policy-governed action. Its architectural center remains further upstream, where Panther collects and normalizes telemetry, operationalizes detection logic as code, supports recurring hunts, and exposes the evidence and reasoning behind alert triage. The maturity and breadth of response execution, rollback, approval-chain governance, source-state confirmation, case management, and broader autonomous remediation vary by release state and deployment scope.</span></p><h4><span>Product and Architecture</span></h4><p><span>Panther&#8217;s architecture centers on collecting security telemetry into a customer-oriented data lakehouse and applying detection logic, enrichment, AI triage, and response workflow on top of that evidence base. The platform can ingest from cloud and application security sources, Snowflake, Databricks, AWS Security Lake, and other log streams. Panther positions this architecture as a consolidation point for environments with disconnected SIEM, data, or log-management systems.</span></p><p><span>This architecture matters to automated response because weak telemetry, inconsistent schemas, and noisy or poorly maintained detections increase uncertainty before an action is selected. Panther&#8217;s role is to improve the evidence state that downstream analysts, agents, or response platforms use to determine whether an incident is actionable and what response is justified.</span></p><p><span>The AI Detection Builder lets users create or modify detections in natural language. The system generates Python detection code and presents a before-and-after view for human review, bridging plain-language analyst intent and Panther&#8217;s detection-as-code model. Panther also supports AI-assisted connector and schema creation for custom streaming sources, reducing some of the engineering burden associated with onboarding new telemetry.</span></p><p><span>AI Scheduled Prompts give customers a way to run recurring hunting questions over time. Self-tuning detection agents are intended to learn from false positives and suggest or apply detection changes. The AI Triage Agent investigates alerts, provides reasoning, follows runbook steps, and can recommend or initiate remediation through connected workflows while retaining human approval for sensitive actions. This gives Panther a credible path from detection and investigation into governed response, even though the product&#8217;s deepest capabilities remain in the data, detection, and evidence layers. Panther-hosted managed SaaS is available in supported US and EU regions, while bring-your-own data lake deployment provides more flexibility for customers with specific hosting needs.</span></p><h4><span>Market Context and Positioning</span></h4><p><span>Panther sits at the intersection of cloud native security data infrastructure, SIEM modernization, detection engineering, and AI-assisted SOC operations. Its primary market role is to provide the evidence and detection layer that supports investigation and downstream response, with agentic workflows extending the platform toward governed action.</span></p><p><span>Its competitive context includes cloud native SIEM and security data platforms, detection-engineering platforms, data-lake security analytics vendors, and broader SOC platforms adding AI-assisted investigation and response. Panther&#8217;s differentiation is the combination of a customer-oriented evidence layer, detection-as-code, AI-assisted detection creation, AI triage, open integration, MCP support, and engineering-native workflows.</span></p><p><span>The strongest buyer fit is a cloud-oriented or technology-forward SOC with substantial log sources and enough security engineering maturity to manage detections, schemas, data pipelines, approvals, and policy boundaries. Panther can support remediation through connected runbooks, approval workflows, and response actions, while its primary differentiation remains the programmable and inspectable evidence foundation that improves the quality of downstream investigation and action.</span></p><h4><span>Narrative Implication</span></h4><p><span>Panther shows that AI SOC readiness begins before investigation and remediation. Reliable action depends on whether the SOC can collect the right telemetry, normalize custom sources, maintain high-quality detections, preserve evidence, and continuously improve the signals that initiate the response loop. Panther&#8217;s architectural contribution is to make that upstream evidence and detection layer more programmable, inspectable, and adaptable.</span></p><p><span>The product&#8217;s publication story is a disciplined evolution from detection-as-code into AI-assisted security operations. Panther is strongest where the buyer values customer-controlled security data, detection quality, engineering-native workflows, and analyst-supervised automation. Its remediation capabilities extend that architecture into governed action, while its central contribution to AI SOC remains the evidence and detection foundation on which trustworthy response depends.</span></p><h2><strong><span>The Managed AI SOC: Service-Led Security Operations</span></strong></h2><p><span>The AI SOC market is developing through both customer-operated platforms and managed service models. Some organizations want to own the architecture and workflow, while others need the operational outcomes without the staff or maturity to achieve them alone.</span></p><p><span>TSRO is independent of whether the SOC is operated internally, through a managed service, or in a hybrid model. In many cases a managed AI SOC can execute portions of the response process, but the customer still defines which authorities are delegated, who is accountable, evidence standards, and outcome verification. The Trusted SOC describes the governance and reliability of action, not the sourcing model used to staff it.</span></p><p><span>Modern MDR providers can fill this role by combining AI-enabled investigation and response platforms with a human service layer. The provider operates the workflow from detection to response on the customer&#8217;s behalf. MDR providers should not be ranked directly against a software platform because the customer is purchasing a different operating model. A platform is evaluated by what the customer can configure, govern, and operate. An MDR provider is evaluated by the quality, speed, and transparency of the outcomes they deliver.</span></p><p><span>The service-led model is particularly relevant for cloud native companies without mature internal security operations, and organizations with persistent staffing constraints. Its effectiveness still depends on integration depth to customer systems, data and telemetry access, clear permissions, transparency, and the provider&#8217;s ability to adapt at scale across multiple tenant environments.</span></p><h3><strong><span>Daylight Security - Service-Led AI SOC</span></strong></h3><h4><span>Vendor Overview</span></h4><p><span>Daylight Security is a managed agentic security services provider that offers MDR, continuous threat hunting, and security data lake services with an AI-native investigation and response platform. The company is best understood as a service-led AI SOC operating model rather than a standalone software product for customer self-operation.</span></p><p><span>Daylight delivers managed agentic security services for organizations that need security operations outcomes without building or staffing a full internal SOC. The platform handles alert investigation, telemetry-driven detection, enrichment, verdict generation, response support, and case communication. Daylight&#8217;s security experts build and tune integrations, detections, and context repositories, and step in where cases require expert involvement.</span></p><h4><span>Product and Architecture</span></h4><p><span>Daylight&#8217;s architecture has three connected elements: a managed services layer, the investigation and response platform, and a customer-context/data layer. The platform can ingest alerts from third-party tools and can also operate on raw telemetry using Daylight-authored detections. Customers are not required to operate a SIEM for Daylight to investigate events, although the service can integrate with existing security tools.</span></p><p><span>The Daylight data lake functions as an investigation context repository. Standard MDR customers receive a defined retention window for investigation context, while longer retention and searchable historical data are provided through the separate agentic security data lake service. The platform is cloud-oriented, with regional isolation options for customers operating in different jurisdictions.</span></p><p><span>Daylight&#8217;s integration model is open and service-assisted. The platform can collect identity, endpoint, network, SASE/VPN, cloud, and organizational context to build a timeline and reach a verdict. Custom integration work is part of the service model, which allows Daylight to adapt investigations to customer-specific environments.</span></p><p><span>Response is policy-dependent. Non-destructive and lower-friction actions can be executed where customer policy allows, while higher-impact actions generally require customer permission or customer execution. The platform preserves case evidence, user verification, chat transcripts, Slack or Teams discussion context, and response/remediation audit information.</span></p><h4><span>Market Context and Positioning</span></h4><p><span>Daylight occupies the managed-service branch of the AI SOC market. It is not a like-for-like substitute for a customer-operated AI SOC platform where the buyer intends to own every operating step internally. Its most direct competitive frame is legacy MDR and MSSP providers, especially for customers seeking more tailored cloud coverage, AI-assisted investigation, and higher service quality.</span></p><p><span>The company fits two primary buyer groups: AI-native or high-growth cloud native organizations that need coverage without building an internal SOC, and mid-enterprise organizations that already use MDR but want better customization, speed, and outcome quality. This makes Daylight most relevant where the buyer wants an outcome-oriented security operations service with a platform-enabled investigation and response layer.</span></p><h4><span>Narrative Implication</span></h4><p><span>Daylight shows that the AI SOC market is not only developing as software for internal SOC teams. A credible branch of the category is emerging around service-led agentic security operations, where the AI platform and human service layer are designed together.</span></p><p><span>The completeness of Daylight&#8217;s model is service-led. Its value depends on the combined platform-plus-service design, customer-granted integrations and permissions, Daylight-operated detection and context work, and jointly agreed response policies. That makes Daylight an important example of AI SOC as an outcome delivery model, not just a software architecture.</span></p><h2><strong><span>Conclusion</span></strong></h2><p><a href="https://softwareanalyst.substack.com/p/ai-soc-technoscope-series-building"><span>Building the Trusted SOC</span></a><span> established that AI SOC maturity is determined at the level of individual response actions through the Trusted Security Response Operations model. This market analysis applies that operating model to the products buyers can evaluate today. It shows where vendors can support the Trusted SOC, how reliably they can deliver capability in production, and which operating environments strengthen their fit.</span></p><p><span>The two ranking dimensions reflect that connection. Architectural Alignment measures how completely a product preserves the trust model from evidence through verified outcome. Production Delivery measures whether the product has the integrations, governance, and controls to sustain the operation model in practice. Together they indicate how well each vendor can support an earned response authority.</span></p><p><span>The rankings also show why a Trusted SOC will take different forms across organizations. AI-native vendors can strengthen a heterogeneous environment, while SOAR-derived vendors can provide a mature deterministic foundation to a regulated environment. Broader security platforms can connect native telemetry and enforcement with a lower integration friction. Critical upstream enablers improve evidence and detection foundations required for trustworthy decisions, while managed providers can operate portions of this lifecycle for customers that need outcomes instead of self-management. Each path supplies different parts of the Trusted SOC and places different responsibilities on the customer.</span></p><p><span>The authority portfolio should guide vendor selection. Buyers should define which actions software may recommend, prepare, execute, or verify, then use this analysis and their own diligence to select the architecture and delivery model best suited to those responsibilities in their environment. A Trusted SOC develops as the organization expands that authority only when evidence, controlled execution, and verified outcomes support it.</span></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Software Analyst Cyber Research! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&quot;,&quot;text&quot;:&quot;Share Software Analyst Cyber Research&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share Software Analyst Cyber Research</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/p/ai-soc-technoscope-series-the-ai/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/p/ai-soc-technoscope-series-the-ai/comments"><span>Leave a comment</span></a></p><div class="community-chat" data-attrs="{&quot;url&quot;:&quot;https://open.substack.com/pub/softwareanalyst/chat?utm_source=chat_embed&quot;,&quot;subdomain&quot;:&quot;softwareanalyst&quot;,&quot;pub&quot;:{&quot;id&quot;:114363,&quot;name&quot;:&quot;Software Analyst Cyber Research&quot;,&quot;author_name&quot;:&quot;SACR&quot;,&quot;author_photo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!gmzz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1abfe3b-34cf-49c6-af16-c3961bb40c4f_512x512.jpeg&quot;}}" data-component-name="CommunityChatRenderPlaceholder"></div><p></p>]]></content:encoded></item><item><title><![CDATA[The Future of Digital Risk Protection (DRP) Is External Trust Operations ]]></title><description><![CDATA[Defending Digital Trust in the AI Era is Hard. Why Verified Closure Is Replacing Takedown as the Measure That Matters]]></description><link>https://softwareanalyst.substack.com/p/the-future-of-digital-risk-protection</link><guid isPermaLink="false">https://softwareanalyst.substack.com/p/the-future-of-digital-risk-protection</guid><dc:creator><![CDATA[Sean Sosnowski]]></dc:creator><pubDate>Wed, 29 Jul 2026 21:16:40 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!-L15!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98e63449-fe20-43fb-b03b-fd198b147688_1920x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h1><strong><span>Key Actionable Summary</span></strong></h1><p>SACR is introducing its first report on Digital Risk Protection. The wording around External Trust Operations as the term for this emerging operating model marks the point where Digital Risk Protection moves from artifact-level detection to campaign-level accountability. </p><p><span>Digital Risk Protection (DRP) programs were built to find visible abuse of known brands, domains, executives, products, and customer-facing assets. That mission remains necessary, but the external threat has outgrown an alert-and-takedown operating model. One campaign can now move across social accounts, cloned sites, fraudulent ads, messaging channels, synthetic personas, mobile apps, and payment or credential-harvesting flows. Each artifact may look like a separate case even when the same adversarial network connects them. AI increases the pace by making convincing content, localization, variation, and relaunches cheaper and easier to produce.</span></p><p><span>The category is resetting around a broader operating requirement: external trust operations, where the protected object expands beyond a domain, account, or listing to the business entity and the public trust relationships being exploited. The campaign becomes the unit of analysis, and the work from discovery and assessment through response, verification, and recurrence monitoring becomes one connected workflow measured by verified campaign closure.</span></p><h2><strong><span>Research Basis</span></strong></h2><p><span>This analysis combines current public threat reporting and vendor positioning with SACR&#8217;s ongoing research across digital risk protection, brand protection, threat intelligence, external attack surface management, fraud, narrative intelligence, and executive protection. Public sources establish the threat environment, SACR&#8217;s analysis defines the category and buyer implications, and Outtake examples show how one vendor is approaching the operating problem.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-L15!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98e63449-fe20-43fb-b03b-fd198b147688_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-L15!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98e63449-fe20-43fb-b03b-fd198b147688_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!-L15!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98e63449-fe20-43fb-b03b-fd198b147688_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!-L15!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98e63449-fe20-43fb-b03b-fd198b147688_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!-L15!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98e63449-fe20-43fb-b03b-fd198b147688_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-L15!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98e63449-fe20-43fb-b03b-fd198b147688_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/98e63449-fe20-43fb-b03b-fd198b147688_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1510488,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://softwareanalyst.substack.com/i/209022917?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98e63449-fe20-43fb-b03b-fd198b147688_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-L15!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98e63449-fe20-43fb-b03b-fd198b147688_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!-L15!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98e63449-fe20-43fb-b03b-fd198b147688_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!-L15!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98e63449-fe20-43fb-b03b-fd198b147688_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!-L15!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98e63449-fe20-43fb-b03b-fd198b147688_1920x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>The accompanying market map is a convergence map built from vendors&#8217; primary market motions and functional relevance to external trust operations. Placement identifies a contribution to the workflow without implying validation, parity, endorsement, or leadership.</span></p><div><hr></div><p></p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/p/the-future-of-digital-risk-protection?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading Software Analyst Cyber Research! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/p/the-future-of-digital-risk-protection?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/p/the-future-of-digital-risk-protection?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><div><hr></div><p>Classic DRP capabilities still matter, but the buyer&#8217;s question is whether the program can progress from isolated artifact detection to coordinated, evidence-backed closure. The lasting requirement is an operating model that connects external abuse to business context, brings the right internal owners into a shared response, and proves that the active threat pathway was closed.</p><p>CISOs should evaluate whether a platform and program can:</p><ol><li><p>Model the business entities and trust relationships that require protection, including brands, executives, employees, products, locations, subsidiaries, partners, domains, apps, official accounts, and customer-facing services.</p></li><li><p>Discover abuse beyond static watchlists, explain why a signal matters, and connect related accounts, content, infrastructure, channels, and monetization paths into a campaign.</p></li><li><p>Route evidence and response across security, fraud, legal, communications, brand, customer support, and executive protection without forcing each team to reconstruct the case.</p></li><li><p>Measure verified campaign closure, recurrence, unresolved infrastructure, analyst effort, and business harm. A completed takedown request is one response action, not proof that the threat has ended.</p></li></ol><p>Outtake sponsored this research and appears later as an illustrative product profile. SACR&#8217;s category definition and buyer framework apply across the market. Buyers should still validate production performance, integration depth, remediation success, recurrence reduction, and business impact rather than treating product direction as proof of outcomes.</p><p></p><div><hr></div><h1><strong><span>Why DRP Is Resetting</span></strong></h1><p><span>DRP became valuable because organizations lost control over how their brands, domains, executives, products, and customer-facing services appeared across the public internet. Attackers could register confusing domains, publish phishing pages, impersonate executives, clone applications, and misuse marketplaces faster than most teams could monitor manually. By bringing those assets into a repeatable monitoring, investigation, escalation, and takedown workflow, DRP gave enterprises a practical response to a rapidly expanding problem.</span></p><p><span>That mandate remains necessary, but a visible artifact rarely represents the full case. A fake executive account may lead to a cloned support page, moving victims into a messaging channel where a synthetic persona continues the conversation. It may also share infrastructure with fraudulent advertisements, lookalike domains, credential-harvesting pages, or payment accounts. What appears to be a collection of unrelated alerts can often be one coordinated operation, allowing a watchlist to find the entry point without revealing the full path to harm.</span></p><h2><strong><span>The Public Enterprise Is an Attack Surface</span></strong></h2><p><span>Security architecture usually begins with the internal enterprise: identities, endpoints, cloud services, SaaS applications, networks, and data. The organization&#8217;s public identity is different because it is distributed across platforms and intermediaries the enterprise does not control, including registrars, app stores, advertising networks, marketplaces, search engines, messaging services, review sites, and social networks.</span></p><p><span>The organization knows which identities, accounts, domains, applications, and support channels are legitimate, but customers, employees, investors, partners, and automated systems must often infer legitimacy from what they encounter. That asymmetry creates an external trust gap that attackers exploit with impersonation, synthetic media, manipulated narratives, and fraudulent infrastructure.</span></p><p><span>Enterprise AI agents now face the same problem as they retrieve web content, process email and documents, summarize public sources, and make recommendations from external information. Manipulated pages, fake entities, poisoned documents, and adversarial instructions can enter internal workflows through systems that trust public content. This does not turn DRP into a complete AI security category, but it raises the importance of external legitimacy as an input to automated decisions.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Puqg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7375bde2-cae9-43fc-bb70-ff49997d2707_1672x941.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Puqg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7375bde2-cae9-43fc-bb70-ff49997d2707_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!Puqg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7375bde2-cae9-43fc-bb70-ff49997d2707_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!Puqg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7375bde2-cae9-43fc-bb70-ff49997d2707_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!Puqg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7375bde2-cae9-43fc-bb70-ff49997d2707_1672x941.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Puqg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7375bde2-cae9-43fc-bb70-ff49997d2707_1672x941.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7375bde2-cae9-43fc-bb70-ff49997d2707_1672x941.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Puqg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7375bde2-cae9-43fc-bb70-ff49997d2707_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!Puqg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7375bde2-cae9-43fc-bb70-ff49997d2707_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!Puqg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7375bde2-cae9-43fc-bb70-ff49997d2707_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!Puqg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7375bde2-cae9-43fc-bb70-ff49997d2707_1672x941.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong><span>AI Changes the Economics and Tempo</span></strong></h2><p><span>AI changes the economics of deception by letting adversaries produce more convincing material, vary it across channels, and localize it for specific targets at far lower cost. Phishing copy, profile images, cloned voices, translated scripts, altered imagery, and fraudulent advertisements can be tested and revised quickly, increasing the pressure on manual review.</span></p><p><span>Current threat reporting reinforces this shift. The </span><a href="https://www.ncsc.gov.uk/report/impact-ai-cyber-threat-now-2027"><span>UK&#8217;s National Cyber Security Centre assessment</span></a><span> through 2027 concludes that AI will continue to improve reconnaissance, vulnerability research, social engineering, malware development, and the processing of stolen data. </span><a href="https://www.verizon.com/business/resources/reports/dbir/"><span>Verizon&#8217;s 2026 Data Breach Investigations Report</span></a><span> found that generative AI bolstered 15 percent of observed attack techniques and reported higher click rates for mobile phishing.</span></p><p><span>Together, these findings point to an acceleration of familiar attack methods rather than a separate class of external threat. Abuse will arrive in more forms and move across channels more quickly, leaving programs built around static lists and isolated alerts to validate fragments while the campaign continues elsewhere.</span></p><h2><strong><span>Crossing Ownership Boundaries</span></strong></h2><p><span>External trust threats cross organizational boundaries because each team encounters a different expression of the same campaign. Security may discover a fake domain while fraud sees customer losses; brand and legal teams may focus on an impersonating account and its takedown; communications, customer support, and executive protection may see reputational damage, victim reports, or a synthetic persona. Each signal creates a legitimate local task, but the campaign becomes visible only when those perspectives are connected.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!icMe!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6eb1769-0435-47e7-bece-a9f24810f6c6_1672x941.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!icMe!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6eb1769-0435-47e7-bece-a9f24810f6c6_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!icMe!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6eb1769-0435-47e7-bece-a9f24810f6c6_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!icMe!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6eb1769-0435-47e7-bece-a9f24810f6c6_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!icMe!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6eb1769-0435-47e7-bece-a9f24810f6c6_1672x941.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!icMe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6eb1769-0435-47e7-bece-a9f24810f6c6_1672x941.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d6eb1769-0435-47e7-bece-a9f24810f6c6_1672x941.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!icMe!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6eb1769-0435-47e7-bece-a9f24810f6c6_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!icMe!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6eb1769-0435-47e7-bece-a9f24810f6c6_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!icMe!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6eb1769-0435-47e7-bece-a9f24810f6c6_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!icMe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6eb1769-0435-47e7-bece-a9f24810f6c6_1672x941.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>This fragmented ownership allows for campaigns to persist through multiple remediation actions. Removing a malicious domain does not automatically trigger a takedown of the social account directing traffic to it. A shared case model can connect the entity under attack, related artifacts and infrastructure, required evidence, actions already taken, and the conditions that must be met before closure to the fragmented teams that are responsible for each individual step of the process.</span></p><h1><strong><span>Defining External Trust Operations</span></strong></h1><p><span>External Trust Operations is the operating model emerging within the DRP category reset. It connects business entities, campaign analysis, coordinated response, and verified closure so that external abuse can be managed as an operating problem rather than a collection of unrelated alerts.</span></p><p><span>The model gives DRP a clearer purpose: protect the public trust surface surrounding the organization&#8217;s brands, people, products, locations, subsidiaries, partners, customer-facing services, domains, apps, accounts, and narratives, while understanding how adversaries exploit the relationships between those entities and the people or systems that rely on them.</span></p><h2><strong><span>Protected Entities Give Context</span></strong></h2><p><span>Traditional DRP programs commonly begin with known assets such as brands, domains, executives, keywords, trademarks, and logos. A protected-entity model adds the operational context required to determine what is legitimate, why a signal matters, and how apparently different artifacts may relate to the same target.</span></p><ul><li><p><span>Products combine official names and imagery with SKUs, authorized sellers, marketplaces, regional availability, and known counterfeit patterns.</span></p></li><li><p><span>Executives combine aliases, verified accounts, public appearances, imagery, organizational relationships, and common impersonation scenarios.</span></p></li><li><p><span>Locations combine signage, geocoordinates, local listings, regional languages, and customer communications.</span></p></li></ul><p><span>This context helps a platform judge relevance and connect fragments that use different text, imagery, or infrastructure. A suspicious profile, cloned login page, advertisement, messaging channel, and payment destination may first become a coherent campaign through their relationship to the same executive, product, customer workflow, or brand.</span></p><h2><strong><span>Campaign as the Unit of Analysis</span></strong></h2><p><span>Artifact-level response remains necessary because teams still need to report accounts, remove pages, block domains, preserve screenshots, and escalate listings. The campaign view provides the context needed to determine whether those individual actions address the full threat or only one visible part of it.</span></p><p><span>By connecting domains, accounts, personas, and other artifacts, campaign analysis reveals behavior that individual nodes cannot show on their own. A low-reach account may justify monitoring in isolation, yet the same account can require an urgent cross-functional response when it is tied to a cloned support page, active advertising, victim reports, and a payment channel.</span></p><h2><strong><span>The Operating Sequence</span></strong></h2><p><span>The operating sequence connects six activities that are often split across tools and teams. Each stage should preserve enough context and evidence for the next stage to act without reconstructing the case.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-yJ5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F762a42fc-e58d-47d6-8df1-70cbac880c68_1672x941.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-yJ5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F762a42fc-e58d-47d6-8df1-70cbac880c68_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!-yJ5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F762a42fc-e58d-47d6-8df1-70cbac880c68_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!-yJ5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F762a42fc-e58d-47d6-8df1-70cbac880c68_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!-yJ5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F762a42fc-e58d-47d6-8df1-70cbac880c68_1672x941.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-yJ5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F762a42fc-e58d-47d6-8df1-70cbac880c68_1672x941.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/762a42fc-e58d-47d6-8df1-70cbac880c68_1672x941.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-yJ5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F762a42fc-e58d-47d6-8df1-70cbac880c68_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!-yJ5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F762a42fc-e58d-47d6-8df1-70cbac880c68_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!-yJ5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F762a42fc-e58d-47d6-8df1-70cbac880c68_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!-yJ5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F762a42fc-e58d-47d6-8df1-70cbac880c68_1672x941.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://www.interpol.int/en/Resources/INTERPOL-Spotlight/Spotlight-Issue-2-Cybercrime/Spotlight-Cybercrime-Innovation"><span>INTERPOL&#8217;s Spotlight Cybercrime analysis</span></a><span> illustrates the connection stage in practice. Its Project Rapid example shows investigators starting with a single suspicious URL and identifying related phishing sites through lookalike visuals, shared hosting, and similar creation dates. The example shows why discovery becomes more valuable when it expands an artifact into an evidence-backed campaign view.</span></p><h2><strong><span>Verified Campaign Closure</span></strong></h2><p><span>Takedown is one of several remediation actions, but isn&#8217;t a good measure of a campaign being closed effectively. A case reaches verified closure when the organization has enough evidence to conclude that the active threat pathway has been disrupted, related assets have been addressed or consciously accepted, the right owners have completed their actions, and recurrence monitoring is in place.</span></p><p><span>Closure must reflect the residual risk of each campaign. An account can disappear while its supporting domain network remains active, a phishing page can be removed after credentials have already been collected, and a counterfeit listing can return through another seller, so the closure standard must account for what remains capable of causing harm.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_QV7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b15a605-9930-4333-bfee-75d647521b62_1672x941.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_QV7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b15a605-9930-4333-bfee-75d647521b62_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!_QV7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b15a605-9930-4333-bfee-75d647521b62_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!_QV7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b15a605-9930-4333-bfee-75d647521b62_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!_QV7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b15a605-9930-4333-bfee-75d647521b62_1672x941.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_QV7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b15a605-9930-4333-bfee-75d647521b62_1672x941.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9b15a605-9930-4333-bfee-75d647521b62_1672x941.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!_QV7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b15a605-9930-4333-bfee-75d647521b62_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!_QV7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b15a605-9930-4333-bfee-75d647521b62_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!_QV7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b15a605-9930-4333-bfee-75d647521b62_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!_QV7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b15a605-9930-4333-bfee-75d647521b62_1672x941.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>Performance should be measured across the full campaign lifecycle rather than through alert volume or takedown throughput alone:</span></p><ul><li><p><span>Discovery and analysis: time to discover unknown abuse, determine relevance and severity, and connect related artifacts into a campaign.</span></p></li><li><p><span>Coordination and response: cross-functional handoff time, analyst effort per case, and time to remediation.</span></p></li><li><p><span>Outcomes and residual risk: percentage of cases with verified closure, recurrence after action, unresolved campaign infrastructure, and customer, employee, executive, or brand harm.</span></p></li></ul><p><span>Together, these measures show where the operating model breaks. Fast takedown can coexist with weak campaign understanding, high alert volume can conceal poor prioritization, and a low backlog can reflect cases that were closed before the threat was resolved.</span></p><h1><strong><span>Market Convergence and Category Boundaries</span></strong></h1><p><span>The next generation of DRP draws on markets that developed around different control points:</span></p><ul><li><p><span>External monitoring and removal: classic DRP and brand protection contribute monitoring, investigation, takedown, trademark protection, counterfeit detection, and marketplace response.</span></p></li><li><p><span>Adversary and infrastructure context: threat intelligence, open-source intelligence, and external attack surface management add underground-community, campaign, infrastructure, and unmanaged-asset context.</span></p></li><li><p><span>Harm, trust, and people-centered response: fraud, trust and safety, narrative intelligence, and executive protection contribute monetization, synthetic-media, reputational, impersonation, and customer-abuse perspectives.</span></p></li></ul><p><span>These categories overlap because an external campaign can move through several control points without fitting cleanly into any one of them. A platform may detect the infrastructure, another may understand the fraud path, and a third may own the relationship needed for removal or customer protection. Their value depends on whether the organization can connect those perspectives into one case.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!VZL8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faefeda36-04bf-410c-b89d-c3c62aaea99e_1672x941.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!VZL8!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faefeda36-04bf-410c-b89d-c3c62aaea99e_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!VZL8!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faefeda36-04bf-410c-b89d-c3c62aaea99e_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!VZL8!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faefeda36-04bf-410c-b89d-c3c62aaea99e_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!VZL8!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faefeda36-04bf-410c-b89d-c3c62aaea99e_1672x941.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!VZL8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faefeda36-04bf-410c-b89d-c3c62aaea99e_1672x941.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/aefeda36-04bf-410c-b89d-c3c62aaea99e_1672x941.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!VZL8!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faefeda36-04bf-410c-b89d-c3c62aaea99e_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!VZL8!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faefeda36-04bf-410c-b89d-c3c62aaea99e_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!VZL8!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faefeda36-04bf-410c-b89d-c3c62aaea99e_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!VZL8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faefeda36-04bf-410c-b89d-c3c62aaea99e_1672x941.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>The market is therefore unlikely to collapse into a single product class. Organizations will continue to use security operations, threat intelligence, fraud, legal, communications, brand protection, and customer-support systems, while DRP vendors compete to become the connective layer around the external entity and campaign. That layer should assemble context, preserve evidence, coordinate action, and maintain an outcome record across the systems teams already use.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!B83D!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbebbb89e-ac83-441f-8dc5-c294b4e41f75_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!B83D!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbebbb89e-ac83-441f-8dc5-c294b4e41f75_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!B83D!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbebbb89e-ac83-441f-8dc5-c294b4e41f75_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!B83D!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbebbb89e-ac83-441f-8dc5-c294b4e41f75_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!B83D!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbebbb89e-ac83-441f-8dc5-c294b4e41f75_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!B83D!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbebbb89e-ac83-441f-8dc5-c294b4e41f75_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bebbb89e-ac83-441f-8dc5-c294b4e41f75_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1510488,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://softwareanalyst.substack.com/i/209022917?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbebbb89e-ac83-441f-8dc5-c294b4e41f75_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!B83D!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbebbb89e-ac83-441f-8dc5-c294b4e41f75_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!B83D!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbebbb89e-ac83-441f-8dc5-c294b4e41f75_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!B83D!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbebbb89e-ac83-441f-8dc5-c294b4e41f75_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!B83D!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbebbb89e-ac83-441f-8dc5-c294b4e41f75_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>Vendors may appear in multiple containers because this is a convergence market. The important point is not to force every vendor into a single box; it is to show how different control points are converging around the same external trust problem.</span></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/subscribe?"><span>Subscribe now</span></a></p><h1><strong><span>How DRP Risks Show in Reality</span></strong></h1><p><span>Executive Impersonation and Fraud</span></p><p><span>Consider an executive impersonation campaign that develops into a customer fraud funnel. The organization first encounters a social account using a senior executive&#8217;s name and image, but the account is only the entry point: it directs users to a cloned customer-support page, moves the conversation into Telegram or WhatsApp, and ultimately sends victims toward a credential-harvesting or payment flow.</span></p><p><span>A conventional workflow may find the first account through a watchlist, keyword match, or customer report, confirm the impersonation, and submit a takedown through security, legal, or brand protection. Closing the case when that account is reported or removed leaves the rest of the campaign free to continue through related profiles, fraudulent advertisements, messaging channels, cloned pages, redirects, and payment infrastructure. The adversary can also relaunch under a different name or shift victims to another platform.</span></p><p><span>An external trust operations workflow begins with the executive and the connected customer journey. Authorized accounts, official domains, known imagery, login flows, brand relationships, and public context establish what legitimate activity looks like; profile similarity, linked domains, forms, calls to action, infrastructure, and customer reports help determine whether a new signal belongs to the threat.</span></p><p><span>The investigation then expands from the first account into a campaign view that connects profiles, advertisements, domains, sites, messaging channels, infrastructure, personas, and monetization paths while showing which relationships are supported by evidence. The organization can prioritize the campaign by reach, velocity, customer and credential risk, fraud exposure, executive impact, and recurrence, then route a shared evidence base to the teams responsible for technical response, fraud intervention, platform action, audience warning, and executive protection.</span></p><p><span>Closure requires evidence that the organization addressed more than the initial account. The case remains active until related assets have been assessed, the fraud path has been contained or consciously accepted, continued victim reports have been checked, and recurrence monitoring is in place.</span></p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/p/the-future-of-digital-risk-protection?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading Software Analyst Cyber Research! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/p/the-future-of-digital-risk-protection?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/p/the-future-of-digital-risk-protection?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><h1><strong><span>Outtake.ai</span></strong></h1><p><span>Outtake is a useful proof point for the shift toward entity-centric external trust defense. Its platform models protected entities, uses specialized agents to interpret multimodal external content, applies signal-based triage, maps related artifacts through threat graphs, coordinates platform-specific takedowns, and preserves context for response and recurrence analysis. The company is best understood as an illustrative solution profile rather than the sole definition of the category.</span></p><h2><strong><span>Why Outtake Fits the Thesis</span></strong></h2><p><span>Outtake organizes protection around brands, people, locations, and products, enriching each entity with relevant context such as authorized accounts, imagery, aliases, geocoordinates, and product information. This gives the platform richer context than static keyword lists alone.</span></p><p><span>This maps to the report&#8217;s broader argument that the protected object is the organization&#8217;s public trust surface, which Outtake describes as its Digital Trust Footprint. Entity context helps establish what is being impersonated, how the activity connects to a broader campaign, and who should act.</span></p><p><span>Search agents use entity descriptions, visual context, transcripts, text overlays, authorized social accounts, and web research to determine relevance. In one example, context-based filtering narrowed roughly 3,000 collected items to 389 relevant findings, illustrating how entity-aware reasoning reduces broad collection to an actionable set.</span></p><h2><strong><span>Agentic Search and Multimodal Analysis</span></strong></h2><p><span>Outtake&#8217;s search layer looks beyond pre-approved watchlists and keyword strings across traditional web domains, social media, deep web, dark web, and customer-reported mobile threats such as smishing. Specialized agents interpret text, images, video transcription, logos, visual similarity, and indirect references before connecting findings to protected entities. Content Wall then aggregates agent-found material into a controlled view, allowing analysts to review external content without visiting each source platform directly.</span></p><h2><strong><span>Intelligent Workflows and Remediation</span></strong></h2><p><span>Outtake turns raw findings into explainable triage and response paths using signals such as external links, Telegram references, profile-image similarity, login forms, MX records, credential-harvesting JavaScript, and infrastructure clues. These signals inform risk scoring and help route related artifacts to the appropriate owners while preserving them within a common case.</span></p><p><span>Flagged queues and takedown workflows support graduated automation, moving from manual review toward automated enforcement as the buyer gains confidence in precision. Buyers should still validate production performance, approval requirements, and how closure is verified after action.</span></p><h2><strong><span>ReconAgent and Campaign Graphing</span></strong></h2><p><span>ReconAgent is the clearest product example of the shift from artifact monitoring to adversarial network understanding. In one example, an investigation began with a single suspicious social media account and expanded into a graph of 27 nodes and 31 edges across various social accounts, communication channels and servers, as well as a dedicated website and live app.</span></p><p><span>The significance is the operating pattern: a single suspicious artifact becomes the starting point for mapping related accounts, communities, infrastructure, and monetization paths. This moves investigation beyond isolated takedowns and gives analysts a stronger basis for prioritization, evidence packaging, disruption, and recurrence monitoring.</span></p><h2><strong><span>Adaptive Learning and Persistent Trust Context</span></strong></h2><p><span>Analysts can label findings, edit learnings, and feed those decisions into future triage. An observer-agent concept can also recommend backfill when new learning would alter the classification of existing alerts. Outtake&#8217;s Digital Reservoir preserves the resulting entity context, suspicious variants, fraudulent assets, adversarial infrastructure, evidence, decisions, takedown outcomes, recurrence signals, and prior cases. Together, these capabilities support adaptive case quality and persistent external trust context.</span></p><h2><strong><span>Digital Trust Kill Chain, Provenance, and Intake</span></strong></h2><p><span>Outtake describes its </span><a href="https://go.outtake.ai/labs/digital-trust-kill-chain"><span>Digital Trust Kill Chain</span></a><span> as extending the MITRE ATT&amp;CK approach beyond traditional cyberattacks to map eight stages across four zones:</span></p><ol><li><p><span>Zone 1: Discovery</span></p><ol><li><p><strong><span>Reconnaissance:</span></strong><span> The attacker profiles an organization&#8217;s public attack surface before building the campaign.</span></p></li><li><p><strong><span>Infrastructure Setup: </span></strong><span>The attacker creates and stages the assets needed to support the operation, including fake domains, applications, and accounts.</span></p></li></ol></li><li><p><span>Zone 2: Exposure</span></p><ol><li><p><strong><span>Trust Exploitation:</span></strong><span> The staged infrastructure is made credible through brand impersonation, fake endorsements, and fraudulent use of trademarks, logos, and other recognizable signals.</span></p></li><li><p><strong><span>Target Engagement:</span></strong><span> The attacker initiates targeted contact with the intended victims through phishing, social media, messaging platforms, and malicious advertising.</span></p></li></ol></li><li><p><span>Zone 3: Compromise</span></p><ol><li><p><strong><span>Engagement Capture:</span></strong><span> The initial engagement becomes a controlled interaction between the victim and the staged malicious infrastructure.</span></p></li><li><p><strong><span>Value Transfer:</span></strong><span> The attacker leverages the controlled interaction to gain value through direct financial transaction, account takeover or compromise, or data exfiltration.</span></p></li></ol></li><li><p><span>Zone 4: Harm</span></p><ol><li><p><strong><span>Impact and Fraud:</span></strong><span> The attacker&#8217;s operation produces a business or human impact, including consumer scams, reputation damage, data exposure, or risk to physical operations.</span></p></li><li><p><strong><span>Monetization: </span></strong><span>The attacker converts and launders the operational proceeds into financial return.</span></p></li></ol></li></ol><p><span>The analytical value that the Digital Trust Kill Chain brings is that it connects what can initially appear as separate artifacts into a progressing operation. Outtake also emphasizes that intervention becomes more expensive as the campaign moves from the Discovery and Exposure zones to Compromise and Harm. Buyers should treat Outtake&#8217;s Digital Trust Kill Chain as an effective vendor-developed model for evaluating campaign maturity and response coverage.</span></p><p><span>Outtake&#8217;s Digital Trust Kill Chain framework, modeled after the MITRE ATT&amp;CK framework, includes stages such as reconnaissance, infrastructure setup, trust exploitation, target engagement, credential capture, account takeover, impact and fraud, and monetization. This is useful as a vendor-developed framework because it shows how external trust attacks can be understood as multi-stage campaigns rather than isolated artifacts. Buyers should treat it as one lens for evaluating campaign maturity, not as the only methodology for the category.</span></p><p><span>Actor Tracing connects related activity, infrastructure reuse, and other actor context to support executive protection, adversary dossiers, remediation, and recurrence monitoring. Buyers should distinguish this form of provenance and adversarial-network analysis from definitive attribution, which remains difficult.</span></p><p><span>Outtake Intake structures customer- or user-reported scams, impersonation, smishing, and suspicious external activity into intelligence, alerts, and takedown workflows. This gives organizations another early-signal path for detecting and responding to external trust abuse.</span></p><h2><strong><span>Integrations and actionability</span></strong></h2><p><span>Outtake uses an open API model to move digital trust context into systems such as Microsoft Sentinel, ServiceNow, Jira, and OpenCTI. This supports SOC escalation, threat intelligence, workflow management, legal review, fraud investigation, and operational response without creating another disconnected queue. Buyers should distinguish customer-deployed integrations from directional or roadmap support.</span></p><h2><strong><span>Analytical assessment</span></strong></h2><p><span>Outtake is compelling because it aligns with the category&#8217;s most important shifts: from keywords to entities, from single alerts to threat graphs, from monitoring to investigation, from takedown to remediation workflows, from static configuration to adaptive context, and from brand-only protection to broader external trust defense.</span></p><p><span>Outtake&#8217;s category-shaping terms are useful, but the category should not become dependent on one vendor&#8217;s language. Evidence is the second risk. Product examples show capability direction, while claims about reduced triage time, takedown success, recurrence reduction, or business harm reduction still require customer evidence, anonymized case studies, or measurable before-and-after data. Scope is the third risk. Outtake&#8217;s model touches DRP, threat intelligence, executive protection, fraud, brand protection, narrative intelligence, and digital trust. That breadth is strategically interesting, but buyers should not assume that one platform replaces every adjacent category. The stronger framing is that Next-Gen DRP complements existing tools by connecting external trust signals around business entities and response workflows.</span></p><h1><strong><span>Buyer Scenario: Executive Impersonation Fraud Funnel</span></strong></h1><p><span>A practical buyer scenario helps make the category shift concrete. Imagine an executive-impersonation campaign that turns into a customer fraud funnel. The organization first sees a suspicious social account using a senior executive&#8217;s name and image. The account links to a cloned customer-support page, pushes users toward a Telegram or WhatsApp channel, and redirects victims into a credential-harvesting or payment-redirection flow.</span></p><p><span>A traditional DRP workflow may find the visible artifact through a watchlist, customer report, or keyword match. An analyst validates that the account, page, or domain abuses the brand or executive identity. Legal, brand protection, or security submits a takedown request. The case may be treated as closed when the artifact is removed or reported. The problem is that related social accounts, messaging channels, fraudulent ads, redirect paths, cloned pages, and monetization infrastructure may remain active or reappear later.</span></p><p><span>A Next-Gen DRP workflow starts with the protected entity. The platform understands the executive, the associated brand, the customer login flow, authorized accounts, domains, products, and known public context. It can detect suspicious social profiles, domains, images, videos, ads, or messaging channels even when the attacker avoids exact keywords. It uses signals such as profile-image similarity, external links, login forms, Telegram or WhatsApp calls to action, infrastructure reuse, and content similarity to assess relevance and severity.</span></p><p><span>The platform then connects the campaign. It links the fake profile, cloned page, messaging channel, domain, ad, infrastructure, and monetization path into a single case or graph. It prioritizes the case against customer harm, credential-harvesting risk, fraud exposure, executive exposure, reach, velocity, and recurrence. It routes evidence to security, fraud, legal, communications, executive protection, customer support, and external platforms based on each team&#8217;s role. It verifies whether visible artifacts were removed or contained, whether related infrastructure remains active, and whether recurrence appears after takedown. It also learns from the case by using analyst feedback, takedown outcomes, recurrence patterns, and entity context to improve future triage.</span></p><h1><strong><span>Buyer Action Plan: First 90 Days</span></strong></h1><p><span>A useful evaluation begins with the organization&#8217;s external trust problem, tests vendors against realistic campaigns, and moves a limited set of high-value use cases into production. The first 90 days should build evidence progressively rather than treating a feature demonstration as proof of operating performance.</span></p><h2><strong><span>First 30 Days: Define the External Trust Baseline</span></strong></h2><p><span>The first month should establish what the organization is protecting, how work moves today, and which measures will show whether the program improves.</span></p><ul><li><p><span>Define the highest-priority entities and the context required to protect them, including aliases, imagery, official accounts, domains, geographies, business relationships, customer journeys, and common abuse patterns.</span></p></li><li><p><span>Map discovery, investigation, escalation, takedown, verification, and recurrence monitoring across security, fraud, legal, brand, communications, customer support, and executive protection. Identify where cases stall, split into duplicate work, or close without verification.</span></p></li><li><p><span>Identify the systems that need external trust context and establish baseline measures for alert volume, analyst effort, severity decisions, campaign connection, handoff time, remediation, recurrence, and premature closure.</span></p></li></ul><h2><strong><span>Within 60 Days: Test Discovery, Reasoning, and Campaign Connection</span></strong></h2><p><span>The second month should test whether the platform can move from isolated signals to an explainable campaign view under realistic operating conditions.</span></p><ul><li><p><span>Run current or representative scenarios in which adversaries avoid exact keywords, rely on images or video, use multilingual content, change platforms, or separate the initial lure from the eventual fraud or credential path.</span></p></li><li><p><span>Require the platform to explain relevance and campaign connections through inspectable entity context, content, infrastructure, relationships, and evidence. The campaign view should distinguish supported relationships from weak or inferred links.</span></p></li><li><p><span>Confirm that evidence, analyst decisions, indicators, screenshots, infrastructure details, and action history can move into each owner&#8217;s systems. Validate deployed integrations, remediation approvals, and the boundary between observable actor context and unsupported attribution.</span></p></li></ul><h2><strong><span>Within 90 Days: Operationalize Remediation and Verified Closure</span></strong></h2><p><span>The final month should place a bounded workflow into production and test whether the organization can prove that its actions changed the active threat.</span></p><ul><li><p><span>Launch a limited production workflow around a small set of high-priority entities and abuse scenarios, with clear response ownership, evidence requirements, approval gates, and closure conditions.</span></p></li><li><p><span>Measure discovery, severity decisions, campaign connection, handoff time, analyst effort, remediation, recurrence, unresolved infrastructure, and verified closure against the baseline established in the first month.</span></p></li><li><p><span>Reopen apparently closed cases to check for surviving assets, platform migration, continued victim reports, or new infrastructure. Use the results to improve entity context, workflow rules, recurrence monitoring, and recurring governance.</span></p></li></ul><h1><strong><span>Market Implications</span></strong></h1><p><span>Source coverage will remain part of DRP buying decisions, but it will carry less weight on its own as campaigns become more connected and operationally complex. Buyers will increasingly assess whether a platform can model protected entities, discover unknown abuse, interpret multimodal content, connect campaigns, explain prioritization, preserve evidence, coordinate workflows, support remediation, and monitor recurrence.</span></p><p><span>Competitive pressure will come from several vendor lineages. Established DRP and brand-protection providers bring collection breadth, takedown experience, and mature customer workflows; threat-intelligence and external-attack-surface vendors contribute infrastructure and adversary context; fraud and trust-and-safety platforms understand customer abuse and monetization; and newer AI-native vendors can make search, context assembly, and investigation more adaptive. Buyers should judge the combined operating outcome, using vendor origin as context rather than as a proxy for capability.</span></p><p><span>Category boundaries will continue to blur as vendors use terms such as digital risk, digital trust, external threat intelligence, brand protection, fraud intelligence, executive protection, and AI-native DRP for overlapping functions. Clear operational requirements will matter more than the label attached to the product.</span></p><p><span>The longer-term direction is Digital Trust Operations, an environment that maintains reliable context about the organization&#8217;s public entities, understands threats against the trust relationships around them, and coordinates responses across security and business teams. DRP is an important route into that future because it already owns many of the external signals and remediation relationships, but the market will earn the expansion only by showing measurable reductions in analyst effort, time to campaign understanding, recurrence, and business harm.</span></p><h1><strong><span>Conclusion</span></strong></h1><p><span>The DRP category reset is an operating-model change. Organizations still need to find fake domains, phishing pages, impersonating accounts, leaked credentials, counterfeit listings, fraudulent apps, and other external abuse. They also need to understand how those artifacts connect, which business entity and trust relationship are under attack, who must respond, and whether the campaign remains active after action.</span></p><p><span>External trust operations provides that structure. It organizes the program around protected entities, campaign analysis, coordinated response, evidence continuity, and verified closure. The model also gives CISOs a more useful way to evaluate vendors because it connects technical capability to operational performance and business harm.</span></p><p><span>A DRP program is moving in this direction when it can discover unknown abuse, explain why it matters, map the wider campaign, route action with the required evidence, and prove that the active threat pathway has been closed. If those steps still depend on manual reconstruction across disconnected tools and teams, the organization has an external trust operations gap. The strongest vendors will help the organization close external trust threats faster, with better context, less coordination burden, and stronger evidence that the risk is actually resolved.</span></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Software Analyst Cyber Research! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/p/the-future-of-digital-risk-protection/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/p/the-future-of-digital-risk-protection/comments"><span>Leave a comment</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/p/the-future-of-digital-risk-protection?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/p/the-future-of-digital-risk-protection?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div class="community-chat" data-attrs="{&quot;url&quot;:&quot;https://open.substack.com/pub/softwareanalyst/chat?utm_source=chat_embed&quot;,&quot;subdomain&quot;:&quot;softwareanalyst&quot;,&quot;pub&quot;:{&quot;id&quot;:114363,&quot;name&quot;:&quot;Software Analyst Cyber Research&quot;,&quot;author_name&quot;:&quot;SACR&quot;,&quot;author_photo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!gmzz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1abfe3b-34cf-49c6-af16-c3961bb40c4f_512x512.jpeg&quot;}}" data-component-name="CommunityChatRenderPlaceholder"></div><p></p>]]></content:encoded></item><item><title><![CDATA[AI SOC Technoscope Series: Building the Trusted SOC (Part 1)]]></title><description><![CDATA[The Operating Model for Transforming AI SOC into the Trusted SOC]]></description><link>https://softwareanalyst.substack.com/p/ai-soc-technoscope-series-building</link><guid isPermaLink="false">https://softwareanalyst.substack.com/p/ai-soc-technoscope-series-building</guid><dc:creator><![CDATA[Sean Sosnowski]]></dc:creator><pubDate>Mon, 27 Jul 2026 20:06:43 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Qd_E!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03e4105a-a054-41be-bd64-ad81af18a04d_1920x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2><strong><span>Key Actionable Summary</span></strong></h2><p><span>If you lead a security operations function today, you already know the feeling this report starts from. The market is loud, crowded, and hard to tell apart. Triage that felt novel eighteen months ago now ships inside almost every SIEM, EDR, XDR, and SOAR product you already own. New logos arrive every week. The acronyms multiply faster than anyone standardizes them. And underneath the noise sits a harder problem that the noise is hiding: your team can now understand an incident faster than ever, and still cannot act on it any faster than before.</span></p><p><span>We call this the </span><strong><span>action gap</span></strong><span>, the distance between a validated incident and a safe, verified, state-changing response an organization is willing to stand behind. The first wave of AI in the SOC compressed investigation. It did very little for the part that actually changes risk, which is response. Knowing the threat exists is only half the battle.</span></p><p><span>Security practitioners and vendors alike have tried to address the action gap in their own ways, but there hasn&#8217;t been a model that can be applied to any environment or any level of maturity to let practitioners close that gap. That&#8217;s why we&#8217;re introducing </span><strong><span>Trusted Security Response Operations (TSRO): </span></strong><span>the operating model through which a security team grants software bounded authority to recommend, prepare, execute, and verify specific response actions, under explicit requirements for evidence, policy, credentials, scope, and accountability.</span></p><p></p><div><hr></div><h2><strong>Building on SACR&#8217;s AI SOC Research</strong></h2><p>We developed this report as a continuation of our coverage of the AI SOC market. <a href="https://softwareanalyst.substack.com/p/revolutionizing-secuity-operations">Revolutionizing Security Operations: The Path Toward AI-Augmented SOCs</a> explored how AI and agentic systems were entering investigation and analyst workflows, while <a href="https://softwareanalyst.substack.com/p/sacr-ai-soc-market-landscape-for">SACR AI SOC Market Landscape For 2025</a> mapped the expanding vendor landscape as the category took shape. This report builds on that foundation by defining the Trusted Security Response Operations model and the Trusted SOC to help CISOs and security leaders move from faster investigation to trusted, governed response.</p><h3>AISOC Market Map</h3><p>These reports reflect extensive primary and secondary research over the past several months: structured interviews with 20 security leaders and practitioners, briefings and live demonstrations with 23 vendors, and targeted surveys across the market. Peer trackers such as <a href="https://secops-unpacked.ai/research/ai-soc-vendors">SecOps Unpacked</a> now map close to 140 vendors touching this space. SACR assesses more than 60 of these as pure-play AI SOC vendors. Our market analysis analyzes a focused set of 18 platforms in depth.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Qd_E!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03e4105a-a054-41be-bd64-ad81af18a04d_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Qd_E!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03e4105a-a054-41be-bd64-ad81af18a04d_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!Qd_E!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03e4105a-a054-41be-bd64-ad81af18a04d_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!Qd_E!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03e4105a-a054-41be-bd64-ad81af18a04d_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!Qd_E!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03e4105a-a054-41be-bd64-ad81af18a04d_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Qd_E!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03e4105a-a054-41be-bd64-ad81af18a04d_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/03e4105a-a054-41be-bd64-ad81af18a04d_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:450988,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://softwareanalyst.substack.com/i/208711341?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03e4105a-a054-41be-bd64-ad81af18a04d_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Qd_E!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03e4105a-a054-41be-bd64-ad81af18a04d_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!Qd_E!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03e4105a-a054-41be-bd64-ad81af18a04d_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!Qd_E!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03e4105a-a054-41be-bd64-ad81af18a04d_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!Qd_E!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03e4105a-a054-41be-bd64-ad81af18a04d_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&quot;,&quot;text&quot;:&quot;Share Software Analyst Cyber Research&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share Software Analyst Cyber Research</span></a></p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Software Analyst Cyber Research! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h3><strong><span>How to Use This Report</span></strong></h3><ul><li><p><span>This Part 1 focuses on building the Trusted SOC, defines the problems faced today, establishes the CISO operating model for addressing them, and explains our rationale behind it.</span></p></li><li><p>Part 2 of our report focuses on vendor market categorizations and market rankings. <span>The accompanying market analysis applies the model to reality, ranking a focused set of vendors across the three operating environments we see the most:</span></p><ul><li><p><span>A mature regulated SIEM-centric enterprise SOC where the SIEM remains the system of record.</span></p></li><li><p><span>A Hybrid mid-market SOC with a leaner team operating across a mixed SIEM and data-lake stack.</span></p></li><li><p><span>An engineering led cloud native data lake SOC that prioritizes direct data access and lightweight administration.</span></p></li></ul></li></ul><div><hr></div><h3>Trusted Security Response Operations (TSRO)</h3><p>We talked about the Trusted Security Response Operations (TSRO) earlier in our report. Using the TSRO model, practitioners will be able to achieve the outcome of a Trusted Security Operations Center (SOC). A Trusted SOC is one that has earned the authority to take specific actions through demonstrated decision quality, controlled execution, and verified outcomes.</p><p>The single most important reframe in this report is this. You are not making one decision about whether to trust AI in your SOC. You are making a portfolio of narrow delegation decisions, one action at a time, each of which can be granted, expanded, narrowed, or withdrawn on evidence. That is the difference between a marketing question, &#8220;Can we trust AI?&#8221; and an operating question you can actually govern: &#8220;Which action, under whose authority, based on what evidence, and verified how?&#8221;</p><ul><li><p><strong>What changed.</strong> AI improved triage, investigation, summarization, and enrichment to the point where those capabilities no longer differentiate a platform. Trust in automated response is now the binding constraint on adoption, and therefore on the return you get from any AI SOC purchase.</p></li><li><p><strong>Category definition.</strong> A Trusted SOC is not a product you buy or a badge a vendor wears. It is a dynamic description of a SOC that has earned action-specific authority through evidence, controlled execution, and verified performance.</p></li><li><p><strong>Buyer takeaway.</strong> Treat the Trusted SOC as the outcome of governed delegation, not a feature list. Require every vendor to show, per action, what the system can recommend, prepare, and execute today, how that authority is constrained, and how the outcome is verified with proof after execution. Discount any answer given at the level of the whole platform.</p></li><li><p><strong>Market prediction.</strong> SACR expects the Trusted SOC to become the North Star operating outcome through which the modern AI SOC earns the authority to act. As the market consolidates around platforms, the winning question shifts from how much a system can automate to how much authority it can be trusted to hold and prove.</p></li></ul><p></p><div><hr></div><h2><strong><span>What The Market In 2026 Tells Us</span></strong></h2><p><span>It&#8217;s important for us to start with the reality that security leaders are facing today, because our TSRO model and the Trusted SOC outcome only earn their keep when they address the problems people face today. Five recurring pressure points came up in nearly every conversation we had:</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rkDF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5daaa54-4fd0-4b5a-923d-9f66a305aff2_1672x941.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rkDF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5daaa54-4fd0-4b5a-923d-9f66a305aff2_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!rkDF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5daaa54-4fd0-4b5a-923d-9f66a305aff2_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!rkDF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5daaa54-4fd0-4b5a-923d-9f66a305aff2_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!rkDF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5daaa54-4fd0-4b5a-923d-9f66a305aff2_1672x941.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rkDF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5daaa54-4fd0-4b5a-923d-9f66a305aff2_1672x941.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d5daaa54-4fd0-4b5a-923d-9f66a305aff2_1672x941.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!rkDF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5daaa54-4fd0-4b5a-923d-9f66a305aff2_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!rkDF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5daaa54-4fd0-4b5a-923d-9f66a305aff2_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!rkDF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5daaa54-4fd0-4b5a-923d-9f66a305aff2_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!rkDF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5daaa54-4fd0-4b5a-923d-9f66a305aff2_1672x941.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><ol><li><p><strong><span>Fragmentation.</span></strong><span> The systems that investigate an incident are still separate from the systems and processes that authorize and execute a response. Evidence lives in one place, authority in another, proof in a third.</span></p></li><li><p><strong><span>Noise.</span></strong><span> Every vendor demo looks similar. Summaries, enrichment, entity extraction, and guided investigation now present a nearly identical analyst experience, even when the evidence handling and the response authority underneath differ enormously.</span></p></li><li><p><strong><span>Lack of differentiation.</span></strong><span> Because investigation has commoditized, front-of-funnel capability no longer separates products. The real differences have moved downstream, into governance, execution, verification, and proof, which are exactly the things a demo does not show well.</span></p></li><li><p><strong><span>Too many players.</span></strong><span> Independent trackers now count well over a hundred vendors claiming a capability here, and the number keeps climbing. Buyers cannot evaluate a hundred products. They need a way to reduce the field to the handful that fit their environment and the specific actions they intend to delegate.</span></p></li><li><p><strong><span>No standard definitions. </span></strong><span>Vendors market AI SOC, agentic SOC, autonomous SOC, ISOC, XDR with agents, AI-native MDR. Analyst firms have not converged either. Gartner has introduced an Integrated Security Operations Center (ISOC) category, while Forrester kept the XDR name and added agentic systems as a distinct evaluation criterion, with SIEM replacement treated as real rather than experimental. When the taxonomers disagree, the buyer pays the tax.</span></p></li></ol><p><span>These pressure points highlight two major structural shifts taking place:</span></p><ol><li><p><strong><span>Category consolidation. </span></strong><span>Every AI SOC conversation has become a consolidation conversation. Buyers are rarely satisfied with triage alone; they want to reduce or replace SIEM, SOAR, and MDR costs at the same time. Vendors have responded by expanding out of the triage middle: some move left into detection engineering, threat hunting, and even SIEM, while others move right into response, automation building, and managed services. Data-pipeline vendors are moving up the stack into detection and AI SOC as well. The line between a pure-play AI SOC and an AI SOC capability bolted onto an incumbent platform is blurring, and for many buyers it is no longer the deciding question. What matters is whether the capability is a genuine, governed response engine or a checkbox.</span></p></li><li><p><strong><span>Urgency. </span></strong><span>For two decades the SOC was organized around a human sitting at the center of every decision that matters. That model assumed human judgment could keep pace with the threat. Frontier models in the hands of adversaries have started to break that assumption, compressing reconnaissance, exploitation, and lateral movement toward machine speed. The industry, including several vendors building operating-model frameworks of their own, now argues that bolting AI onto a human-speed process only relocates the bottleneck. We agree with the diagnosis, but our emphasis is different: speed without governed authority is a liability. The answer to a machine-speed adversary is a response that is fast, bounded, evidence-based, and provable. That is precisely what TSRO is designed to produce.</span></p></li></ol><h3><strong><span>The Practitioner Signal</span></strong></h3><p><span>Our interviews with security leaders surfaced the following themes often enough to shape our analysis:</span></p><ul><li><p><strong><span>The context moat. </span></strong><span>Security telemetry alone rarely contains enough to justify a response. The same behavior means different things in a media company and a regulated bank. Practitioners consistently told us that the platforms worth trusting are the ones that let an operator inspect the context behind a conclusion, add what is missing, challenge the hypothesis, and watch the recommendation change.</span></p></li><li><p><strong><span>Detection quality is critical. </span></strong><span>Several AI SOC vendors are adding detection engineering and even SIEM capabilities, partly because weak detections upstream cap the value of any downstream investigation or response.</span></p></li><li><p><strong><span>Proof lags ambition. </span></strong><span>Vendors define investigations, actions, and time saved differently, so headline metrics do not compare. The most credible teams measure at the level of the individual action, through execution and verified outcome, not at the level of the whole platform.</span></p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/p/ai-soc-technoscope-series-building?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading Software Analyst Cyber Research! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/p/ai-soc-technoscope-series-building?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/p/ai-soc-technoscope-series-building?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div></li></ul><h2><strong><span>The Wider SOC Architecture</span></strong></h2><p><span>SACR&#8217;s 2025 research described the SOC as a layered architecture spanning the data fabric, storage and detection, and response and automation. Those layers remain relevant, but the boundaries between them have become less stable. The most important architectural change over the past year is that capabilities previously purchased and operated separately are being pulled into a more continuous operating layer. AI SOC vendors are moving upstream into detection engineering, threat hunting, security data, and SIEM. SOAR vendors are bringing model-based investigation and decision support into their workflows. Data-pipeline vendors are adding detection and AI-assisted operations, while incumbent platforms connect their own telemetry and analytics to enforcement. Buyers are now evaluating how far a provider can carry an incident through the workflow and which existing costs or systems can be consolidated.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1FAA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b150732-a4eb-4889-801d-4736eeb096a0_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1FAA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b150732-a4eb-4889-801d-4736eeb096a0_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!1FAA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b150732-a4eb-4889-801d-4736eeb096a0_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!1FAA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b150732-a4eb-4889-801d-4736eeb096a0_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!1FAA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b150732-a4eb-4889-801d-4736eeb096a0_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1FAA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b150732-a4eb-4889-801d-4736eeb096a0_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2b150732-a4eb-4889-801d-4736eeb096a0_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!1FAA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b150732-a4eb-4889-801d-4736eeb096a0_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!1FAA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b150732-a4eb-4889-801d-4736eeb096a0_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!1FAA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b150732-a4eb-4889-801d-4736eeb096a0_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!1FAA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b150732-a4eb-4889-801d-4736eeb096a0_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong><span>Reinforcing Detections</span></strong></h3><p><span>This expansion has pulled detection engineering back into the AI SOC discussion. The first generation of products relied on alerts from external sources, while newer platforms generate and tune detections in addition to the traditional AI SOC capabilities. This shift is a natural market response to a recurring theme in our research: weak upstream signals and poor context correlation undermine the investigation and response decisions built on them.</span></p><h3><strong><span>Investigation and Response Consolidation</span></strong></h3><p><span>Investigation and response have also begun to shift to a continuous runtime across the traditional layers of the SOC. Evidence collection, case development, decision-making, and execution were historically distributed across different tools and human handoffs. Modern AI SOC tools are increasingly attempting to maintain a case state across that path, mixing AI reasoning and deterministic automation to take dynamic and repeatable actions.</span></p><p><span>This report focuses heavily on this theme. Vendors approach this layer from three architectural starting points:</span></p><ol><li><p><span>AI-native platforms begin with dynamic evidence collection, case development, and decisioning.</span></p></li><li><p><span>SOAR-derived platforms build on established strengths in workflow automation, case management, and repeatable deterministic execution.</span></p></li><li><p><span>Platform-consolidated vendors connect these functions to telemetry and control surfaces they already own. Each path creates distinct advantages and adoption burdens, but the required outcome is the same: a defensible path from incident to verified remediation.</span></p></li></ol><p><span>AI&#8217;s role in security operations should remain distinct from deterministic automation. Repeatable enrichment, normalization, and containment are inherently safer and less expensive when handled through fixed logic, while AI provides greater value when the system must interpret ambiguous circumstances and recommend an action under uncertainty. Through TSRO, a mature architecture should make the division between AI and fixed logic visible, allowing operators to understand when a model is reasoning, when a workflow is executing, and how they work together to build the Trusted SOC.</span></p><h3><strong><span>Introduction of Governance</span></strong></h3><p><span>Governance now sits inside the architecture. Approval routing, policy constraints, credential separation, action scope, audit records, and outcome verification determine whether a system can move beyond investigation. These controls connect an AI-generated conclusion to a response action the organization is willing to authorize. TSRO applies at this boundary, giving security teams a model for granting and expanding authority one action at a time, based on the evidence and controls attached to that action.</span></p><p><span>Most buyers will end up with a hybrid SOC architecture. An independent AI SOC layer can sit over the existing stack, while some organizations will consolidate around a platform that already owns telemetry and enforcement. Others will keep a SOAR-derived execution layer or have a managed provider operate the capability. Few will replace every component at once. The practical questions are where the incident&#8217;s evidence and case state live, which system holds the authority to act, and how the organization proves the intended change occurred.</span></p><h2><strong><span>How SACR Defines the Market</span></strong></h2><p><span>The expansion of AI SOC across detection, investigation, response, and service delivery has made the category harder to define under a single term or product shape. Vendors use terms such as AI SOC, Agentic SOC, Autonomous SOC, Integrated SOC (ISOC), XDR with agents, and AI-native MDR to describe capabilities that increasingly overlap. These labels are useful for identifying where a platform began and how it is delivered, but they provide limited insight into the authority an organization should grant it.</span></p><p><span>SACR uses AI SOC to describe the broader technological environment and market. Within that environment, Trusted Security Response Operations defines how a security team governs software authority, and the Trusted SOC is the resulting operating state: a SOC that has earned authority to perform specific actions through demonstrated decision quality, controlled execution, and verified outcomes.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ejad!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdd97566-a83e-4274-ba48-5d015e69c9ab_1672x941.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ejad!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdd97566-a83e-4274-ba48-5d015e69c9ab_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!ejad!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdd97566-a83e-4274-ba48-5d015e69c9ab_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!ejad!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdd97566-a83e-4274-ba48-5d015e69c9ab_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!ejad!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdd97566-a83e-4274-ba48-5d015e69c9ab_1672x941.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ejad!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdd97566-a83e-4274-ba48-5d015e69c9ab_1672x941.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bdd97566-a83e-4274-ba48-5d015e69c9ab_1672x941.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ejad!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdd97566-a83e-4274-ba48-5d015e69c9ab_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!ejad!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdd97566-a83e-4274-ba48-5d015e69c9ab_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!ejad!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdd97566-a83e-4274-ba48-5d015e69c9ab_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!ejad!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdd97566-a83e-4274-ba48-5d015e69c9ab_1672x941.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong><span>Defining Trusted Security Response Operations</span></strong></h2><p><span>Trusted Security Response Operations (TSRO) is the operating model through which security teams grant software bounded authority to recommend, prepare, execute, and verify response actions under explicit requirements for evidence, policy, credentials, scope, and accountability.</span></p><p><span>TSRO does not require or build toward blanket autonomy in the SOC. It can begin with recommended or prepared actions that remain subject to human approval. The key is the controlled process connecting evidence, decisions, authority, execution, and verification.</span></p><p><span>Security teams grant authority one decision at a time. An organization can often trust a system to close a clearly understood case while still requiring oversight or approval for more impactful state-changing action. These decisions form an authority portfolio that can expand, narrow, or be withdrawn as performance is monitored.</span></p><h4><span>Trusted Security Operations Center</span></h4><p><span>The objective of TSRO is to build a Trusted SOC. It is a dynamic description of a SOC that has earned authority to execute specific response actions through demonstrated decision quality, controlled execution, and verified outcomes. Trusted SOC should not be viewed as a category or market label applied to a series of products.</span></p><p><span>As the evidence supporting Trusted SOC actions becomes stronger, an organization can expand the system&#8217;s authority across different risk levels. The Trusted SOC is progressive by design, built through a growing portfolio of authorities bounded by policy and accountable to the people who own the security and business outcomes.</span></p><h3><strong><span>Where TSRO Sits Among Existing Frameworks</span></strong></h3><p><span>We did not arrive at this in an empty field, and it would be dishonest to present TSRO as if the market had said nothing about autonomy and trust. Several strong frameworks already exist. TSRO is designed to occupy the specific gap they leave open. It helps to see the market&#8217;s frameworks as answering three different questions.</span></p><ol><li><p><strong><span>Question one: where does a vendor play across the lifecycle?</span></strong><span> This is the mapping question, and the clearest work here is the </span><a href="https://secops-unpacked.ai/research/ai-soc-vendors?view=shiftmap"><span>SecOps Shift Map from SecOps Unpacked</span></a><span>, which tracks how vendors that began in the triage middle have moved left into detection and SIEM or right into response and automation, with a separate lane for those adding MDR services. Analyst firms answer the same question at the category level, Gartner with the Integrated SOC (ISOC) label and Forrester by extending XDR to include agentic systems. These are coverage maps. They tell you what a platform touches.</span></p></li><li><p><strong><span>Question two: what infrastructure makes autonomy possible?</span></strong><span> This is the architecture question. The clearest recent example is </span><a href="https://www.extrahop.com/blog/the-soc-needs-a-new-operating-model"><span>ExtraHop&#8217;s Context, Harness, Model</span></a><span> operating model, which separates the real-time evidence an agent reasons on (context), the governed control plane that mediates and scopes every action an agent may take (harness), and the swappable model layer that does the work. Its companion idea, an open alliance of interoperating best-of-breed layers, argues that no single vendor delivers the whole model. This is an infrastructure blueprint. It tells you how the pieces fit.</span></p></li><li><p><strong><span>Question three: how independent is the agent, in the abstract?</span></strong><span> This is the autonomy-ladder question, and it has both academic and industry versions: peer-reviewed SOC frameworks that define five levels of AI autonomy mapped to human-in-the-loop roles and task-specific trust thresholds, the </span><a href="https://labs.cloudsecurityalliance.org/wp-content/uploads/2026/03/agentic-ai-autonomy-levels-control-framework-v2-csa-styled.pdf"><span>Cloud Security Alliance&#8217;s six-level agentic autonomy and control framework</span></a><span> with boundary enforcement, and vendor progressions from human-in-the-loop to human-on-the-loop. </span><a href="https://www.kaspersky.com/blog/autonomous-soc-2026-challenges-and-solutions/55977/"><span>Kaspersky&#8217;s Trusted Autonomy framing </span></a><span>sits here too. These are capability tiers. They tell you how much a system could do.</span></p></li></ol><p><strong><span>TSRO answers a fourth question that the others assume: how does a specific organization earn, govern, and prove authority for a specific action, over time?</span></strong></p><p><span>Two distinctions make that a genuinely different question rather than a rebrand.</span></p><ul><li><p><strong><span>Authority, not autonomy.</span></strong><span> Autonomy is a capability a vendor claims. Authority is a permission a buyer grants. The autonomy ladders describe what a system is technically able to do. TSRO describes what a named organization has decided to let it do, on which action, on what evidence, with which owner accountable. The locus of control moves from the vendor&#8217;s roadmap to the buyer&#8217;s governance.</span></p></li><li><p><strong><span>A portfolio, not a level.</span></strong><span> Every framework above tends to place a platform at a level or in a layer. TSRO holds that a single platform occupies many positions at once: proven authority to quarantine confirmed malicious email, policy-bounded authority to block a confirmed indicator, approval-bounded authority to isolate an endpoint, and advisory-only authority for privileged identity actions, all in the same deployment on the same day.</span></p></li></ul><p><span>The honest overlap is with the governance layer of the architecture frameworks. What ExtraHop calls the harness, a governed control plane that scopes and audits agent actions, is the technical substrate that a TSRO program needs. We see them as complementary. The harness is the enforcement mechanism. TSRO is the operating discipline that decides what the enforcement should permit, how authority is earned, and when it expands or is revoked. Infrastructure alone does not tell a CISO which business risks to accept. TSRO is the layer that does.</span></p><h3><strong><span>Where TSRO Begins</span></strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rgHY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe0e39f9-bf1e-4af4-aff6-bb2262a5fa30_1672x941.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rgHY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe0e39f9-bf1e-4af4-aff6-bb2262a5fa30_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!rgHY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe0e39f9-bf1e-4af4-aff6-bb2262a5fa30_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!rgHY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe0e39f9-bf1e-4af4-aff6-bb2262a5fa30_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!rgHY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe0e39f9-bf1e-4af4-aff6-bb2262a5fa30_1672x941.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rgHY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe0e39f9-bf1e-4af4-aff6-bb2262a5fa30_1672x941.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/be0e39f9-bf1e-4af4-aff6-bb2262a5fa30_1672x941.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!rgHY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe0e39f9-bf1e-4af4-aff6-bb2262a5fa30_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!rgHY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe0e39f9-bf1e-4af4-aff6-bb2262a5fa30_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!rgHY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe0e39f9-bf1e-4af4-aff6-bb2262a5fa30_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!rgHY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe0e39f9-bf1e-4af4-aff6-bb2262a5fa30_1672x941.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>Many products improve an analyst&#8217;s understanding of an incident without affecting the response path. These capabilities accelerate AI SOC workflows, but they do not establish TSRO on their own.</span></p><p><span>TSRO begins when software enters the governed path to a remediation action. A product supports TSRO when it can define or prepare an action, route it to the proper authority, and contribute to execution and verified outcome at its granted stage. The clearest distinction is whether a product helps move the incident beyond completed investigation toward controlled, verifiable remediation.</span></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Software Analyst Cyber Research! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h2><strong><span>The Buyer Problem: Why the Action Gap Persists</span></strong></h2><p><span>Even with visible product consolidation, the systems used to investigate an incident remain separate from the processes used to authorize a response in most environments. Even after the SOC reaches a conclusion, evidence from fragmented sources has to be translated into a proposed action and carried into a different operational process.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tHFS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c9eb4e3-1cce-4b92-b7ee-f867762a40be_1672x941.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tHFS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c9eb4e3-1cce-4b92-b7ee-f867762a40be_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!tHFS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c9eb4e3-1cce-4b92-b7ee-f867762a40be_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!tHFS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c9eb4e3-1cce-4b92-b7ee-f867762a40be_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!tHFS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c9eb4e3-1cce-4b92-b7ee-f867762a40be_1672x941.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tHFS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c9eb4e3-1cce-4b92-b7ee-f867762a40be_1672x941.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3c9eb4e3-1cce-4b92-b7ee-f867762a40be_1672x941.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tHFS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c9eb4e3-1cce-4b92-b7ee-f867762a40be_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!tHFS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c9eb4e3-1cce-4b92-b7ee-f867762a40be_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!tHFS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c9eb4e3-1cce-4b92-b7ee-f867762a40be_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!tHFS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c9eb4e3-1cce-4b92-b7ee-f867762a40be_1672x941.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>Ownership is fragmented in the same way. The SOC can identify a compromised account, but authority over directory, endpoint, and workload actions is distributed across other teams. The delay often has nothing to do with uncertainty about the incident. It comes from determining who can authorize the action, what evidence they require, and how to execute without creating new risk.</span></p><p><span>And that risk varies sharply by action. Quarantining an email is usually bounded and reversible. Isolating a production server or changing a firewall rule can interrupt critical operations. The decision has to weigh asset criticality, blast radius, and the available recovery path, and existing workflows rarely bring that context into the moment of decision.</span></p><p><span>Finally, the process leaves an incomplete record. Many systems can show that an action was initiated, but not why it was chosen, what evidence supported it, who authorized it, or how the outcome was verified. Without that record, an organization cannot compare performance across incidents or decide whether software has earned broader authority. TSRO closes these gaps by bringing evidence, authority, execution, and verification into one operating process. The buyer problem then becomes tractable: how to make delegation operationally safe, organizationally accountable, and defensible over time.</span></p><h3><strong><span>Different Actions Require Different Authority</span></strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2K4V!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71838c6c-b3a7-4f4f-a042-ff0af269973f_1672x941.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2K4V!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71838c6c-b3a7-4f4f-a042-ff0af269973f_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!2K4V!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71838c6c-b3a7-4f4f-a042-ff0af269973f_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!2K4V!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71838c6c-b3a7-4f4f-a042-ff0af269973f_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!2K4V!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71838c6c-b3a7-4f4f-a042-ff0af269973f_1672x941.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2K4V!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71838c6c-b3a7-4f4f-a042-ff0af269973f_1672x941.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/71838c6c-b3a7-4f4f-a042-ff0af269973f_1672x941.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!2K4V!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71838c6c-b3a7-4f4f-a042-ff0af269973f_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!2K4V!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71838c6c-b3a7-4f4f-a042-ff0af269973f_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!2K4V!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71838c6c-b3a7-4f4f-a042-ff0af269973f_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!2K4V!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71838c6c-b3a7-4f4f-a042-ff0af269973f_1672x941.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><ul><li><p><strong><span>Email response</span></strong><span> is a common starting point because it is contained. A platform can inspect the message, correlate recipient activity, review related identity events, and prepare a quarantine. The affected systems are known, the action is usually reversible, and success can be verified across mailboxes.</span></p></li><li><p><strong><span>Identity response</span></strong><span> requires more organizational context. An unusual login may signal compromise, or it may be a known administrative jump host. The right response depends on privilege, active sessions, device state, business role, and access to sensitive applications. Incomplete context turns a reasonable response into an avoidable business disruption.</span></p></li><li><p><strong><span>Cloud containment</span></strong><span> raises the threshold again, because a credential, policy, or workload may support several dependent services. The platform needs service ownership, production criticality, credential scope, dependency information, and a recovery path before action can be delegated safely.</span></p></li></ul><p><span>The point is that each action carries its own evidence, policy, and authority decision. The same platform may hold policy-bounded authority for email quarantine while remaining advisory-only for identity revocation and cloud containment.</span></p><h2><strong><span>Building the Trusted SOC: The TSRO Trust and Delegation Model</span></strong></h2><p><span>TSRO treats trust as an operational state that is earned and maintained. An organization does not decide that an AI SOC or automation platform is trusted as a whole. Trust is determined incrementally as the system recommends and takes specific actions. The accumulation of those trusted actions is what builds the Trusted SOC.</span></p><p><span>Understanding this distinction is important because the consequences of error change with the risk level of the action. Recommending quarantine of a clearly malicious email carries less operational risk than disabling privileged identities or isolating production workloads.</span></p><p><span>There are conditions that can limit the progression of trust. Weak data and telemetry can undermine investigations, allowing routine incidents to be handled reliably while ambiguous cases expose missing context, poor data quality, and uncertainty. Business accountability also remains with the CISO and security operators regardless of whether software recommends or executes an action.</span></p><p><span>The TSRO model addresses these conditions through a chain of evidence, decision, authority and action, proof, and improvement. Weakness in any part of the chain provides clear justification to limit the authority granted to the system.</span></p><h3><strong><span>The Five-Layer Trust Model</span></strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1R08!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca2676df-6271-47f8-82d6-71a7453b3788_1672x941.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1R08!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca2676df-6271-47f8-82d6-71a7453b3788_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!1R08!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca2676df-6271-47f8-82d6-71a7453b3788_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!1R08!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca2676df-6271-47f8-82d6-71a7453b3788_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!1R08!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca2676df-6271-47f8-82d6-71a7453b3788_1672x941.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1R08!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca2676df-6271-47f8-82d6-71a7453b3788_1672x941.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ca2676df-6271-47f8-82d6-71a7453b3788_1672x941.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!1R08!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca2676df-6271-47f8-82d6-71a7453b3788_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!1R08!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca2676df-6271-47f8-82d6-71a7453b3788_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!1R08!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca2676df-6271-47f8-82d6-71a7453b3788_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!1R08!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca2676df-6271-47f8-82d6-71a7453b3788_1672x941.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h4><span>Evidence</span></h4><p><span>The foundation of trust begins with evidence. The evaluated platform must collect the information needed to support a decision and preserve where it came from, how it was used, and when it was collected. Outdated or contradictory evidence should be clearly annotated, along with the absence of evidence. A lack of evidence should not be treated as justification for safe action; it should be a warning sign.</span></p><h4><span>Decision</span></h4><p><span>The evidence collected supports the decision layer. A defensible decision surfaces the leading explanation of the incident, how the evidence supports it, uncertainty, and plausible alternatives. The decision layer should give the operator enough information to challenge the conclusion and understand what additional context could change the outcome.</span></p><h4><span>Authority and Action</span></h4><p><span>The action layer governs both authority and execution. It defines who can authorize a response and the target, scope, execution method, stop conditions, and recovery options associated with it. An evidence-supported decision can still produce a harmful outcome if authority or execution is not properly controlled.</span></p><h4><span>Proof</span></h4><p><span>The proof layer connects the decision and action to the resulting outcome. It records what was authorized, what was executed, whether the action achieved the intended objective, and whether rollback or recovery is required. A narrative record supports accountable human review, while structured output supports measurement and comparison across incidents.</span></p><h4><span>Improvement</span></h4><p><span>The improvement layer uses structured outputs to inform future operations. Details about accepted and rejected recommendations, failures, human overrides, and successful actions can drive updates to policy and workflows. This layer closes the loop across the five layers of trust and supports continued improvement.</span></p><h3><strong><span>Stages of Graduated Authority</span></strong></h3><p><span>We designed the stages of authority around the conditions that exist today in the market. Our surveys and interviews showed a consistent progression from recommend-only workflows through approval-required and policy-bounded actions. The data showed broader support for partial autonomy, while a fully autonomous or &#8220;lights-out&#8221; SOC remains constrained by trust, ownership, and business process.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!b9Vg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2ff1e2e-6050-4355-9bbd-28799431da11_1672x941.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!b9Vg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2ff1e2e-6050-4355-9bbd-28799431da11_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!b9Vg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2ff1e2e-6050-4355-9bbd-28799431da11_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!b9Vg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2ff1e2e-6050-4355-9bbd-28799431da11_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!b9Vg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2ff1e2e-6050-4355-9bbd-28799431da11_1672x941.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!b9Vg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2ff1e2e-6050-4355-9bbd-28799431da11_1672x941.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e2ff1e2e-6050-4355-9bbd-28799431da11_1672x941.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!b9Vg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2ff1e2e-6050-4355-9bbd-28799431da11_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!b9Vg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2ff1e2e-6050-4355-9bbd-28799431da11_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!b9Vg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2ff1e2e-6050-4355-9bbd-28799431da11_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!b9Vg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2ff1e2e-6050-4355-9bbd-28799431da11_1672x941.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h4><span>Stage 1: Advisory Authority</span></h4><p><span>The platform gathers evidence, develops a conclusion, and proposes an action while humans retain decision and execution authority. This stage tests investigation quality, relevance, and the platform&#8217;s ability to explain uncertainty without placing production systems at risk.</span></p><h4><span>Stage 2: Approval-Bounded Authority</span></h4><p><span>The platform prepares the action, defines the target and scope, presents the supporting evidence, and routes approval to the accountable owner. Human authorization remains part of the execution path, while much of the delay and manual handoff can be removed.</span></p><h4><span>Stage 3: Policy-Bounded Authority</span></h4><p><span>The platform may act for approved action types, assets, identities, scopes, and risk tiers without case-by-case approval. Policy replaces the one-off decision while preserving accountability. Clear stop conditions, exception paths, rollback, and verification are required.</span></p><h4><span>Stage 4: Proven Authority</span></h4><p><span>The organization maintains delegated execution authority for a specific action because evidence quality, decision accuracy, control reliability, false-action rates, rollback performance, and outcome verification have remained within accepted thresholds over time. Proven authority does not mean unrestricted control. High-impact actions may remain approval-bounded permanently.</span></p><h4><span>The Authority Portfolio</span></h4><p><span>An organization will usually operate at several stages of authority simultaneously. It may grant the same platform proven authority to quarantine confirmed malicious email, policy-bounded authority to block confirmed malicious indicators at selected control points, approval-bounded authority to isolate endpoints, and advisory authority for privileged identity actions.</span></p><p><span>Together, these action-specific decisions form the authority portfolio. Each individual authority should identify:</span></p><ul><li><p><span>Eligible incident and action</span></p></li><li><p><span>Required evidence</span></p></li><li><p><span>Decision threshold</span></p></li><li><p><span>Action scope</span></p></li><li><p><span>Accountable owner</span></p></li><li><p><span>Blast radius assessment</span></p></li><li><p><span>Rollback and recovery method</span></p></li><li><p><span>System&#8217;s performance history on similar actions</span></p></li></ul><p><span>The maturity of the Trusted SOC is determined by the breadth and reliability of this portfolio. Authority may expand as records support it, narrow when conditions change, or be withdrawn after a failure.</span></p><h3><strong><span>How Authority Varies by Action Type</span></strong></h3><p><span>Low-risk response actions can often move into policy-bounded automation first. Selected email quarantine, session termination, and temporary blocks on confirmed malicious indicators are usually reversible and have limited business impact. The main control requirements are accuracy, verification, and a clear audit trail.</span></p><p><span>Medium-risk actions should usually begin with approval-bounded execution and expand only after validation. Endpoint isolation and narrow containment can reduce risk quickly but may disrupt users or systems. The evidence threshold, owner, and rollback path should be explicit.</span></p><p><span>High-risk actions should remain advisory or approval-bounded until the platform proves decision quality, scope control, recovery, and audit-grade proof. Privileged identity revocation, broad cloud containment, and network policy changes can create business-wide effects. Evidence requirements should match the consequence of error, and automation should expand only when the proof supports it.</span></p><h3><strong><span>Failure Modes and Design Risks</span></strong></h3><p><span>The authority portfolio must respond to failure in practice. A system that performed reliably under one set of circumstances can encounter new data sources, attack techniques, and organizational constraints. TSRO therefore requires organizations to identify where the trust chain breaks and adjust authority appropriately as the environment changes.</span></p><p><span>Evidence-layer failures include missing, incorrect, stale, or poorly normalized data. Business context used by AI investigations can also be improperly correlated or maliciously modified by attackers. Source controls and rules for handling incomplete context are required before evidence can be trusted to support an action.</span></p><p><span>Decision-layer failures include unsupported claims, inflated confidence levels, and failure to consider plausible alternatives. They can be hidden when an investigation is compressed into a summary. Evaluators should test ambiguous incidents, conflicting evidence, and cases outside a vendor&#8217;s common demonstrations to assess reasoning in non-standard situations.</span></p><p><span>Execution-layer failures include an inability to complete the state-changing remediation, excessive permissions, incorrect targets, and API errors. Confirmation that a task ran through an API does not prove that the security objective was met. Verification of the completed objective is critical to evaluating the execution layer.</span></p><p><span>These failures should directly influence the authority portfolio. Consistent collection of metrics and evidence provides security operators with the basis for granting, adjusting, and revoking authority.</span></p><h2><strong><span>Measuring the Trusted SOC</span></strong></h2><p><span>The authority portfolio depends on continuous measurement. Organizations need evidence that a system continues to meet the thresholds attached to each delegated action, along with clear signals for when authority should expand, narrow, or be withdrawn. The Trusted SOC measurement stack connects technical performance, reliability, response outcomes, and operating economics to those decisions.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!593C!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a4180d9-1f26-4da3-a7a4-be1b9f26e34a_1672x941.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!593C!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a4180d9-1f26-4da3-a7a4-be1b9f26e34a_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!593C!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a4180d9-1f26-4da3-a7a4-be1b9f26e34a_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!593C!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a4180d9-1f26-4da3-a7a4-be1b9f26e34a_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!593C!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a4180d9-1f26-4da3-a7a4-be1b9f26e34a_1672x941.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!593C!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a4180d9-1f26-4da3-a7a4-be1b9f26e34a_1672x941.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3a4180d9-1f26-4da3-a7a4-be1b9f26e34a_1672x941.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!593C!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a4180d9-1f26-4da3-a7a4-be1b9f26e34a_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!593C!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a4180d9-1f26-4da3-a7a4-be1b9f26e34a_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!593C!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a4180d9-1f26-4da3-a7a4-be1b9f26e34a_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!593C!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a4180d9-1f26-4da3-a7a4-be1b9f26e34a_1672x941.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>The most useful unit of measurement is the individual response action. Platform-wide automation rates combine activities with very different levels of risk and operational value. Quarantining an email, isolating an endpoint, and revoking a privileged identity should not be counted as equivalent forms of automation.</span></p><h3><strong><span>Measuring the Response Path</span></strong></h3><p><span>Time from detection to verified remediation remains an important measure because it identifies when the state of the environment changed. It should be divided into detection, triage, investigation, approval, execution, verification, and documentation.</span></p><p><span>This phase view is important because a single mean-time-to-respond figure can conceal the actual operational bottleneck. A platform may reduce investigation time while approval or execution time remains unchanged. Breaking the process into phases shows where technology created value and where organizational ownership or workflow continues to introduce delay.</span></p><p><span>The same approach should be applied to verification. An action is not complete when an API call returns a successful status. Endpoint isolation must be confirmed, and a malicious email must be removed from the intended mailboxes. Mean time to verify remediation measures the period between execution and confirmation that the security objective was achieved.</span></p><h3><strong><span>Measuring Authority and Human Review</span></strong></h3><p><span>Delegated execution should be reported by action type and authority stage. The organization should know how many actions remained advisory, how many required approval, how many executed within policy, and how many operated under proven authority.</span></p><p><span>Recommendation acceptance rate shows how often analysts or system owners agree with the platform&#8217;s proposed response. Rejection and override reasons provide more useful information than the acceptance rate alone. They should distinguish incorrect conclusions, missing context, business exceptions, and reviewer preference.</span></p><p><span>This distinction helps the organization identify the source of disagreement. A rejected recommendation may reveal a product failure, but it may also expose incomplete data or a policy that does not reflect current operations.</span></p><h3><strong><span>Measuring Safety and Recovery</span></strong></h3><p><span>False-action rate should include actions that were incorrect or unsupported by the available evidence. It should be calculated separately for each action type because the consequences of error vary significantly.</span></p><p><span>Rollback and exception rates show how often an action must be reversed, escalated, or completed outside the normal process. These measures should capture both technical and operational failures, including incorrect targets, approval errors, and unintended business impact.</span></p><p><span>Recovery performance is also important. An organization should know whether the platform identified the failure, initiated the correct recovery path, and restored the affected system. A low failure rate provides limited assurance when the system cannot recover safely from the failures that do occur.</span></p><h3><strong><span>Metrics to Approach with Caution</span></strong></h3><p><span>Broad mean-time-to-respond measures often combine too many phases to identify where improvement occurred. The percentage of alerts handled automatically may include duplicate suppression, enrichment, ticket creation, or low-risk closure without distinguishing state-changing response.</span></p><p><span>Analyst-hours-saved claims require a baseline workflow, defined task boundary, sample period, and quality control. Time saved has limited value when the work must be repeated, reviewed extensively, or corrected after an unsafe action.</span></p><p><span>A platform-wide autonomy percentage is particularly weak. Authority is granted to specific actions under defined conditions, not to the platform as a whole. Activity metrics become meaningful once they can be connected to a measurable operational outcome.</span></p><h3><strong><span>The Economics of AI-Driven Operations</span></strong></h3><p><span>Once response is measured at the action level, the organization can evaluate its true cost. The cost of AI-driven security operations extends beyond the platform license. It includes:</span></p><ul><li><p><span>Model inference</span></p></li><li><p><span>Agent runtime</span></p></li><li><p><span>Data movement</span></p></li><li><p><span>Storage</span></p></li><li><p><span>Retrieval</span></p></li><li><p><span>Connector development</span></p></li><li><p><span>Workflow design</span></p></li><li><p><span>Implementation</span></p></li><li><p><span>Credential governance</span></p></li><li><p><span>Testing</span></p></li><li><p><span>Human review</span></p></li><li><p><span>Exception handling</span></p></li><li><p><span>Ongoing maintenance</span></p></li></ul><p><span>Failures add cost as well. An incorrect action may consume analyst time, disrupt users, or create business impact. A platform with a low license price can still produce an expensive operating model when integration and oversight requirements are high.</span></p><p><span>AI also changes the cost structure of security work. Security telemetry and operational artifacts are converted into model input. Costs increase when several agents process the same evidence, context is rebuilt at each step, tool responses are unnecessarily verbose, or the system retries and validates work without maintaining a reusable case state.</span></p><p><span>More capable workflows will require larger contexts, longer reasoning paths, additional tool calls, multimodal evidence, and repeated validation. Each may improve decision quality but will also increase consumption. Complex incidents can consequently cost substantially more than routine cases, making a simple average cost per investigation an unreliable forecast of production spend.</span></p><p><span>Commercial pricing can further obscure the relationship between cost and value. Flat platform fees may include usage ceilings, overage rates, or model-routing policies. Per-agent, per-investigation, per-action, and token-based pricing all tie costs to different forms of activity. Buyers need visibility into model selection, context size, and quality thresholds to understand how costs will change at production scale.</span></p><p><span>Economic discipline depends on using the appropriate method for each task. Fixed enrichment, normalization, ticket creation, approval routing, and repeatable response steps often fit deterministic automation. Model use should be concentrated where interpretation, adaptation, or judgment materially improves the result. Efficient retrieval, reusable case state, selective context, and observable model routing reduce duplicated work without weakening decision quality.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QjQb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ff7f00d-26e5-4470-8615-8398903908c3_1672x941.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QjQb!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ff7f00d-26e5-4470-8615-8398903908c3_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!QjQb!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ff7f00d-26e5-4470-8615-8398903908c3_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!QjQb!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ff7f00d-26e5-4470-8615-8398903908c3_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!QjQb!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ff7f00d-26e5-4470-8615-8398903908c3_1672x941.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QjQb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ff7f00d-26e5-4470-8615-8398903908c3_1672x941.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1ff7f00d-26e5-4470-8615-8398903908c3_1672x941.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!QjQb!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ff7f00d-26e5-4470-8615-8398903908c3_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!QjQb!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ff7f00d-26e5-4470-8615-8398903908c3_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!QjQb!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ff7f00d-26e5-4470-8615-8398903908c3_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!QjQb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ff7f00d-26e5-4470-8615-8398903908c3_1672x941.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>Organizations should measure model and agent spend by use case, repeated retrieval and retry rates, the proportion of work handled deterministically, and the cost of human review, failed actions, and verification. Cost per investigation remains useful for workload analysis, but cost per verified remediation is the stronger operating measure because it connects the full cost of the response process to a confirmed reduction in risk.</span></p><div><hr></div><p></p><h2><span>CISO Implications and TSRO Adoption</span></h2><h3><strong><span>The CISO Decision</span></strong></h3><p><span>The CISO&#8217;s practical decision is which response actions can be delegated today, what evidence is required to maintain that authority, and what performance would justify changing it.</span></p><p><span>Those decisions will vary by organization. A financial institution, healthcare provider, technology company, and public-sector agency may reach different conclusions about the same action because their operating environments, regulatory obligations, and tolerance for disruption differ. TSRO provides a common decision structure without prescribing one acceptable level of authority.</span></p><p><span>The CISO must also determine who can grant or change that authority. Security may own the incident, but it does not always own the affected identity, application, or business process. Authority must reflect the organization&#8217;s actual accountability boundaries.</span></p><h3><strong><span>Adoption as Controlled Expansion</span></strong></h3><p><span>Adoption should begin with a small number of response actions whose scope, owner, evidence requirements, and expected outcomes can be clearly defined. The first use case should be meaningful enough to test the operating model but bounded enough that errors can be identified and recovered safely.</span></p><p><span>The initial evaluation should include normal incidents, benign anomalies, incomplete evidence, edge cases, and situations that cross team boundaries. The evaluation should surface disagreements between analysts and the platform, revealing missing context, inconsistent practices, and policy that needs clarification.</span></p><p><span>A time-bounded pilot using a representative set of cases can provide an initial baseline, but elapsed time and case volume are not sufficient on their own. The evaluation must include enough diversity to test uncertainty, escalation, ownership, and proof. A platform that performs well on repetitive phishing cases has not necessarily demonstrated readiness for privileged identity or cloud actions.</span></p><p><span>The authority stages established earlier in the report should operate as decision gates. Advisory operation tests the quality of the evidence and recommendation. Approval-bounded execution tests action preparation, scope, routing, and execution. Policy-bounded authority tests whether those controls remain reliable without case-by-case authorization. Proven authority depends on sustained performance rather than completion of a predetermined pilot period.</span></p><p><span>Expansion should follow the evidence, not a deployment schedule. An action may advance, remain at its current stage, return to an earlier stage, or be withdrawn. Different actions supported by the same platform will progress at different rates.</span></p><h3><strong><span>Governance Ownership</span></strong></h3><p><span>TSRO does not transfer accountability from the organization to the product. The SOC may own the investigation and recommend containment, while the teams responsible for identity, cloud, endpoint, applications, or affected business processes should participate in defining the conditions under which those actions may be delegated.</span></p><p><span>A cross-functional authority group should oversee material changes to the authority portfolio, review failures and recurring exceptions, and resolve ownership conflicts. Its role is to govern policy and authority, not approve every incident.</span></p><h3><strong><span>Build, Buy, or Hybrid</span></strong></h3><p><span>The three architectural paths described earlier&#8212;integration through an AI-native platform, extension of existing automation, and consolidation within a broader security platform&#8212;create different build, buy, and hybrid decisions. Each path can support TSRO when the organization retains control of its authority portfolio.</span></p><p><span>Building internally may fit organizations with mature SOC engineering, strong data and detection foundations, durable AI development resources, and workflows that commercial platforms cannot support. It can provide greater control over models, context, routing, deployment, and process design. The long-term burden includes maintenance, evaluations, model changes, and exception handling after the original development team moves on.</span></p><p><span>Buying may fit organizations that need packaged integrations, case workflows, and a faster path to production. The buyer still needs to determine how much configuration and service support the platform requires, whether it preserves existing investments, and whether its governance model fits internal ownership boundaries. A platform that deploys quickly but requires a new data architecture or operating process may create costs elsewhere.</span></p><p><span>A hybrid model will likely be the most common. A vendor platform may provide connectors, workflow, policy enforcement, and proof while the organization retains internal models, custom automations, decision logic, and managed context. Hybrid design is most effective when responsibilities are explicit and the organization does not maintain two overlapping control planes.</span></p><p><span>Regardless of the technical path, the organization must retain ownership of its authority portfolio. Vendors can provide the infrastructure for evidence, decisioning, execution, and proof. They cannot determine which business risks the organization should accept or who remains accountable for the outcome.</span></p><p></p><h2><span>Conclusion</span></h2><p><span>The shift from AI-assisted investigation to governed response changes how AI SOC maturity should be judged. More alerts summarized, cases investigated, or workflows initiated may improve productivity, but those measures do not establish whether software can be trusted to act. Maturity is demonstrated when the organization can define an authority, control how it is exercised, and verify that the action produced the intended outcome.</span></p><p><span>TSRO provides the operating model for managing that progression. Each authority is tied to a specific action, operating context, evidence requirement, policy owner, execution scope, and performance record. Authority expands when the evidence supports it and can be narrowed or withdrawn when conditions change. The resulting portfolio gives the organization a more defensible measure of progress than a platform-wide autonomy percentage.</span></p><p><span>The resulting Trusted SOC defines exactly what software is permitted to do, under whose authority, within which boundaries, and with what evidence of success. Humans retain accountability while intervening more precisely. Trust is earned through the organization&#8217;s ability to turn security decisions into controlled, verified, and accountable outcomes.</span></p><p></p><div><hr></div><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Software Analyst Cyber Research! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&quot;,&quot;text&quot;:&quot;Share Software Analyst Cyber Research&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share Software Analyst Cyber Research</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/p/ai-soc-technoscope-series-building/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/p/ai-soc-technoscope-series-building/comments"><span>Leave a comment</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[The CISO Guide to Endpoint Control and Prevention (ECP): The Next Architecture for Endpoint Security]]></title><description><![CDATA[New category market definition and buyer framework for securing users, agents, identities, and data at the endpoint. A five zone framework for securing AI-centric software at the endpoint.]]></description><link>https://softwareanalyst.substack.com/p/the-ciso-guide-to-endpoint-control</link><guid isPermaLink="false">https://softwareanalyst.substack.com/p/the-ciso-guide-to-endpoint-control</guid><dc:creator><![CDATA[SACR]]></dc:creator><pubDate>Wed, 22 Jul 2026 16:02:52 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!1Ovm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F698220fd-912d-47a8-b087-ab990a563584_1920x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h1><strong>Executive Summary</strong></h1><p>Endpoint security is entering its next architectural transition. For nearly fifteen years, <a href="https://www.ibm.com/think/topics/edr">Endpoint Detection and Response (EDR)</a> has been the foundation of endpoint defence for enterprises. It was designed for an era where attackers executed malware, launched processes, and modified files that operating systems could observe. That assumption is rapidly breaking down. Companies like <a href="https://www.crowdstrike.com/en-us/cybersecurity-101/endpoint-security/endpoint-detection-and-response-edr/">Crowdstrike EDR,</a>  <a href="https://www.sentinelone.com/cybersecurity-101/endpoint-security/what-is-endpoint-detection-and-response-edr/">SentinelOne EDR</a>, <a href="https://www.paloaltonetworks.ca/cyberpedia/what-is-endpoint-detection-and-response-edr">Palo Alto Networks EDR </a>earned that position by answering the question of its era: <strong>what did this program do on the machine?</strong> EDR watches the operating system. It logs when a process starts, and when a file is written, then matches those events to known attacker behavior. It worked because anything dangerous had to run as a visible program the operating system could see.</p><p>This assumption is now failing with AI usage in enterprises today. This is because the <strong>way work</strong> happens on the endpoint is changing. Three shifts separate the 2026 endpoint from the one most security programs were built for prior to 2023:</p><ul><li><p><strong>The rise of AI coding agents:</strong> In 2023, AI in the developer&#8217;s tools meant autocomplete that suggested code a human accepted line by line. In 2026, agents such as Cursor, Claude Code, and Copilot agent mode read the codebase, run shell commands, install packages, and complete tasks directly on the machine using the developer&#8217;s own permissions.</p></li><li><p><strong>Capabilities connect through a live protocol, not an installer.</strong> The rise of Model Context Protocol (MCP), which did not exist before late 2024, lets agents plug into tools, data, and internal systems at runtime. Each connection is a new link in the supply chain that never appears in a traditional software inventory.</p></li><li><p><strong>Everyone became a builder (not just engineers).</strong> AI tools for employees, Low-code and no-code frameworks can now let someone in finance or operations assemble a working application, workflow, or agent in an afternoon, often with no ticket, no review, and no security checkpoint. </p></li></ul><p>The pattern underneath all three is the same. The risky action is no longer a file the system can scan. It is an instruction written in plain language, carried out by software acting on a person&#8217;s behalf, often across steps that each look harmless alone. The endpoint has stopped being a device the operating system governs and become the point where people, agents, applications, and data meet. Securing it means governing that interaction as it happens, not reviewing the process after it ends. These interactions often occur <strong>above the operating system,</strong> leaving conventional EDR with only a partial view of what is actually happening.</p><p><strong>SACR believes this shift will create a new architectural category for the next decade: Endpoint Control and Prevention (ECP).</strong> </p><p>ECP covers a new vector that EDR&#8217;s today miss. They focus primarily on detecting malicious processes after execution; ECP expands endpoint security into a runtime control plane capable of governing AI agents, browser activity, application workflows, identity context, and sensitive data before attacks complete.</p><p><strong>The market landscape ecosystem is emerging.</strong> We have seen an explosion in companies on the market moving to solve the problem.  Specialized vendors are expanding endpoint security across software posture, application enforcement, AI runtime visibility, behavioural analysis, and data-centric controls. Over time, these capabilities are likely to converge into broader endpoint platforms.</p><ul><li><p><strong>EDR to ECP players</strong>: CrowdStrike, Palo Alto Networks, SentinelOne have moved to cover the new agentic market complementing their EDR solutions. </p></li><li><p><strong>Emerging ECP native key players</strong> include: <a href="https://www.neo.ai/">Neo Security</a>,  <a href="https://bay.security/">Bay Security</a>, <a href="https://bloom.security/">Bloom Security</a>, <a href="https://www.glow.io/">Glow Security,</a> <a href="https://pluto.security/">Pluto Security,</a> <a href="https://www.originhq.com/">Origin HQ</a>, <a href="https://ent.ai/">Ent</a>, <a href="https://www.bold.security/">Bold Security</a>, <a href="https://neuraltrust.ai/">NeutralTrust</a>, and <a href="https://www.cyberhaven.com/product/ai-security">Cyberhaven</a>, which define individual zones through purpose-built architecture. The vendors that already span several zones point to where the category is heading, toward one converged control plane rather than five separate tools. These are leading the charge to solve this market issue. We have partnered closely with the key players to perform our analysis, which is attached in the report.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1Ovm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F698220fd-912d-47a8-b087-ab990a563584_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1Ovm!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F698220fd-912d-47a8-b087-ab990a563584_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!1Ovm!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F698220fd-912d-47a8-b087-ab990a563584_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!1Ovm!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F698220fd-912d-47a8-b087-ab990a563584_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!1Ovm!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F698220fd-912d-47a8-b087-ab990a563584_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1Ovm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F698220fd-912d-47a8-b087-ab990a563584_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/698220fd-912d-47a8-b087-ab990a563584_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1447584,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://softwareanalyst.substack.com/i/208058321?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F698220fd-912d-47a8-b087-ab990a563584_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!1Ovm!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F698220fd-912d-47a8-b087-ab990a563584_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!1Ovm!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F698220fd-912d-47a8-b087-ab990a563584_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!1Ovm!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F698220fd-912d-47a8-b087-ab990a563584_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!1Ovm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F698220fd-912d-47a8-b087-ab990a563584_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>On the left is the EDR market as it stands today, competing on process and file telemetry that has largely commoditized. On the right, that same market fans out into the five zones where endpoint defence is now expanding, from software posture and supply chain governance at one end to data-centric enforcement at the other. The connective idea is that EDR becomes ECP: an extension of the endpoint, not a replacement of it. </p><h4>The Report Summary:  This report makes five observations.</h4><ol><li><p><strong>The endpoint is becoming the primary enforcement point for AI.</strong> Security controls must move closer to where prompts, tool calls, browser actions, and agent decisions actually occur. In 2026, more of this activity is happening at the endpoint.</p></li><li><p><strong>EDR is approaching an architectural ceiling.</strong> Process and file telemetry remain essential but no longer provide sufficient visibility into AI-driven workflows, browser sessions, SaaS applications, and non-binary software.</p></li><li><p><strong>Context becomes the new detection engine.</strong> Modern security requires understanding who initiated an action, what prompted it, which tools were used, and whether the resulting behavior aligns with legitimate intent.</p></li><li><p><strong>Prevention increasingly replaces response.</strong> Rather than terminating processes after compromise, next-generation platforms intervene earlier using software governance, workflow controls, behavioral guidance, and inline enforcement.</p></li></ol><p>Endpoint Control and Prevention should not be viewed as the replacement for EDR. Instead, it represents the next stage of endpoint security, extending protection from the operating system into the interactions between users, AI agents, applications, identities, and data that increasingly define enterprise risk.</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Software Analyst Cyber Research! Subscribe for free to receive new cybersecurity reports and analysis</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h1><strong>Endpoint Control and Prevention (ECP) Thesis</strong></h1><p>Our thesis is that the core failure in EDR is structural. Defenders lack actionable context within the execution workflow. Traditional endpoint tools secured basic machine hygiene and website access, but the next generation must secure the active interaction flow between users, autonomous agents, and SaaS platforms. Endpoint defense must transform from a passive detection sensor into a strategic control plane for the expanded use cases. EPP and EDR protected the machine and EDR protected the processes and some scripts; today, the defense perimeter must expand. The next-generation Endpoint Control and Prevention (ECP) endpoint protects the interaction of the critical flow between humans, AI systems, services, and data.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Bot1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba1d263c-decc-4a63-8354-47c359e05eba_1456x1158.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Bot1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba1d263c-decc-4a63-8354-47c359e05eba_1456x1158.png 424w, https://substackcdn.com/image/fetch/$s_!Bot1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba1d263c-decc-4a63-8354-47c359e05eba_1456x1158.png 848w, https://substackcdn.com/image/fetch/$s_!Bot1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba1d263c-decc-4a63-8354-47c359e05eba_1456x1158.png 1272w, https://substackcdn.com/image/fetch/$s_!Bot1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba1d263c-decc-4a63-8354-47c359e05eba_1456x1158.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Bot1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba1d263c-decc-4a63-8354-47c359e05eba_1456x1158.png" width="1456" height="1158" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ba1d263c-decc-4a63-8354-47c359e05eba_1456x1158.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1158,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1258321,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://softwareanalyst.substack.com/i/208058321?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba1d263c-decc-4a63-8354-47c359e05eba_1456x1158.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Bot1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba1d263c-decc-4a63-8354-47c359e05eba_1456x1158.png 424w, https://substackcdn.com/image/fetch/$s_!Bot1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba1d263c-decc-4a63-8354-47c359e05eba_1456x1158.png 848w, https://substackcdn.com/image/fetch/$s_!Bot1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba1d263c-decc-4a63-8354-47c359e05eba_1456x1158.png 1272w, https://substackcdn.com/image/fetch/$s_!Bot1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba1d263c-decc-4a63-8354-47c359e05eba_1456x1158.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Market Definition: Endpoint Control and Prevention (ECP)</strong></h2><p>Endpoint Control and Prevention (ECP) is a pivot in endpoint security that reframes endpoint defense as a runtime visibility, operational workflow, and user contextual gap problem. ECP expands endpoint visibility beyond operating systems, files, and processes into developer environments, SaaS applications, AI tools, and agent frameworks. It secures these environments by monitoring the interactions and data flows between users, AI agents, applications, and command-line activities. Next-generation ECP focuses on prevention, enhancing context sharing and user-driven responses across emerging AI, SaaS, and data environments. It focuses on the governance of non-binary software, deeper application-layer execution context (especially for AI and data movement) for better user and agent behavioral characterization or judgement, and machine-speed intent recognition from AI to ameliorate precision action. All of which offers endpoints stronger attribution capabilities, allowing endpoints to transform from more passive detection and response-oriented sensors into more active control planes for the user, AI or agent for prevention, investigation or response actions.</p><p><strong>Strategic Imperative: Transforming Telemetry into Decision Support</strong></p><ol><li><p>Application-layer discovery and posture control for non-binary software (extensions, plugins, models, MCP tooling, configuration risk)</p></li><li><p>Greater application user behavior visibility depth, governance and control by extending policies to the browser and its contextual telemetry.</p></li><li><p>AI Prompt-to-action attribution for agentic systems (what triggered an action, what tools were used, and what happened next)</p></li><li><p>Local semantic inference (often via small local language models SLMs and graph storage) to interpret intent and drive proportional controls and responses autonomously from back-end operations.</p></li></ol><p><strong>The outcome requirement is simple: </strong>Intercept risky flows and sessions before completion, reduce blast radius, and produce evidence that stands up in investigations and governance.</p><p><strong>In scope</strong></p><ul><li><p>Threat detection evolution for AI and local agentics</p></li><li><p>Surgical intervention for lineage, evidence, and governance of users, data, and AI and agents</p></li><li><p>Local application context and extension to non-binary configurations and unmanaged dark matter identities (secrets, certificates and other artifacts)</p></li><li><p>User, Identity and agent telemetry, traceability and data lineage</p></li><li><p>Trusted, zero trust access and software postures above the OS (e.g. visibility and control over local DevOps integrated development environments, IDE plugins, AI agent harnesses/frameworks)</p></li><li><p>Identity and SaaS-mediated execution context (e.g endpoint and SaaS shared telemetry to shift more policy and threat detection from backend to frontend)</p></li></ul><p><strong>Out of scope</strong></p><ul><li><p>Standard EDR feature updates focused on legacy malware, traditional endpoint focused indicators of attack (IOA) or indicators of compromise (IOC) indicators</p></li><li><p>Standalone SIEM or SOAR platforms</p></li><li><p>Network-layer-only controls</p></li><li><p>General XDR bundles that primarily aggregate endpoint detection + response</p></li></ul><h3><strong>Why is Endpoint Security being Re-Written?</strong></h3><p>Endpoint defense is being rewritten because decision points and context that can be derived and used are moving upwards in the stack. Context has taken precedence in a world of dispersed applications and interactions. In the near future, federated context from MCP will contribute significantly to both backend analytics and endpoint security as the threat landscape expands. Classic malware remains a threat, but many incidents now begin with a compromised session, a risky SaaS authentication (OAuth) grant, a compromised API secret, credentials, or a workflow executed legitimately with a stolen identity.</p><p>As adversaries bypass technical controls through credential attacks, session hijacking, and autonomous agent manipulation, the traditional telemetry stack encounters three terminal blind spots:</p><ol><li><p><strong>Invisibility of non-binary software</strong>: Browser extensions, plugins, and local models execute without traditional installations, leaving file-centric EDR blindsided.</p></li><li><p><strong>Deficit in intent and attribution</strong>: EDR tools fail to distinguish between malicious injections and legitimate commands, lacking autonomous oversight and intent assessment.</p></li><li><p><strong>Contextual blindness in execution paths</strong>: Encrypted connections, AI apps, and SaaS environments obscure user and application context from traditional tools.</p></li></ol><p>Nefarious actors can now progress via autonomous AI agents and their delegated toolchains, where the file system becomes more secondary (or irrelevant) to the execution context or location of execution. This means shared context must come from new sources to make better, more localized decisions with enhanced visibility and context on the endpoint, giving security responders faster, real-time prevention, depth for incident response efficiency and enhanced precision. We depict the new evolution in the timeline graphic below.</p><h3>Era Emergence: From EDR to Endpoint Control and Prevention (ECP)</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!L9yE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd71ec970-df34-44cb-81c7-e5f93f6d44cb_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!L9yE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd71ec970-df34-44cb-81c7-e5f93f6d44cb_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!L9yE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd71ec970-df34-44cb-81c7-e5f93f6d44cb_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!L9yE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd71ec970-df34-44cb-81c7-e5f93f6d44cb_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!L9yE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd71ec970-df34-44cb-81c7-e5f93f6d44cb_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!L9yE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd71ec970-df34-44cb-81c7-e5f93f6d44cb_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d71ec970-df34-44cb-81c7-e5f93f6d44cb_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!L9yE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd71ec970-df34-44cb-81c7-e5f93f6d44cb_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!L9yE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd71ec970-df34-44cb-81c7-e5f93f6d44cb_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!L9yE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd71ec970-df34-44cb-81c7-e5f93f6d44cb_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!L9yE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd71ec970-df34-44cb-81c7-e5f93f6d44cb_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Legacy EDR is failing because it targets symptoms and conditions rather than the underlying structural issues or overall execution contexts. By focusing on file system telemetry and process trees, traditional security boundaries miss the strategic shift up-stack to non-binary software, sessions, autonomous workflows and SaaS. ECP resolves this structural blindness by transforming the endpoint into an active control plane that monitors, participates and governs the interaction layer between humans, agents, and data.</p><p>Conceptualizing the evolution of endpoint defense transformation requires transitioning to a framework focused on establishing new architectural layers or zones, leading directly to improvement of endpoint defensive and prevention posture. By integrating advanced visibility and control across these areas, organizations can re-align with contemporary threat landscapes and optimize the use of multi-model context, behavioral intent, and diverse data interactions to drive proactive defensive and prevention-focused decisions.</p><h1><strong>The Eras of Endpoint Security</strong></h1><p>Endpoint security has evolved through three distinct eras, each triggered by the structural failure of the previous architecture.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Itdr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58c53421-8bb4-41ee-9ab3-d6f18f023000_2216x1266.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Itdr!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58c53421-8bb4-41ee-9ab3-d6f18f023000_2216x1266.png 424w, https://substackcdn.com/image/fetch/$s_!Itdr!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58c53421-8bb4-41ee-9ab3-d6f18f023000_2216x1266.png 848w, https://substackcdn.com/image/fetch/$s_!Itdr!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58c53421-8bb4-41ee-9ab3-d6f18f023000_2216x1266.png 1272w, https://substackcdn.com/image/fetch/$s_!Itdr!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58c53421-8bb4-41ee-9ab3-d6f18f023000_2216x1266.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Itdr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58c53421-8bb4-41ee-9ab3-d6f18f023000_2216x1266.png" width="1456" height="832" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/58c53421-8bb4-41ee-9ab3-d6f18f023000_2216x1266.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:832,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:659552,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://softwareanalyst.substack.com/i/208058321?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58c53421-8bb4-41ee-9ab3-d6f18f023000_2216x1266.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Itdr!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58c53421-8bb4-41ee-9ab3-d6f18f023000_2216x1266.png 424w, https://substackcdn.com/image/fetch/$s_!Itdr!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58c53421-8bb4-41ee-9ab3-d6f18f023000_2216x1266.png 848w, https://substackcdn.com/image/fetch/$s_!Itdr!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58c53421-8bb4-41ee-9ab3-d6f18f023000_2216x1266.png 1272w, https://substackcdn.com/image/fetch/$s_!Itdr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58c53421-8bb4-41ee-9ab3-d6f18f023000_2216x1266.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><h2><strong>The Antivirus Era (late 1980s to late 2000s): Protecting the File</strong></h2><p>The first commercial endpoint security products industrialized the idea of maintaining a database of signatures for known malicious files. This worked while malware was a static file, the industry was in a race between virus authors and signature distribution. The model collapsed under the pressure of polymorphic malware and targeted attacks like Operation Aurora (2010), which demonstrated that adversaries could bypass signatures entirely by using bespoke, never-before-seen implants.</p><h2><strong>The EPP Era (late 2000s to mid 2010s): Protecting the Machine</strong></h2><p>The industry&#8217;s first response was to bundle security tools, antivirus, firewalls, and device control into Endpoint Protection Platforms (EPP). While EPP improved prevention, it lacked visibility into what occurred when prevention failed. Breach investigations of the era consistently revealed that intruders remained resident for months, leading to an assume-breach doctrine and the realization that the decisive capability of the EPP era was not blocking malicious files, but rather observing endpoint activity.</p><h2><strong>The EDR Revolution (2011 to the mid 2020s): Protecting the Process</strong></h2><p>Endpoint Detection and Response (EDR) succeeded by recording everything, from process creation, file writes, and registry changes, into a cloud-hosted graph to identify adversary behavior. EDR&#8217;s dominance rested on one foundational architectural assumption: everything that matters on an endpoint executes as a process the kernel can see. As threats migrate up-stack to non-binary software, sessions, and AI agents, this reliance on kernel-level process visibility is reaching its limit, necessitating the shift to Endpoint Control and Prevention (ECP).</p><h2><strong>The ECP Redefinition (2026 through 2030): All we need is Context and Intent</strong></h2><p>The ECP redefinition phase marks a strategic pivot away from reactive process monitoring toward holistic, interaction-centric, SaaS and context-aware governance with user and agent intent awareness. This timeline emphasizes the necessity of newly emerging agentic workloads, managing high-speed autonomous execution, where the endpoint must evolve into an active control plane capable of verifying intent and securing non-binary and user execution contexts in real time.</p><p><strong>Focused on Emergent areas such as:</strong></p><ol><li><p><strong>The Human User (Shadow Builders)</strong></p></li><li><p><strong>AI Agents</strong></p></li><li><p><strong>Agentic Layer</strong></p></li><li><p><strong>Application and Workflow Layer</strong></p></li><li><p><strong>Identity, Session and Artifacts</strong></p></li></ol><p>The rapid proliferation of enterprise AI agents and automated supply chain vulnerabilities has intensified this crisis. Modern adversaries bypass OS-level signatures entirely by injecting malicious tools directly into shadow builder or developer ecosystems and agentic frameworks. These autonomous threats often operate with high-level permissions, independently navigating networks and executing custom, on-the-fly commands or building and executing their own code at machine speed. Recently, attackers have adapted part of their game; since so much net-new AI is being adopted on endpoints, threat actors are now targeting the new AI and agentic software supply chains to execute their nefarious acts.</p><p>Recent supply chain breaches highlight the urgency of securing this non-binary execution context:</p><ul><li><p><strong>PyTorch Lightning PyPI Compromise (April 2026): </strong>Hijacked credentials allowed malicious library versions to harvest and exfiltrate environment secrets via automated CI/CD pipelines.</p></li><li><p><strong>Mercor-LiteLLM Upstream Breach (April 2026): </strong>A compromised routing dependency propagated downstream, exposing sensitive training pipelines and forcing immediate contractor suspensions.</p></li><li><p><strong>NX NPM Breach &amp; Agent Hijacking (August 2025): </strong>Poisoned packages executed locally to hijack active AI tools, systematically hunting and exfiltrating SSH keys and API tokens.</p></li><li><p><strong>Hugging Face Weaponized Models (Ongoing): </strong>Malicious models embed reverse shells within unsafe serialization formats, instantly compromising the host endpoint upon model loading.</p></li></ul><p><strong>Assumption: </strong>AI agents and their arrival with Endpoint harnesses creates a cascade of new demands such as monitoring, assessment of risk, management and control, driving net-new technology adoption in endpoint security. These and the emergence of custom software generated on-demand by AI agents (even apps, scripts and services deployed locally on endpoints) become a new IT standard; legacy endpoint security metrics and even DevOps or DevSecOps metrics will also become obsolete on a standalone basis. One way to think of this is in the Builder Era (where all users become agentic shadow builders), federated development becomes the norm. This strongly shifts the value proposition of endpoint defense decisively from post-incident response to real-time execution control and proactive context governance.</p><p>To defend the modern enterprise, endpoint security must pivot from general user, software, and binary-driven monitoring and acquire higher-order contexts in the stack, helping unify disparate activities on the endpoint for enforcement pre prevention consideration. We need specialized oversight for autonomous agentic systems, integrated SaaS and the context created by users and agents, and visibility and control over the workflows connecting them. In older environments, investigators struggled to tie a user&#8217;s actions to automated agents they triggered. Today, as users increasingly become shadow builders spawning agents, writing and executing code via local chat interfaces and agentic harnesses, these new agents effectively become net-new bots on the internet. This is mandating evolution in adjacent areas (outside endpoint), for example, how we identify bots vs agents online. AI Agents often use similar tools to bot scraping services and other engagement tools that make them overlap with traditional malicious bots, representing the same dynamic and challenge to overcome on the endpoint. Even when operating under a user&#8217;s identity, actions taken by agents require a new forensic perspective and better context for decisions.</p><p>Effective defense now relies on our ability to provide user and agent context and enable rapid context sharing and enforcement mechanisms at machine speed. By adopting this approach, acceleration enables near-instantaneous security decisions, empowering both users and automated monitoring agents and other local sensory software to intervene and halt malicious behaviors the moment they arise. This shift opposes the traditional, slower-moving world of traditional breach-oriented detection and response focused on users or simple administrative functions or scripts (already representing a detection challenge). As enterprises weigh the benefits of control against the need for agility, the industry is moving decisively away from manual human-in-the-loop (HITL) processes and toward automated, proactive control and prevention.</p><p>In today&#8217;s environments, high-consequence actions rarely occur as simple file executions. They happen inside:</p><ul><li><p><strong>Browser Sessions:</strong> Where copilots handle approvals and data movement.</p></li><li><p><strong>The Identity Plane:</strong> Where attackers leverage tokens, OAuth grants, and API keys.</p></li><li><p><strong>Delegated Toolchains and Self-Developed Agent software:</strong> Where agents run scripts, build their own tools on the fly and move data directly.</p></li></ul><p>Historically, Endpoint Detection and Response (EDR) has failed to extend into these specific areas on the device. However, technical shifts, such as machine-speed risks and AI-powered attacks using the advanced capabilities of Mythos, are forcing a faster transition to higher speed, greater context, and prevention prioritized over the EDR detection and response heritage. Organizations that continue to rely solely on traditional detection and response strategies will fail, the landscape is being redefined into one of real-time, active control and prevention-focused defense.</p><h3>Emerging ECP Value Proposition</h3><p>The Endpoint Control and Prevention (ECP) value proposition centers on transforming endpoint defense from a passive, binary-centric sensor into an active control plane capable of governing the modern interaction lifecycle, whether user or agent. By shifting visibility and enforcement up-stack, beyond kernel-level activity and file-based telemetry, ECP restores defender advantage in an era of AI-driven, machine-speed attacks. It bridges the gap between legacy detection and the reality of autonomous workflows, providing the contextual evidence and granular, real-time intervention primitives needed to secure the critical flow between humans, identities, agents, and SaaS applications.</p><h3><strong>Critical Endpoint Control and Prevention Layers</strong></h3><ul><li><p><strong>OS and Kernel (classic EDR center of gravity):</strong> This layer represents the traditional foundation of endpoint security, focusing on low-level system activity and kernel-mode monitoring to identify malicious behavior at the hardware-software interface.</p></li><li><p><strong>Process, file and memory (EDR telemetry &amp; response primitives):</strong> These core primitives enable the detection of legacy file-based threats and post-incident reconstruction by analyzing how processes interact with the file system and system memory.</p></li><li><p><strong>Identity and session artifacts (tokens, OAuth, browser auth, session abuse):</strong> In ECP, visibility and context extend to the identity plane to protect against session hijacking and the theft of cryptographic artifacts in real time, at runtime: for example, tokens and API keys used in SaaS-mediated workflows.</p></li><li><p><strong>App &amp; workflow layer (browser actions, SaaS actions, agent tool calls):</strong> Endpoint defense now necessitates runtime observability at the application layer, governing non-binary software such as browser extensions and IDE plugins where critical modern execution context resides, but is often not shared.</p></li><li><p><strong>Agentic prompt-to-action layer (prompt, tool, action traceability):</strong> This critical new layer provides full attribution for autonomous systems, linking natural language prompts to specific tool invocations and downstream actions to ensure governability at machine speed.</p></li></ul><h2>Endpoint and End-User Organization Trends Enabling the Shift</h2><p>Modern end-user organizations are driving the shift toward Endpoint Control and Prevention (ECP) as traditional security perimeters dissolve. With the rise of hybrid work and the proliferation of &#8220;shadow builders&#8221;, which are often non-technical staff deploying custom AI-driven application development, workflows and SaaS applications. The endpoint attack surface has expanded beyond legacy and more stable binary and process-centric threats. To address these complex risks, organizations are prioritizing comprehensive visibility into application-layer interactions and autonomous agentic behaviors, necessitating a move toward granular, real-time control.</p><ul><li><p><strong>Broad adoption of hybrid working and the rise of Shadow AI and Shadow Builders: </strong>The emergence of shadow builders and Shadow AI both represent a significant market driver for ECP, as non-technical staff increasingly use low-code and no-code AI agent frameworks tools and AI plugins to assemble automated tools and workflows. This decentralized development creates new third-party supply chain models directly on the endpoints or inside designated harness infrastructure for agents, necessitating visibility into non-binary software linked to browser sessions, extensions, and IDE plugins.</p></li><li><p><strong>Instrumentation is shifting down-stack while risk shifts up-stack.</strong> Kernel and eBPF-era telemetry improves what happens, but the differentiator is increasingly interpreting and governing what runs above the OS (extensions, plugins, packages, models, MCP tools and shadow supply chains).</p></li><li><p><strong>Shadow builder risks are now a first-class endpoint problem.</strong> Since non-developer users and teams can now assemble powerful workflows, build net new applications and deploy plugins and AI tools, security needs visibility into all of this new installable software, its permissions, composition risk, configuration and communications, which are no longer limited to just malware-style OS level indicators.</p></li><li><p><strong>Deep Posture Assessment and Identity Awareness are emerging.</strong> As per-endpoint detection commoditizes, budget and evaluation energy move to application posture, attribution depth, and real-time intervention primitives (warn/block/guide) that reduce blast radius.</p></li></ul><h2><strong>Operational Reality: Aligning Defense with Machine Speed</strong></h2><p>We have entered the age of Mythos, which is an era defined by the industrialization of vulnerability exploitation at machine speeds. Automated models are compressing the time required to weaponize software flaws from weeks to ~seconds. With the emergence of models like Mythos and open-source frameworks like GLM 5.2, the cybersecurity landscape has transitioned into a high-speed race to automate both AI vulnerability discovery and remediation via threat management processes. This evolution renders traditional, manual patch cycles obsolete, forcing a strategic pivot toward continuous, autonomous prevention engineering and retooling of the flows of data and context across security systems more generally.</p><p>The failure of legacy defense stems from a structural misalignment with how work actually occurs:</p><ul><li><p><strong>Execution has shifted from local binaries to SaaS-mediated workflows:</strong> Security telemetry cannot stop at the file system or process tree when the action and critical context occur in browser sessions, SaaS and API calls.</p></li><li><p><strong>Identity is still a primary chokepoint:</strong> Tokens, OAuth grants, and session artifacts like cookies or authentication bits are the new crown jewels, and their abuse is a primary vector for modern compromise.</p></li><li><p><strong>Non-binary attack surfaces are expanding:</strong> The real risk resides in extensions, IDE plugins, and agentic configurations that mutate daily; a compositional, use- driven attack surface can bypass legacy signature-based scanning.</p></li><li><p><strong>Autonomy has changed the unit of risk:</strong> We have moved from a user running a process to an agentic toolchain executing a workflow. These actions occur at machine speed, rendering human-in-the-loop triage a strategic bottleneck.</p></li><li><p><strong>MTTR requirements have collapsed:</strong> Cloud-backend analytics loops cannot keep pace with agentic misuse. Defensive logic must shift right to the endpoint runtime.</p></li></ul><h3><strong>The Strategic Imperative: Securing the AI and Agentic Layer</strong></h3><p>Modern ECP architectures require deep visibility into the non-deterministic nature of local agentic infrastructures, including IDE copilots, local AI runtimes, and MCP-integrated toolchains. Governance must extend to the prompt-to-action trace to ensure full context, lineage, and verifiability for autonomous systems. Defenders must ensure that actions taken by local agents against remote APIs or SaaS platforms are properly contextualized, mediated, attributed, as well as mapping out what triggered an action, what tools were used, and what happened next. These are very important aspects of monitoring context to drive enhanced endpoint prevention and behavioral response decisions.</p><h3><strong>Small Language Models (SLMs) Arrive on the Endpoint</strong></h3><p>The transition toward AI PCs and Minis, along with an increase in shadow builders (unauthorized) or authorized users setting up local agent harnesses, is accelerating the need for deployment of local models, bringing agentic benefits to endpoint security. This development empowers local AI models and agents specialized in Endpoint Security to manage scaling agentic telemetry and localized or remote context, circumventing the cloud-pipeline expenses, latency, and contextual issues inherent in current setups.</p><p>Traditional, EDR-centric protection models are proving inadequate for modern defenders. In this report, SACR highlights a necessary paradigm shift: migrating full-stack context and security logic directly to the device. By leveraging local agents (Endpoint Defense Agents), Small Language Models (SLMs), and local graph databases, systems can achieve semantic and behavioral insight to improve threat prevention. This architecture facilitates instantaneous enforcement, circumventing the delayed, cloud-reliant detection pipelines characteristic of legacy EDR/XDR vendors that depend on central storage backends.</p><h3><strong>Endpoint Defense Agents Rise</strong></h3><p>Moving agentic inference onto the Endpoint hardware redefines the threat landscape, where local inference risks, data lineage and attribution emerge as the primary detection hurdles. Rather than simply evaluating if a process is malicious, defenders must identify the specific user, agent, workflow or tool and identify errant or malicious prompts that initiated an activity, confirming if it aligned with user intent. This establishes prompt, user and agent action lineage as the modern extension of threat detection from the traditional process tree.</p><h3><strong>Adaptive and Predictive Prevention Becomes the New Goal</strong></h3><p>Cloud-backend analytics and context enrichment loops can no longer keep pace with AI and agentic misuse, causing traditional MTTR requirements to collapse and forcing defensive logic to shift right to the endpoint runtime. Moving endpoint defense beyond traditional process and file centricity, this approach rejects standard signature or rules-based logic in favor of probabilistic, anomaly-based detection driven by local semantic inference. Endpoint security systems must evolve into proactive, predictive prevention engines and contextual sharing architectures. By leveraging expansions and preemptive modeling of advanced context, behavioral modeling and intent awareness of both user and agent, endpoints can enhance and anticipate agent-driven threats before they fully manifest, achieving millisecond-level mean time to response (MTTR). This proactive stance supports a self-healing zero-trust model, where the endpoint facilitates faithful action execution while continuously reducing the attack surface. By executing defensive logic directly at runtime via local SLMs, the endpoint can interpret user and agent intent to intercept risky or non-deterministic workflows at machine speed before any malicious intent can fully execute.</p><h3><strong>7 Critical Endpoint Control Moment Pillars Important for ECP</strong></h3><p>To effectively govern modern autonomous workflows and minimize the blast radius of agentic toolchains, security teams must embed defensive logic across the entire interaction lifecycle. Shifting to Endpoint Control and Prevention (ECP) requires moving beyond reactive, post-execution detection to establish high-fidelity visibility at each stage of the workflow.</p><p>The following pillars identify the critical control moments where ECP architectures must intervene to ensure policy adherence, verify intent, and mitigate risk before an action completes.</p><p><strong>Endpoint Security Enforcement Control Moments</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xPWW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01294ec2-ed2b-409f-b01e-342f1792fcf9_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xPWW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01294ec2-ed2b-409f-b01e-342f1792fcf9_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!xPWW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01294ec2-ed2b-409f-b01e-342f1792fcf9_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!xPWW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01294ec2-ed2b-409f-b01e-342f1792fcf9_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!xPWW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01294ec2-ed2b-409f-b01e-342f1792fcf9_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xPWW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01294ec2-ed2b-409f-b01e-342f1792fcf9_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/01294ec2-ed2b-409f-b01e-342f1792fcf9_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!xPWW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01294ec2-ed2b-409f-b01e-342f1792fcf9_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!xPWW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01294ec2-ed2b-409f-b01e-342f1792fcf9_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!xPWW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01294ec2-ed2b-409f-b01e-342f1792fcf9_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!xPWW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01294ec2-ed2b-409f-b01e-342f1792fcf9_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><ol><li><p><strong>Before Installation (Pre-deploy gate): </strong>Focuses on proactive curation of the software supply chain to neutralize threats before they manifest on the device. By treating the endpoint similarly to an app store, this phase discovers and risk-ranks non-binary software components, such as browser extensions, IDE plugins, MCP servers, packages, and local models, ensuring configuration hygiene and preventing unauthorized dependencies from landing on the machine.</p></li><li><p><strong>Before Action Completes: </strong>Involves gating risky behaviors, dangerous tool calls, or unauthorized data sharing mid-flow. Instead of relying on disruptive post-execution process termination, this control point uses inline, flow-level session evaluation to intercept actions at machine speed before they can fully complete.</p></li><li><p><strong>During &amp; After Execution: </strong>Builds runtime observability and behavioral baselines above the operating system layer. It continuously monitors active interactions, including natural language prompts, shell commands, tool execution, and network activity, using local semantic inference to detect intent-level anomalies and maintain complete forensic traceability.</p></li><li><p><strong>Context Enrichment (Environmental Signal): </strong>Integrates deep identity plane and environmental telemetry, such as active session states, cryptographic tokens, OAuth grants, and API keys. This shared context connects endpoint activity directly to SaaS-mediated execution paths, providing the multi-layer visibility needed for continuous trust validation.</p></li><li><p><strong>Data Understanding (Semantic Layer): </strong>Leverages on-device AI models and local small language models (SLMs) to interpret the natural language context of prompts and workflows. Shifting from rigid pattern-matching rules to probabilistic inference, this layer evaluates user and agent motivations to recognize risky prompt injection or unauthorized orchestration before execution.</p></li><li><p><strong>At the Moment Data Moves: </strong>Monitors and intercepts sensitive data flows at critical interaction points, such as clipboard paste, file downloads, or model prompt submissions. By performing local AI classification directly at the endpoint edge, it successfully inspects cert-pinned or SASE-bypassed traffic that network proxies miss.</p></li><li><p><strong>Final Policy Decisioning: </strong>Evaluates the combined signals of intent, posture, identity, and data behavior against organizational security rules to drive real-time, graduated interventions. Rather than defaulting to binary allow-or-block decisions, it enables proportional enforcement primitives such as surgical inline redaction, warnings, or context-aware user coaching.</p></li></ol><h1><strong>SACR Security Zones for Endpoint Control and Prevention (ECP)</strong></h1><p>To evolve new use cases across the control moments pillars, we see emerging technology concepts and vendors evolving endpoint defense in several key emerging zones of technology and use case expansion, which requires transitioning from legacy, process-centric models to a robust architectural framework of ECP security zones. These zones serve as the blueprint for securing the modern, autonomous workflow by establishing high-fidelity visibility and control at the critical layers where risk now resides. By mapping defenses to these five distinct evolutionary focus areas, security teams can move beyond reactive detection, enabling proactive governance of user, agent, and data interactions at machine speed.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_piH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c4417c9-0129-4b24-8808-4bb2f116a00c_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_piH!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c4417c9-0129-4b24-8808-4bb2f116a00c_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!_piH!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c4417c9-0129-4b24-8808-4bb2f116a00c_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!_piH!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c4417c9-0129-4b24-8808-4bb2f116a00c_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!_piH!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c4417c9-0129-4b24-8808-4bb2f116a00c_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_piH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c4417c9-0129-4b24-8808-4bb2f116a00c_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4c4417c9-0129-4b24-8808-4bb2f116a00c_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!_piH!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c4417c9-0129-4b24-8808-4bb2f116a00c_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!_piH!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c4417c9-0129-4b24-8808-4bb2f116a00c_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!_piH!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c4417c9-0129-4b24-8808-4bb2f116a00c_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!_piH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c4417c9-0129-4b24-8808-4bb2f116a00c_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Zone 1: Software Posture &amp; Governance</h2><p><strong>Concept: </strong>By treating the endpoint similarly to an app store, this layer controls the ingestion of various software components such as extensions, MCP servers, packages, models, and containers. Proactive curation of the software supply chain neutralizes incidents before they manifest by maintaining an active inventory and comprehensive posture assessment.</p><p><strong>Operational Pillar</strong></p><p>Shifts endpoint defense from reactive binary signature matching to proactive continuous governance of the non-binary software composition layer. This involves discovery and continuous risk-ranking of browser extensions, IDE plugins, and local model frameworks to establish an active inventory and continuous posture assessment above the operating system layer.</p><p>By treating the endpoint similarly to an app store, this layer controls the ingestion of various software components such as extensions, MCP servers, packages, models, and containers. The foundational premise is that because the vast majority of AI risk is acquired, proactive curation of the software supply chain can neutralize incidents before they ever manifest. Referenced as Endpoint Application Posture Management (EAPM) within SACR advisory frameworks and as a critical feature of ECP expansion, this paradigm and concept marks a strategic resurgence of classic OS oriented posture and control application control and configuration assessment with renewed focus on endpoint and agentic applications and supply chains.</p><p>While traditional allowlisting was historically constrained by operational overhead, intensive manual fine-tuning, and rapid policy challenges, AI completely redefines this resource-heavy dynamic. By deploying automated fleets of specialized agents, organizations can continuously analyze software behaviors and dynamically maintain allowlists at machine speed. Enforcement within this zone shifts the primary security discipline away from reactive detection engineering toward proactive policy engineering. It treats platforms as first-class citizens where configuration liabilities, such as a Claude instance, for example, with dangerous permissions enabled, are surfaced as high-severity posture anomalies rather than traditional malware events. The ultimate goal is to sustain an active inventory and comprehensive posture assessment of all non-binary dependencies functioning above the operating system layer, verifying configuration hygiene, access permissions, and the intricate workflows generated by shadow builders using AI agents before any malicious intent can execute.</p><h2>Zone 2: Application Layer Enforcement</h2><p><strong>Concept: </strong>Sits at the interface between native apps and AI agents, governing layers like browser extensions, developer packages, MCP servers, and AI agent toolchains. It blocks dangerous tool-calls mid-flow or potentially risky data sharing without killing the session.</p><p><strong>Operational Pillar</strong></p><p>Enforce inline gating and session evaluation mid-flow to block dangerous tool calls or data sharing before completion, replacing disruptive process termination with surgical intervention embedded directly within the active workflow layer.</p><p>Sits at the interface between native apps and AI agents, governing layers like browser extensions, developer packages, MCP servers, and AI agent toolchains. It blocks the dangerous tool-call mid-flow or potentially risky data sharing without killing the session. The core bet is that at machine speed, where autonomous agents read natural language instructions, execute shell commands, edit files, and call APIs at a speed no human could perform or anticipate, traditional detection-and-response is operationally and structurally too late, and therefore must evolve to keep pace with emerging risks.</p><p>The rising prevention-first approach mandates that actions be gated using inline, flow-level, session evaluation, or data-layer enforcement before tool calls can fully complete. This strategy successfully replaces disruptive process termination with a more precise, surgical intervention embedded directly within the active workflow layer. Vendors in AI are hard at work continuously modeling both AI interactions to preemptively identify attacks while also expanding their ability to monitor deep workflows, and as DNS for Agents emerges in DNS land, most organizations still lack methods for executing more complex multi-layer agentic workflow recording and intercede. Traditional tools cannot block potentially harmful actions on both Application AI agents and their workflows together as a continuum, where the evaluation of intent and outcome behavioral analysis focuses on precision prevention.</p><h2>Zone 3: Agent Runtime Visibility (AI-EDR)</h2><p><strong>Concept: </strong>This architectural layer builds its own above-OS telemetry and baselines of why actors behave as they do, rejecting standard signature or rules-based EDR logic in favor of probabilistic, anomaly-based detection driven by local semantic inference.</p><p><strong>Operational Pillar</strong></p><p>Provides full context and verifiability for autonomous systems by establishing absolute traceability from natural language prompts to downstream execution steps, tool calls, and system responses. It reframes the endpoint as an identity-centric control plane evaluating intent to mitigate credential theft and session hijacking through continuous identity-state validation and active blast-radius reduction.</p><p>This architectural layer builds its own above-OS telemetry and baselines of why actors behave as they do, shifting endpoint defense beyond traditional process and file centricity. It rejects standard signature or rules-based EDR logic in favor of probabilistic, anomaly-based detection driven by local semantic inference. The underlying bet is that novel AI-era attacks are anomalies of intent, making them invisible to both legacy signatures and passive posture scans. By executing defensive logic directly at the endpoint runtime using small language models (SLMs), it interprets user and agent intent to intercept risky or non-deterministic workflows at machine speed before a malicious action can fully manifest.</p><h2>Zone 4: Intent-Aware Behavioral Analysis</h2><p><strong>Concept: </strong>Shifts endpoint control from passive file or process monitoring to active assessment of user and agent intent. This layer validates the behavioral risk profile of AI-driven interactions by correlating actions with their underlying intent. It ensures that autonomous agent activity and human-initiated commands are continuously evaluated against security policy in real-time, effectively neutralizing risks like malicious prompt hijacking, unauthorized agent orchestration, and anomalous workflow execution.</p><p><strong>Operational Pillar: </strong>Deploys granular, intent-aware enforcement gates that provide real-time, behavioral guardrails rather than static blocking. By integrating surgical user coaching and inline friction directly into the interaction flow, this mechanism replaces binary, disruptive termination with adaptive, intent-aligned guidance that secures the workflow while maintaining productivity.</p><p>Anchors on intent and behavioral context, rather than just the file or software artifact. The core bet is that you cannot judge whether an AI-driven action is dangerous unless you understand the motivation behind it and the behavior it exhibits. This intent-anchored layer evaluates the risk of an action based entirely on its behavioral trajectory and alignment with authenticated user or agent intent, providing the control plane for mitigating autonomous misuse, shadow agent orchestration, and workflow manipulation. Rather than relying on rigid rules, next-generation architectures in this zone utilize local intent inference to issue pre-action verdicts at the point of interaction.</p><h2>Zone 5: Data-Centric Enforcement</h2><p><strong>Concept: </strong>Sits at the data itself, classifying, tracing, and intercepting sensitive data movement at the moment of creation, use, or exfiltration across the endpoint, browser, and SaaS/API plane.</p><p><strong>Operational Pillar</strong></p><p>Anchors on the data object and its lineage to achieve convergence with DSPM and insider risk platforms, employing on-device AI classification at the endpoint edge to handle cert-pinned or SASE-bypassed traffic directly.</p><p>Sits at the data itself, classifying, tracing, and intercepting sensitive data movement at the moment of creation, use, or exfiltration across the endpoint, browser, and SaaS/API plane. The hypothesis: one cannot govern AI-era risk without understanding what data was touched, by whom, through what workflow, and whether that movement was authorized. Unlike Zones 1&#8211;4, which focus on software posture, attribution, behavior, or browser enforcement, Zone 5 anchors on the data object and its lineage, making it the natural control plane for insider risk, AI prompt leakage, shadow builder exfiltration, and supply chain data theft.</p><p><strong>What distinguishes Zone 5 from legacy DLP:</strong> Classic DLP relied on static policy rules, perimeter chokepoints, and pattern matching, generating ~90% false-positive rates and high operational burden. Next-gen Zone 5 vendors replace policy brittleness with local AI classification, context-aware intent inference, and coaching-first enforcement that reduces noise and preserves workflow continuity.</p><h1><strong>Market Landscape</strong></h1><h2><strong>The Market Landscape: Decoupling ECP from Legacy EDR</strong></h2><p>The shift toward Endpoint Control and Prevention (ECP) signifies a fundamental decoupling of endpoint security from the constraints of legacy, process-tree-based detection models. As traditional security perimeters dissolve into dynamic, SaaS-mediated execution environments and autonomous agentic workflows, the market for defense is rapidly evolving. To address this complexity, the vendor landscape has begun to fragment, coalescing around three distinct strategic notable motions:</p><ul><li><p><strong>Software Posture &amp; Supply-Chain Governance:</strong> Treating the endpoint as an app store. Prioritizing the discovery and configuration risk-ranking of extensions, IDE plugins, and agentic toolchains rather than binary malware.</p></li><li><p><strong>Intent-Aware Observation &amp; Semantic Defense:</strong> Moving beyond <em>what</em> a process did to <em>why </em>a process occurred. <strong>Ent</strong> and <strong>Origin HQ</strong> provide high-fidelity telemetry that maps prompt-to-action, establishing the forensic evidence chains required for governance.</p></li><li><p><strong>App-Layer Enforcement &amp; Browser-Centric Control:</strong> Leveraging the browser as the primary control surface. Vendors like <strong>Neo Security</strong> and <strong>Cyberhaven</strong> move enforcement directly into the execution context (the browser or app), enabling surgical warn/block/guide interventions without the latency of kernel-level processing.</p></li></ul><h2><strong>Emerging Players in Endpoint Control and Prevention (ECP)</strong></h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!TUQX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1359b3e1-f848-4781-8264-7a2077e26a4b_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!TUQX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1359b3e1-f848-4781-8264-7a2077e26a4b_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!TUQX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1359b3e1-f848-4781-8264-7a2077e26a4b_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!TUQX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1359b3e1-f848-4781-8264-7a2077e26a4b_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!TUQX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1359b3e1-f848-4781-8264-7a2077e26a4b_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!TUQX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1359b3e1-f848-4781-8264-7a2077e26a4b_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1359b3e1-f848-4781-8264-7a2077e26a4b_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1308714,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://softwareanalyst.substack.com/i/208058321?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1359b3e1-f848-4781-8264-7a2077e26a4b_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!TUQX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1359b3e1-f848-4781-8264-7a2077e26a4b_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!TUQX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1359b3e1-f848-4781-8264-7a2077e26a4b_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!TUQX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1359b3e1-f848-4781-8264-7a2077e26a4b_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!TUQX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1359b3e1-f848-4781-8264-7a2077e26a4b_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Source: SACR Briefings 2026 (Sampling of Notable Vendors)</p><h3><strong>Agentless vs. Agent-Based Trade-offs</strong></h3><p>The deployment debate has persisted for decades, with many buyers rightfully wary of the systemic stability risks inherent in legacy kernel-integrated drivers, most notably the catastrophic Blue Screen of Death (BSOD) events. While the adoption of Extended Berkeley Packet Filter (eBPF) technology has significantly neutralized these driver-conflict anxieties, a strategic appetite for agentless architectures remains. The primary driver for agentless adoption is the elimination of net-new software footprints, allowing organizations to achieve specialized outcomes, such as advanced forensic depth, novel data correlation, or unique AI-driven inference, without the operational friction of traditional sensor management. Whether delivered via API integration or cloud-mediated browser plugins, endpoint harnesses, or agentless solutions, they might provide the surgical, complementary telemetry required to bridge functional gaps without duplicating the existing endpoint protection stack.</p><h3><strong>Agentless Deployment Performance Claims May be Misleading</strong></h3><p>The value proposition of agentless deployment includes that they ensure zero performance degradation, which isn&#8217;t entirely true. If a vendor solution hits customer API rate limits, or maybe query maximums, the solution may have significant gaps in data freshness and quality, leading to potentially poor alignment to detections or lack of the latest functionality releases. But on the endpoint, in some cases agentless solutions can significantly augment the current endpoint software&#8217;s use cases, either delivering new telemetry, data science or machine learning approaches of their own to a complementary endpoint protection tool. The primary drivers for adoption of agentless is for a customer to avoid net-new software or processes deployed, thereby optimizing endpoint battery life, and in the eyes of many buyers, the overall user experience.</p><h3><strong>Rapid Deployment and Scaling</strong></h3><p>Agentless solutions facilitate instantaneous deployment, typically requiring only a service account, an application API key, or standard credentials. Scalability is achieved seamlessly without necessitating reboots or software installations. Centralized control mechanisms of agentless solutions can sometimes simplify management, particularly for platforms utilizing differentiated or advanced reporting or offering analytic graph interfaces that incumbents aren&#8217;t providing out of the box. By minimizing the local attack surface, agentless options, if used to unify datasets and operations, help somewhat strengthen an organization&#8217;s security posture while maintaining compatibility and lowering the total cost of ownership (TCO). This aligns with a broader cybersecurity trend where specialized vendors integrate synergistically with existing infrastructures to deliver enhanced capabilities, such as data enrichment, advanced workflows, and deep analytical graphing.</p><h3>Vendor Use Case Limitations and Dependency Issues</h3><p>Agentless architectures present clear operational constraints. Chief among these are reduced context and visibility stemming from a lack of their own, controlled local file system access, drivers, or parsing engines, which can hinder deeper forensic investigations, delivery of new functionality, use cases or performance while they also remain fundamentally dependent on the capabilities and rate limits of provided APIs. Reliance on network connectivity introduces latency risks and potentially restricts real-time response actions when local remediation alternatives are absent. Organizations should implement a hybrid defense model with preference towards agent-based solutions where possible for the lowest latency of endpoint defensive measures. In some situations, customers of endpoint software might want agentless monitoring for high-performance locations or IoT environments that have limited processing capacity, where agentless may be more ideal, while deploying agent-based ECP solutions across critical endpoints that demand comprehensive file inspection and immediate, machine-speed containment and prevention capabilities.</p><h1><strong>Vendor Profiles</strong></h1><p>(by Primary ECP Expansion Zone)</p><h1>Zone 1: Software Posture &amp; Governance</h1><h3><strong>Bloom Security</strong></h3><h4>Vendor Profile</h4><p>Bloom Security is an endpoint security company with Zone 1-3 coverage of the ECP market, delivering visibility, context, and control across the AI-native endpoint. It offers a hybrid AI-native endpoint security platform with selectable deployment options (agent and agentless), including a user-mode endpoint agent, supply-chain firewall, remediation, runtime guardrails, and policy enforcement. Bloom enables security teams to govern the modern workstation: what runs on it, how it&#8217;s configured, and whether it&#8217;s appropriate for the user and environment it operates in. Its approach is preventive, establishing governance at the workstation level before the conditions for incidents are created.</p><p>Bloom continuously discovers everything running across the fleet: AI agents, extensions, IDE plugins, MCP servers, packages, and CLI tools. It evaluates each asset and its configuration in context: who is running it, what data it can reach, and what else is installed alongside it. The same setup can be low-risk on one workstation and high-risk on another.</p><p>Bloom then acts on that context, enabling blocking of malicious or high-risk software before it installs, remediating dangerous configurations in place, setting runtime guardrails on what AI agents can access and execute, and enforcing policy continuously. <br>When enforcement happens, employees are told why, shown approved alternatives, and educated in the moment.</p><p><strong>Applicable ECP Zones:</strong></p><ul><li><p><strong>Zone 1</strong></p></li><li><p><strong>Zone 2</strong></p></li><li><p><strong>Zone 3</strong></p></li></ul><h4><strong>Products/Services Overview</strong></h4><p><strong>Bloom Platform:</strong> AI-native endpoint security platform that gives security teams complete visibility and control over the AI-native endpoint: what runs on it, how it&#8217;s configured, and how policy is enforced, without manual workflows or employee disruption. Bloom covers the full security cycle, from continuous discovery and contextual risk evaluation through direct enforcement and remediation, in a single platform.</p><h4><strong>Core Functions</strong></h4><ul><li><p><strong>Discovery and Inventory: </strong>Continuously maps every AI agent, extension, plugin, MCP server, package, and CLI running across the fleet in real time</p></li><li><p><strong>Software Risk Analysis: </strong>Evaluates each through marketplace intelligence, static code analysis, and behavioral sandboxing to determine what it can do, what it can reach, and how it behaves</p></li><li><p><strong>Configuration and Context Analysis: </strong>Evaluates each against the workstation it runs on: the user&#8217;s role, their data access, and what else is installed alongside. The same setup can be low-risk on one workstation and high-risk on another.</p></li><li><p><strong>Install Prevention: </strong>Intercepts compromised or malicious components upstream via the Supply Chain Firewall before they reach the endpoint, and enforces installation policy continuously across the fleet</p></li><li><p><strong>Agentic Runtime Governance:</strong> Sets and enforces guardrails on what AI agents can access, execute, and connect to while running, scaling back over-permissioned configurations to safe defaults automatically</p></li></ul><h4><strong>Use Cases and Pain Points Addressed</strong></h4><ol><li><p><strong>Endpoint Policy Enforcement: </strong>Bloom enforces precise, context-aware policy automatically, blocking risky installs and fixing configurations without manual review or employee friction.</p></li><li><p><strong>AI Governance and Usage Control: </strong>Bloom enables security teams to govern how every AI tool, extension, and agent operates across the fleet: approved configurations, access boundaries, and usage policies per user and workstation</p></li><li><p><strong>AI Supply Chain Security: </strong>Bloom&#8217;s Supply Chain Firewall monitors and intercepts marketplace traffic in real time, blocking compromised packages, malicious extensions, and backdoored MCP servers before they reach the endpoint. Bloom&#8217;s in-house research team surfaces findings before public disclosure, so customers are always protected first.</p></li></ol><h3><strong>Key Takeaway / Recommendation</strong></h3><p>Bloom is the recommended first investment for enterprises securing the AI-native endpoint. Bloom&#8217;s preventive approach creates the foundation that detection and enforcement in higher zones depend on: establishing what runs across the fleet, how it&#8217;s configured, and whether it&#8217;s appropriate, before incidents occur. Bloom stands out by combining contextual risk evaluation, precise enforcement, and direct remediation in a single platform, with an approach to employee communication that addresses the productivity concern most security teams struggle to overcome. </p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><h1>Zone 2: Application Layer Enforcement</h1><h2><strong>Neo Security</strong></h2><h3>Vendor Profile</h3><p>Neo Security is a Zone 1+2+3 Application Layer Enforcement vendor delivering lightweight, user-mode endpoint and browser security for AI-era threats. Neo offers a 3-stage control flow: Discover all software and define what should be allowed to run, fix any configuration and posture issues of that software and enforce deterministic runtime guardrails on it. Neo&#8217;s architecture combines a fast (~30-second) initial scanner with a persistent user-mode in-application sensor that instruments browser, office and IDE extensions as well as conducts agentic harness-level monitoring. Neo feeds an agentic backend that reverse-engineers the software characteristics and produces the expected &#8220;good&#8221; posture and behavior at runtime. Unlike kernel-mode EDR, Neo&#8217;s user-mode sensor carries zero kernel stability risk while still capturing high-fidelity application-layer telemetry covering extensions, plugins, libraries, MCP servers, skills, and LLM. Every interaction is attributed to the agent, model, or human that caused it, giving SecOps teams full prompt-to-action traceability for every agentic interaction. The critical architectural differentiator is flow-level enforcement: Neo starts with static and posture gates and then also monitors for potentially dangerous tool calls <em>before</em> they execute, not after the fact. This inline enforcement model at the point of API call or tool invocation, rather than at process creation, is specifically designed for the agentic workflow threat model, where machine-speed execution renders post-hook detection operationally irrelevant. Enforcement happens on device, and doesn&#8217;t require any sensitive data to leave the machine, given the sensor-based architecture. Neo requires no MDM, kernel module, or proxy, and supports IdP integration to complete the endpoint + tool + identity picture, rather than requiring it. Neo&#8217;s enforcement scope spans extensions, binaries, plugins, MCPs, skills, and LLMs, making it broadly applicable across shadow builder, agentic workflow, and developer toolchain use cases.</p><p><strong>Applicable ECP Zones:</strong></p><ul><li><p><strong>Zone 1</strong></p></li><li><p><strong>Zone 2</strong></p></li><li><p><strong>Zone 3<br><br></strong></p></li></ul><h3><strong>Products/Services Overview</strong></h3><ul><li><p><strong>Neo Scanner:</strong> Lightweight ~30-second initial scan of endpoint software inventory covering extensions, plugins, MCP servers, and AI toolchains</p></li><li><p><strong>User-Mode In-App Sensor:</strong> Persistent application-layer sensor for browser, IDE and office environments providing static monitoring and real-time telemetry and enforcement.</p></li><li><p><strong>Agentic Backend:</strong> A continually updated repository of agentic app analysis intelligence</p></li><li><p><strong>Flow-Level Enforcement:</strong> Inline enforcement layer that gates which extensions can be loaded, which binaries can be executed, and what tool calls, API invocations, and LLM interactions are allowed before execution.</p></li><li><p><strong>Agentic Copilot:</strong> A designated SOC, GRC and IT personas that fully automate any activity, research and policy creation over the Neo Platform.</p></li></ul><h3><strong>Core Functions</strong></h3><ul><li><p><strong>User-Mode Application Instrumentation:</strong> Instruments browser extensions, IDE plugins, and MCP servers at the user-mode application layer without kernel drivers or proxies, eliminating stability risk.</p></li><li><p><strong>Monitoring:</strong> Monitors all AI activity, including network activity like MCP calls, LLM communications, authentication and other API calls from the application itself (the harness, the browser, the IDE, etc).</p></li><li><p><strong>Flow-Level Pre-Completion Enforcement:</strong> Intercepts and evaluates tool calls, API invocations, and agentic actions before they complete, enabling inline block/warn/guide decisions at machine speed.</p></li><li><p><strong>Agentic Software Reverse-Engineering:</strong> Backend behavioral analysis engine models the risk profile of newly encountered extensions, plugins, and AI tools by reverse-engineering their runtime behavior.</p></li><li><p><strong>IdP-Only Deployment:</strong> Full enforcement capability requires only an IdP integration (no kernel module, MDM dependency, or proxy deployment), minimizing enterprise deployment friction. Other integrations are supported for enrichments but not required.</p></li></ul><h3><strong>Use Cases and Pain Points Addressed</strong></h3><ol><li><p><strong>Agentic Conversation and Tool Call Interception:</strong> Full visibility into the agentic sessions. Neo blocks or gates dangerous tool invocations (e.g., a compromised MCP server calling a file exfiltration API) before the action is executed.</p></li><li><p><strong>Browser, Office and IDE Extension Governance:</strong> Provides continuous monitoring and enforcement for extensions and plugins, surfacing over-permissioned or malicious components and blocking unauthorized actions.</p></li><li><p><strong>Binary control: </strong>Control over which binaries should be able to run on the system, and which software should be installed to begin with (uninstall).</p></li><li><p><strong>LLM and MCP Server Runtime Security:</strong> Monitors and gates interactions between enterprise users, AI models, and MCP-connected toolchains in real time.</p></li></ol><h3><strong>Key Takeaway / Recommendation</strong></h3><p>Neo Security is the leading purpose-built Zone 1-3 enforcement-focused vendor, providing comprehensive control across the entire endpoint spanning binary and non-binary assets, as well as agentic and non-agentic software. It enables organizations to prioritize flow-level, pre-execution interception of tool calls and actions. Its IdP deployment model and user-mode architecture make it the lowest-friction path to genuine inline enforcement, not just posture visibility, for enterprises adopting AI agents and MCP-connected toolchains. CISOs should evaluate Neo as the primary enforcement layer in a Zone 1, Zone 2 and Zone 3 (enforcement-focused) stack. The key due diligence question is enforcement fidelity under high-volume agentic workloads: validate that Neo&#8217;s flow-level interception operates at the latency and throughput required for production agentic environments without introducing workflow-breaking delays.</p><h2><strong>Pluto Security</strong></h2><h3>Vendor Profile</h3><p>Pluto Security is a fully agentless AI workspace security platform occupying Zones 1-3 of the ECP market. Pluto delivers posture visibility into how employees actually use AI, contextual risk scoring that separates real danger from noise, and real-time enforcement that acts on those findings. Pluto governs three distinct layers spanning across AI tools employees use (ChatGPT, Claude, Copilot, etc.), the ecosystem surrounding those tools (npm packages, MCP servers, IDE plugins, browser extensions), and the artifacts employees build using those tools (custom apps, automated workflows, deployed agents). The platform deploys via API integrations and proprietary collectors that run through existing CrowdStrike, Defender, and MDM infrastructure, and claims to achieve approximately 30-minute deployment timelines even in large enterprises of 80,000+ employees. Pluto&#8217;s differentiation is structural. Most of the category secures one layer, the tool, the ecosystem, or the artifact, in isolation. Pluto not only connects context across all three layers but also delivers the visibility and governance to act on what that context reveals. A session that installs a package, calls an MCP server, ships an application, and runs a sequence of agent commands and prompts along the way is read as one event rather than three unrelated signals, with enforcement acting on the full picture rather than a single point. AI has turned employees into creators, wiring applications, agents, and workflows into production systems in an afternoon, often without a ticket, a review, or a security checkpoint. Pluto&#8217;s architectural bet is that the majority of AI-era endpoint risk is compositional: risk emerges from the combination of tools, permissions, and built artifacts, and that agentless monitoring of all three layers, paired with inline runtime hooks on coding agents, provides sufficient coverage to govern this risk without a local agent footprint.</p><p><strong>Applicable ECP Zones:</strong></p><ul><li><p><strong>Zone 1</strong></p></li><li><p><strong>Zone 2</strong></p></li><li><p><strong>Zone 3</strong></p></li></ul><h3><strong>Products/Services Overview</strong></h3><ul><li><p><strong>AI Tool Posture and Governance:</strong> Continuous discovery and policy enforcement for employee-facing AI applications (SaaS AI tools, local models, copilots);</p></li><li><p><strong>Ecosystem Posture and Governance:</strong> Discovery, risk-ranking, and enforcement for packages, MCP servers, IDE plugins, and browser extensions associated with AI workflows;</p></li><li><p><strong>Artifact Posture and Governance:</strong> Visibility, risk-ranking, and enforcement for apps, automated workflows, and AI agents built by employees using AI tools, the shadow builder output layer.</p></li><li><p><strong>Agentless Collector Infrastructure:</strong> Proprietary collectors operating through existing CrowdStrike, Defender, and MDM APIs, with an inline hook configuration on coding agents for runtime observability and enforcement where API coverage alone isn&#8217;t sufficient.</p></li></ul><h3><strong>Core Functions</strong></h3><ul><li><p><strong>Three-Layer Agentless Inventory:</strong> Simultaneously governs AI tools, their surrounding software ecosystems, and the artifacts (apps, agents, workflows) employees build with them.</p></li><li><p><strong>Rapid Enterprise Deployment:</strong> Achieves full fleet coverage via API integration in approximately 30 minutes for organizations of 80,000+ employees, with no reboots or agent installations.</p></li><li><p><strong>Shadow Builder Artifact Detection:</strong> Discovers and risk-ranks AI-assembled apps, scripts, and automated workflows deployed by non-IT employees, the artifact layer unique to Pluto&#8217;s scope.</p></li><li><p><strong>Policy-Based Access Control:</strong> Enforces allow/ask/deny policies on AI tool usage and ecosystem components via integration with existing MDM and IdP infrastructure.</p></li><li><p><strong>Continuous Risk-Ranking:</strong> Scores all three governance layers by permission scope, data access, behavioral signals, and upstream threat intelligence.</p></li><li><p><strong>Agent Runtime Observability and Governance:</strong> Continuously observes and governs AI agent execution, including prompts, commands, MCP servers, skills, tools, package installations, and network access, enabling context-aware policy enforcement.</p></li></ul><h3><strong>Use Cases and Pain Points Addressed</strong></h3><ol><li><p><strong>AI Tool and Ecosystem Governance at Scale:</strong> Rapidly inventories and governs the full AI toolchain, tools, packages, and plugins across a large enterprise fleet without a deployment project.</p></li><li><p><strong>Shadow Builder Artifact Risk Management:</strong> Surfaces AI-assembled apps, workflows, and deployed agents created by non-technical employees that introduce supply chain and data leakage risk.</p></li><li><p><strong>Federated AI Adoption Risk Reduction:</strong> Gives security and GRC teams an auditable record of AI tool adoption patterns across business units for compliance, procurement, and risk reporting.</p></li><li><p><strong>Govern AI Agent Behavior:</strong> Reduces the risk of AI agents performing unauthorized or unintended actions by enforcing runtime policies on agent execution, such as blocking an agent from collecting credentials and exfiltrating them to a remote location mid-session, helping organizations safely deploy AI into enterprise workflows.</p></li></ol><h3><strong>Key Takeaway / Recommendation</strong></h3><p>Pluto Security offers the broadest agentless governance scope in Zone 1, covering tools, ecosystem, and artifacts. This makes Pluto one of the strongest choices for enterprises whose primary concern is the shadow builder problem: employees assembling and deploying AI-powered workflows without security review. The 30-minute deployment claim is compelling for organizations facing board or regulatory pressure to inventory AI tool risk quickly. Enforcement runs today across EDR, MDM, and IdP policy rules, plus inline coding-agent hooks for runtime control, with granular blocking down to a specific tool, skill, or MCP action rather than an all-or-nothing cutoff. Pluto&#8217;s applicability extends into Zone 2 and Zone 3, so this coverage doesn&#8217;t require pairing with a separate enforcement vendor. Organizations building toward full-spectrum coverage, including Zone 5 data-centric enforcement such as classification-driven data loss prevention, may still want to evaluate that layer to complete the coverage stack.</p><h2><strong>Glow</strong></h2><h3>Vendor Profile</h3><p>Glow is a cybersecurity startup operating in Zone 1 and 2 of the ECP market, currently valued at over ~$1 billion with backing from Sequoia, Redpoint, Index, and Cyberstarts, among the most prominent venture investors in enterprise security. Glow is building an agentic solution that maps all the software and applications running on the endpoint, including local apps, AI agents, MCPs, browser extensions, packages, and developer plugins. The platform uses AI agents to analyze risk and enforce policies, proactively deciding which software is allowed and which AI tool configurations need to be hardened. The software governance and app enforcement framing aligns Glow with Zone 1 and Zone 2, where the primary threat models involve supply chain threats like compromised plugins and extensions and malicious packages as well as agentic app misconfigurations and unvetted software issues that increase endpoint exposure. Glow&#8217;s $1B+ valuation, achieved while the company was still in stealth, signals extreme investor conviction in the problem space and the founding team&#8217;s pedigree, drawn from top-tier prior security startups and enterprises. Buyers should monitor Glow&#8217;s emergence closely given its capitalization level, which will enable aggressive go-to-market, potential acquisitions, and rapid product development. Glow is expected to compete directly with Bay and Pluto in the Zone 2 enforcement and identity-governance space.</p><p><strong>Applicable ECP Zones:</strong></p><ul><li><p><strong>Zone 1</strong></p></li><li><p><strong>Zone 2</strong></p></li></ul><h3><strong>Products/Services Overview</strong></h3><ul><li><p><strong>Zone 1 Coverage:</strong> Software visibility, risk assessment and remediation of software plugins, packages, extensions, IDEs, and MCPs</p></li><li><p><strong>Zone 2 Coverage:</strong> Application-layer enforcement with the ability to block and remove software, review and remediate app configurations</p></li></ul><h3><strong>Core Functions</strong></h3><ul><li><p><strong>Inventory Reconciliation:</strong> Reconciles asset information across multiple data sources (EDR, MDM, IdP) and maps people to devices and software, enriched with information about vendor reputation, known issues, data privacy terms and other publicly available information</p></li><li><p><strong>AI Configuration Management: </strong>Discovers, analyzes and remediates configuration risks in agentic apps</p></li><li><p><strong>Supply Chain Exposure: </strong>Discovers, analyzes and remediates risks in the AI supply chain including MCPs, IDE plugins, browser extensions, and packages</p></li><li><p><strong>Software Control:</strong> Provides inline enforcement at the application and workflow layer, consistent with Zone 2 positioning.</p></li></ul><h3><strong>Use Cases and Pain Points Addressed</strong></h3><ol><li><p><strong>Asset Management: </strong>Consolidates endpoint, user, and application data from existing sources into a single reconciled inventory, addressing the persistent challenge of incomplete or conflicting asset records across tools.</p></li><li><p><strong>Software Control: </strong>Applies allow, audit, and block policies to installed software, packages, developer plugins, and browser extensions, with per-item risk assessment to identify and prevent execution of unauthorized or vulnerable code.</p></li><li><p><strong>Safe AI Adoption:</strong> Provides visibility into AI tools, plugins and MCP servers, and enforces configuration and usage policy to manage AI risk at the endpoint layer.</p></li></ol><h3><strong>Key Takeaway / Recommendation</strong></h3><p>Glow is a high-signal watch-list vendor for CISOs and security architects evaluating the Zone 1 and Zone 2 enforcement space. Its $1B+ valuation and top-tier VC backing suggest a founding team and product thesis that sophisticated investors consider category-defining. With their impending launch, buyers should request briefings and demos to learn more about its current capabilities and roadmap.SACR will update this profile with full product details upon demo completion. In the interim, Glow should be treated as a strong potential competitor to Bay and Pluto, particularly given its software and application governance focus.</p><h2><strong>NeuralTrust</strong></h2><h3>Vendor Profile</h3><p>NeuralTrust is an EU-based agentic runtime security platform that raised a $20M seed round in June 2026, the largest EU cybersecurity seed to date, to build centralized discovery and governance of AI agents from reasoning and planning through to action execution. NeuralTrust occupies Zone 2 of the ECP market as an AI infrastructure control plane rather than a traditional OS-level endpoint agent, operating through TrustGate, its agent gateway, which serves as the connectivity and enforcement layer between software, agents, tools, and models (API gateway, MCP proxy, and SDK integration) to enforce security policy mid-flow. The platform comprises four products: TrustGate (agent gateway), TrustGuard (runtime security), TrustLens (agent discovery and posture), and TrustTest (red teaming), delivering capabilities such as prompt injection detection, data leakage prevention, and runtime policy enforcement, and has been recognized by analyst firms as an enterprise platform for securing AI agents. NeuralTrust&#8217;s architecture is fundamentally different from OS/browser-layer Zone 2 vendors like Neo: it is designed for organizations building and deploying AI agents in production, instrumenting the agent reasoning and planning layer rather than the endpoint execution layer. This makes NeuralTrust most relevant to engineering and platform security teams managing internal AI agent deployments, AI application developers, and enterprises requiring governance of AI agents that operate autonomously across cloud services and APIs. The EU origin is relevant for buyers with data residency and GDPR requirements, as NeuralTrust&#8217;s architecture is designed with European compliance standards in mind.</p><p><strong>Applicable ECP Zones:</strong></p><ul><li><p><strong>Zone 2</strong></p></li><li><p><strong>Zone 3</strong></p></li></ul><h3><strong>Products/Services Overview</strong></h3><ul><li><p><strong>TrustGate (Agent Gateway):</strong> Connectivity and enforcement layer between software, agents, tools, and models; manages API gateway, MCP proxy, and SDK integration.</p></li><li><p><strong>TrustGuard (Runtime Security):</strong> Agent-to-agent flow governance, tool authorization, indirect prompt injection protection, and runtime DLP.</p></li><li><p><strong>TrustLens (Agent Discovery and Posture):</strong> Centralized discovery, cataloging, and security posture management for agents across the enterprise.</p></li><li><p><strong>TrustTest (Red Teaming):</strong> Security testing, validation, and red teaming for AI agents.</p></li></ul><h3><strong>Core Functions</strong></h3><ul><li><p><strong>TrustGate Gateway Enforcement:</strong> Serves as the central connectivity and enforcement layer mid-flow, executing API gateway, MCP proxy, and SDK integration controls across software, tools, and models.</p></li><li><p><strong>TrustGuard Agent Security Scope:</strong> Enforces advanced runtime policies that govern the entire agent reasoning layer, including tool authorization, autonomous agent-to-agent flow governance, and runtime data leakage prevention.</p></li><li><p><strong>Indirect Prompt Injection Prevention:</strong> Leverages TrustGuard to deliver real-time detection and blocking of adversarial inputs and indirect prompt injections, preventing agent hijacking during execution.</p></li><li><p><strong>TrustLens Centralized Discovery and Posture:</strong> Catalogues and inventories all AI agents across the enterprise, managing security posture from development through production deployment.</p></li><li><p><strong>TrustTest Agent Red Teaming:</strong> Conducts specialized security validation, continuous testing, and adversarial red teaming focused specifically on autonomous agent action execution and planning paths.</p></li></ul><h3><strong>Use Cases and Pain Points Addressed</strong></h3><ol><li><p><strong>Production AI Agent Runtime Security:</strong> Governs AI agents deployed in production, customer service bots, internal copilots, and autonomous workflow agents, enforcing security policy on every reasoning step and tool call.</p></li><li><p><strong>Prompt Injection Attack Prevention:</strong> Detects and blocks adversarial prompt injection attacks targeting enterprise AI agents, preventing attackers from hijacking agent behavior via crafted inputs or via poisoned content and tool outputs the agent consumes (indirect prompt injection), blocked at enforcement points</p></li><li><p><strong>GDPR-Compliant AI Governance:</strong> Provides EU-resident AI agent governance with data residency controls, audit logging, and compliance reporting aligned to GDPR and emerging EU AI Act requirements.</p></li></ol><h3><strong>Key Takeaway / Recommendation</strong></h3><p>NeuralTrust is the leading purpose-built Zone 2 option for organizations managing production AI agent deployments and requiring governance at the reasoning and planning layer which is above and beyond what OS and browser-layer endpoint tools can reach. Its $20M seed backing signal offers a strong market validation for the platform thesis. CISOs should position NeuralTrust as the AI infrastructure security layer complementary to endpoint-focused Zone 2 vendors like Neo. Neo governs the human user and endpoint tool layer, while NeuralTrust governs the autonomous AI agent and API layer. For organizations with GDPR or EU AI Act compliance requirements, NeuralTrust&#8217;s EU-native architecture is a significant procurement advantage. CISO&#8217;s should evaluate NeuralTrust early in any production AI agent deployment programs; runtime security is significantly easier to instrument before agents go to production than after.</p><h1>Zone 3: Agent Runtime Observability (AI-EDR)</h1><h3><strong>Origin (OriginHQ)</strong></h3><h4>Vendor Profile</h4><p>Origin (operating as OriginHQ / Prelude) is a Zone 3 Agent Runtime Observability vendor delivering probabilistic endpoint defense through a proprietary user-mode agent, patented CPU branch and instruction telemetry, and a local graph database that stores per-endpoint behavioral baselines. Origin&#8217;s core architectural thesis is that novel AI-era attacks are anomalies of intent where they are invisible to legacy signatures and passive posture scans but detectable as statistical deviations from an established behavioral baseline built from prompt-to-action traces.</p><p>The Origin platform watches every AI-agent interaction, cloud-connected or local-only, on the endpoint, including prompts, tool calls, shell commands, file writes, and network activity, across laptops, build servers, and CI/CD runners. Origin&#8217;s local TLS-intercepting proxy and OTEL collector achieve hook coverage without kernel-mode instrumentation, and its local graph database ensures that behavioral inference operates on-device, eliminating cloud-pipeline latency and cost at agentic telemetry volumes. Origin positions as the next layer stacked on top of incumbent EDR platform add-ons in the user behavioral analysis and agentic endpoint observability space.</p><p><strong>Applicable ECP Zones:</strong></p><ul><li><p><strong>Zone 3</strong></p></li></ul><h3><strong>Products/Services Overview</strong></h3><ul><li><p><strong>User-Mode Endpoint Agent:</strong> Proprietary user-mode agent with patented CPU branch/instruction telemetry and local TLS-intercepting proxy; no kernel driver required. Also surfaces shadow AI locally, including agent hardnesses, IDEs, and browser-based AI, with no cloud connection or extra installation required.</p></li><li><p><strong>Local Graph Database:</strong> Per-endpoint graph database storing behavioral baselines and prompt-to-action traces for on-device inference</p></li><li><p><strong>Agentic Observability Platform:</strong> Real-time monitoring of AI agent interactions, prompts, tool calls, shell commands, file and network activity, across laptops, build servers, and CI runners</p></li><li><p><strong>Probabilistic Behavioral Defense:</strong> An anomaly detection engine using local AI models and Bayesian behavioral baselines to detect intent-level deviations at machine speed</p></li><li><p><strong>AI Observability Ontology:</strong> Built-in relational model of agent activity that correlates telemetry into the context graph and prompt-to-action trace, turning disconnected event logs into one connected investigation narrative.</p></li></ul><h3><strong>Core Functions</strong></h3><ul><li><p><strong>Patented CPU-Level Telemetry:</strong> Captures CPU branch and instruction telemetry to build high-fidelity behavioral baselines without kernel-mode instrumentation, achieving coverage via a user-mode agent.</p></li><li><p><strong>Local TLS Interception:</strong> Intercepts TLS-encrypted application traffic and OTEL locally on the endpoint to capture full AI model API call content including prompts, responses, and tool invocations.</p></li><li><p><strong>Per-Endpoint Local Graph Database:</strong> Maintains a behavioral graph database on each endpoint, enabling on-device probabilistic inference without requiring cloud-backend latency.</p></li><li><p><strong>Prompt-to-Action Lineage:</strong> Establishes absolute traceability from natural language prompts through tool invocations to downstream system actions, providing forensic evidence chains for governance and incident response.</p></li><li><p><strong>On-Device Behavioral Inference:</strong> Executes anomaly detection locally using small language models and graph-based baselines, addressing agentic telemetry volume without cloud-pipeline cost.</p></li></ul><h3><strong>Use Cases and Pain Points Addressed</strong></h3><ol><li><p><strong>Agentic Workflow Observability and Forensics:</strong> Provides complete prompt-to-action traceability for AI agent interactions across the enterprise, enabling post-incident reconstruction and governance.</p></li><li><p><strong>Intent-Level Anomaly Detection:</strong> Detects AI-era attacks that bypass signature-based detection by identifying statistical deviations from established behavioral baselines at the intent layer.</p></li><li><p><strong>CI/CD and Build Server Agentic Security:</strong> Extends behavioral monitoring and enforcement to build servers and CI/CD runners where AI agents operate outside traditional endpoint security perimeters.</p></li></ol><h3><strong>Key Takeaway / Recommendation</strong></h3><p>Origin is the most technically differentiated Zone 3 vendor in the market, with its patented CPU telemetry, local graph database, and endpoint-centric architecture representing a genuine architectural moat against cloud-dependent incumbent EDR platforms. For CISOs managing large developer populations and AI agent deployments in production environments, particularly those running CI/CD pipelines and build infrastructure, Origin provides observability and forensic depth that no incumbent EDR platform currently matches. Buyers should evaluate Origin in environments where forensic evidence quality and agentic observability depth are primary buying criteria, rather than fast time-to-first-detection on commodity threats.</p><h1>Zone 4: Intent-Aware Behavioral Analysis</h1><h2><strong>Ent</strong></h2><h3>Vendor Profile</h3><p>Ent is a Zone 4 Intent-Aware Behavioral Analysis vendor that deploys a proprietary application-layer endpoint agent to build multimodal behavioral baselines of user and agent intent, then enforces policy through real-time pop-up interventions that block, warn, or redirect risky actions before completion. Unlike kernel-mode or network-layer EDR, Ent&#8217;s agent mints its own telemetry stream, capturing clicks, window focus, clipboard content, file activity, and screen context, and processes this multimodal data using on-device AI models (the &#8220;edge&#8221; inference architecture). Ent&#8217;s policy language, EntLang, enables security teams to express behavioral intent policies in structured natural language that the on-device model evaluates against the Bayesian behavioral baseline in real time. The Bayesian baseline uses a 90-day decay model, ensuring that behavioral norms adapt to legitimate changes in user workflows without requiring manual policy updates. Ent&#8217;s user-facing intervention model, real-time pop-ups that block, warn, redirect, alert, or block, where supported, is designed to replace the binary allow/block paradigm with a graduated, coaching-first enforcement experience that reduces friction for legitimate users while stopping risky behaviors at machine speed. Like Origin, Ent pushes inference to the device to handle agentic-volume telemetry without cloud-pipeline cost, which is the key architectural asymmetry against CrowdStrike&#8217;s AIDR network-dependent model.</p><p><strong>Applicable ECP Zones:</strong></p><ul><li><p><strong>Zone 3</strong></p></li><li><p><strong>Zone 4</strong></p></li><li><p><strong>Zone 5</strong></p></li></ul><h3><strong>Products/Services Overview</strong></h3><ul><li><p><strong>Application-Layer Endpoint Agent:</strong> Proprietary agent that captures multimodal telemetry (clicks, focus, clipboard, screenshots) for user and agent behavioral analysis</p></li><li><p><strong>Edge AI Inference Engine:</strong> On-device multimodal AI model for real-time intent evaluation against behavioral baselines</p></li><li><p><strong>EntLang Policy Engine:</strong> Structured natural language policy language enabling security teams to express intent-based behavioral and organizational rules</p></li><li><p><strong>Bayesian Behavioral Baseline:</strong> Adaptive behavioral model with 90-day decay that baselines both user and agent behavior and detects anomalies</p></li><li><p><strong>Real-Time Intervention System:</strong> Pop-up enforcement layer delivering block/warn/redirect/block interventions inline within the active workflow</p></li><li><p><strong>Data Sovereignty: </strong>Data stays within the customer boundary where the Ent platform is self-hosted and managed by the customer, delivering privacy and trust by design</p></li></ul><h3><strong>Core Functions</strong></h3><ul><li><p><strong>Multimodal Telemetry Capture:</strong> Mints proprietary telemetry including clicks, window focus, clipboard content, and screen context to build high-fidelity behavioral context for both users and AI agents operating on the endpoint.</p></li><li><p><strong>On-Device Intent Inference:</strong> Executes behavioral intent analysis locally using edge AI models, eliminating cloud-pipeline latency and cost while maintaining privacy for sensitive telemetry streams.</p></li><li><p><strong>Bayesian Behavioral Baselines:</strong> Maintains adaptive 90-day behavioral baselines for users and agents using Bayesian methods, automatically adjusting to legitimate workflow changes without manual tuning.</p></li><li><p><strong>EntLang Policy Authoring:</strong> Enables security teams to express behavioral intent policies in structured natural language, reducing the operational expertise required to configure intent-aware enforcement rules.</p></li><li><p><strong>Graduated Enforcement Interventions:</strong> Delivers real-time block/warn/redirect interventions via user-facing pop-ups, in addition to block and alert where supported, replacing binary allow/block with surgical, context-appropriate enforcement that coaches users rather than breaking workflows.</p></li></ul><h3><strong>Use Cases and Pain Points Addressed</strong></h3><ol><li><p><strong>User and Agent Intent Verification:</strong> Distinguishes between legitimate user-directed AI actions and malicious or anomalous agent behaviors using multimodal behavioral context.</p></li><li><p><strong>Insider Risk and Data Exfiltration Prevention:</strong> Detects and intercepts risky data movement and exfiltration behaviors by users and AI tools using clipboard, screen activity, and focus telemetry.</p></li><li><p><strong>Shadow Builder and AI Tool Misuse Governance:</strong> Monitors and enforces policy on user and agent interactions with AI tools and applications, flagging and intercepting misuse patterns before data or credential exfiltration completes.</p></li></ol><h3><strong>Key Takeaway / Recommendation</strong></h3><p>Ent is the strongest Zone 4 option for organizations prioritizing user-facing coaching enforcement and insider risk governance alongside agentic behavioral analysis. Its multimodal telemetry approach, capturing the full richness of user and agent interaction context, not just process and network signals, provides a behavioral depth that traditional EDR and network-layer tools cannot replicate. The EntLang policy language and Bayesian adaptive baselines significantly reduce the operational overhead of intent-aware enforcement compared to rule-based alternatives. CISOs should note that Ent overlaps with Bold Security on insider risk positioning; the differentiation is that Ent focuses on intent and behavior while Bold focuses on data payload and lineage, a complementary rather than competing stack in mature deployments. Origin provides the deepest forensic and developer pipeline observability, while Ent provides the strongest user-facing enforcement and insider risk governance.</p><h2><strong>Harmonic Security</strong></h2><h3>Vendor Profile</h3><p>Harmonic Security is a Zone 4 Intent-Aware Behavioral Analysis vendor delivering AI-native sensitive data classification and governance purpose-built for the era of enterprise AI tool adoption. Unlike legacy DLP platforms that rely on static pattern-matching rules, Harmonic uses AI-powered classification to identify sensitive data flowing into and out of AI applications, SaaS platforms, and collaboration tools in real time, at the point of user interaction, before data movement completes. Harmonic&#8217;s primary architectural bet is that the GenAI data leakage problem cannot be solved with rule-based DLP because the data types, destinations, and interaction patterns are too dynamic and context-dependent for static policies to govern. Its classification engine understands business context and not just PII and PCI patterns, enabling it to detect sensitive data submissions to AI tools that traditional DLP misclassifies as benign. Harmonic is designed to extend, rather than replace, existing endpoint and insider risk stacks, providing the AI tool governance layer that legacy DLP and Code42-style insider risk platforms were not built to address.</p><p><strong>Applicable ECP Zones:</strong></p><ul><li><p><strong>Zone 2</strong></p></li><li><p><strong>Zone 4</strong></p></li><li><p><strong>Zone 5</strong></p></li></ul><h3><strong>Products/Services Overview</strong></h3><ul><li><p><strong>AI-Native Data Classification Engine: </strong>Real-time classification of sensitive data flowing into AI applications, SaaS platforms, and collaboration tools using AI models tuned for business-context data types</p></li><li><p><strong>AI Tool Data Flow Monitoring: </strong>Continuous monitoring and enforcement for data submitted to or extracted from GenAI tools (ChatGPT, Claude, Copilot, Gemini) via endpoint and browser interactions</p></li><li><p><strong>Shadow AI Data Governance:</strong> Discovery and governance of unauthorized AI tool usage and the data flows they generate, providing visibility into unapproved GenAI adoption across the enterprise</p></li><li><p><strong>Workflow-Integrated Enforcement: </strong>Inline coaching and policy enforcement delivered within the active user workflow rather than via disruptive hard blocks</p></li><li><p><strong>Remote MCP Gateway: </strong>Governs MCP servers and agent tool calls inline, blocking dangerous tool-calls or risky data sharing mid-flow without killing the session.</p></li></ul><h3><strong>Core Functions</strong></h3><ul><li><p><strong>Business-Context AI Classification: </strong>Classifies sensitive data submissions to AI tools using AI models that understand business-context categories (financial data, IP, HR records, source code) beyond standard PII/PCI/PHI pattern matching.</p></li><li><p><strong>Real-Time AI Tool Interaction Governance: </strong>Monitors and enforces policy on data flowing into GenAI tools at the point of submission, prompt text, file uploads, clipboard paste, before the data reaches the model.</p></li><li><p><strong>Shadow AI Discovery and Risk Ranking: </strong>Identifies unauthorized AI tool usage across the enterprise fleet, ranking data exposure risk by tool, user, and data type to prioritize governance interventions.</p></li><li><p><strong>Inline User Coaching: </strong>Delivers contextual coaching and policy guidance to users at the moment of a risky AI tool interaction, reducing friction for legitimate use while intercepting genuine policy violations.</p></li><li><p><strong>SIEM/SOAR Integration: </strong>Feeds AI tool data governance findings into existing SOC workflows via SIEM and SOAR integrations, enabling correlation of AI-era data movement events with identity and endpoint telemetry.</p></li></ul><h3><strong>Use Cases and Pain Points Addressed</strong></h3><ol><li><p><strong>GenAI Prompt Leakage Prevention: </strong>Detects and intercepts sensitive business data submitted to AI tools in AI prompts, source code, financial reports, customer PII, HR data before it reaches the model and potentially leaves the organization&#8217;s control.</p></li><li><p><strong>Shadow AI Data Exposure Governance:</strong> Provides security and GRC teams with visibility into which employees are using which AI tools and what categories of sensitive data are flowing through those interactions, enabling risk-based governance without blanket blocking.</p></li><li><p><strong>AI Tool DLP Gap Coverage: </strong>Closes the data governance gap that legacy DLP platforms leave open when employees interact with AI tools via browser, which is a channel that network-layer DLP and proxy-based tools struggle to inspect with sufficient business context.</p></li></ol><h3><strong>Key Takeaway / Recommendation</strong></h3><p>Harmonic Security spans Zones 2, 4, and 5 natively, anchored in Zone 4 as its primary zone, while also providing coverage for Zones 1 and 3 through shadow AI discovery and prompt-to-action visibility. This native multi-zone reach makes it the strongest option for organizations whose primary data governance gap is sensitive data flowing into GenAI tools and AI-assisted workflows, which represent a risk that legacy DLP platforms and traditional insider risk tools were not architected to address. Its AI-native classification engine provides the business-context awareness required to govern AI tool interactions without generating the false-positive rates that make legacy DLP operationally unsustainable. CISOs should position Harmonic as the AI tool data governance layer within an existing Zone 4 stack. The key evaluation question is classification accuracy for the organization&#8217;s specific sensitive data types in AI tool interaction contexts; request a proof-of-concept with representative prompt and file submission scenarios to validate detection fidelity before broad deployment.</p><h1>Zone 5: Data-Centric Enforcement</h1><h2><strong>Bold Security</strong></h2><h3>Vendor Profile</h3><p>Bold Security is a Zone 4/5 Intent-Aware Behavioral Analysis and Data-Centric Enforcement vendor that deploys a modular endpoint agent and an agent-deployed browser extension (no proxy required) to classify sensitive data locally on the device using small language AI models, delivering pre-action verdicts and inline coaching at creation, download, clipboard moments and other ingress and egress moments. Bold&#8217;s core architectural bet is that effective data protection in the AI era requires on-device AI classification, not network-layer proxies or cloud-backend DLP rules, because a growing proportion of sensitive data movement occurs within cert-pinned AI applications (ChatGPT, Claude, Copilot) that network proxies cannot inspect. Bold&#8217;s classification engine extends beyond traditional PII and PCI categories into business-context categories: financial reports, IT/security data, AI application outputs, and custom organizational data types. The platform provides stacked data lineage, human risk scoring, and AI risk scoring in a unified view, and has been validated at 100,000-endpoint enterprise scale. Bold&#8217;s on-device AI classification is the primary architectural differentiator, a distinction that becomes increasingly material as enterprise AI tool adoption grows and proxy-bypassed data movement becomes the norm.</p><p><strong>Applicable ECP Zones:</strong></p><ul><li><p><strong>Zone 4</strong></p></li><li><p><strong>Zone 5</strong></p></li></ul><h3><strong>Products/Services Overview</strong></h3><ul><li><p><strong>Modular Endpoint Agent:</strong> Lightweight endpoint agent providing on-device AI data classification and enforcement at creation, download, and clipboard interaction points</p></li><li><p><strong>Agent-Deployed Browser Extension:</strong> Proxy-free browser extension for in-browser data movement monitoring and enforcement, deployed via the endpoint agent without proxy infrastructure</p></li><li><p><strong>On-Device AI Classification Engine:</strong> Small AI models running locally that classify data beyond PII/PCI into business-context categories at enterprise scale</p></li><li><p><strong>Data Lineage and Risk Scoring:</strong> Unified data lineage view with stacked human risk, AI risk, and data risk scoring for investigation and governance</p></li><li><p><strong>Inline Coaching and Justification Prompts:</strong> User-facing enforcement delivering pre-action verdicts with coaching and exception justification workflows rather than hard blocks</p></li></ul><h3><strong>Core Functions</strong></h3><ul><li><p><strong>On-Device AI Data Classification:</strong> Classifies sensitive data locally using small AI models at creation, download, and clipboard moments, covering business-context categories beyond standard PII/PCI/PHI.</p></li><li><p><strong>Cert-Pinned AI App Traffic Inspection:</strong> Inspects data movement within cert-pinned AI applications (ChatGPT, Claude, Copilot) that network proxies cannot reach, closing a critical gap in legacy DLP architectures.</p></li><li><p><strong>Pre-Action Data Verdict Enforcement:</strong> Delivers block/warn/coach verdicts before data movement completes, at the moment of clipboard paste, file download, or prompt submission rather than detecting exfiltration post-hoc.</p></li><li><p><strong>Stacked Risk Scoring:</strong> Provides unified human risk, AI risk, and data lineage scoring in a single dashboard, enabling security teams to correlate data movement risk with user behavioral and AI tool usage context.</p></li><li><p><strong>Inline User Coaching:</strong> Delivers contextual coaching and justification prompts to users at the point of risky data interaction, reducing false positives and building security-aware behavior rather than blocking workflows.</p></li></ul><h3><strong>Use Cases and Pain Points Addressed</strong></h3><ol><li><p>AI Application Data Leakage Prevention: Prevents sensitive data from being pasted into or extracted from cert-pinned AI applications (ChatGPT, Claude, Copilot) that bypass network-layer DLP.</p></li><li><p>Shadow Builder Data Exfiltration Prevention: Detects and intercepts sensitive data movement within AI-assembled workflows and shadow builder toolchains before exfiltration completes.</p></li><li><p>AI Risk and Human Risk Correlation for Investigations: Provides stacked data lineage with human risk and AI risk scoring to accelerate incident investigation and insider threat analysis.</p></li></ol><h3><strong>Key Takeaway / Recommendation</strong></h3><p>Bold Security is a leading purpose-built Zone 4/5 option targeting cert-pinned AI application traffic missed by network-layer DLP. Operating at a validated 100,000-endpoint scale, its proxy-free architecture uses a modular agent and browser extension to classify data locally using small AI models. Classification goes beyond PII to business-context categories and user policies, providing stacked data lineage, human risk, and AI risk. Bold delivers pre-action verdicts at creation, download, and clipboard moments, utilizing inline coaching or justification prompts. CISOs should position Bold as an on-device enforcement layer complementary to network CASB/SWG tools, not a replacement.</p><h2><strong>Cyberhaven</strong></h2><h3>Vendor Profile</h3><p>Cyberhaven is a data lineage and browser-centric Zone 5 governance platform that tracks the origin, movement, and destination of sensitive data across endpoint, browser, SaaS, and cloud environments, providing high-fidelity evidence chains of user data interactions. Unlike traditional DLP tools that classify data by content pattern at a point in time, Cyberhaven builds a continuous lineage graph that follows data from its point of origin- a document created, a record copied from a database, a file downloaded from a cloud service- through every subsequent interaction, transformation, and transfer. This lineage model enables security teams to answer the forensic question that matters most in AI-era investigations. Cyberhaven&#8217;s browser-centric architecture captures SaaS and web application data interactions that endpoint-only agents miss, making it particularly relevant for organizations where the majority of sensitive data movement occurs within browsers interacting with cloud-based AI tools, SaaS platforms, and collaboration applications with on-device AI classification as the primary architectural differentiator.</p><p><strong>Applicable ECP Zones:</strong></p><ul><li><p><strong>Zone 5</strong></p></li></ul><h3><strong>Products/Services Overview</strong></h3><ul><li><p><strong>Data Lineage Platform:</strong> Continuous tracking of sensitive data origin, movement, and destination across endpoint, browser, SaaS, and cloud environments</p></li><li><p><strong>Browser-Centric Governance:</strong> Browser extension-based data movement monitoring providing full visibility into SaaS application and web-based data interactions</p></li><li><p><strong>Data Movement Evidence Chains:</strong> High-fidelity forensic evidence chains of user data interactions for incident investigation, governance, and compliance reporting</p></li><li><p><strong>AI Tool Data Flow Monitoring:</strong> Visibility into data flows into and out of AI applications accessed via the browser</p></li></ul><h3><strong>Core Functions</strong></h3><ul><li><p><strong>Continuous Data Lineage Tracking:</strong> Follows sensitive data from its origin through every subsequent interaction, transformation, and transfer across endpoint, browser, and cloud, building a persistent lineage graph.</p></li><li><p><strong>Browser Data Movement Capture:</strong> Instruments the browser to capture the full richness of SaaS and web application data interactions, including copy-paste, upload, download, and AI tool prompt submissions.</p></li><li><p><strong>Forensic Evidence Chain Generation:</strong> Produces investigation-grade evidence chains that answer the origin, path, and destination questions for any sensitive data movement event.</p></li><li><p><strong>AI Tool Data Flow Visibility:</strong> Monitors data flowing into and out of browser-accessed AI tools (ChatGPT, Copilot, Gemini), providing governance coverage for AI-mediated data movement.</p></li><li><p><strong>Cross-Environment Lineage Correlation:</strong> Correlates data movement events across endpoint, browser, SaaS, and cloud to provide a unified view of sensitive data flows across the enterprise.</p></li></ul><h3><strong>Use Cases and Pain Points Addressed</strong></h3><ol><li><p><strong>Insider Threat and Exfiltration Forensics:</strong> Provides complete data lineage for forensic investigation of insider threat and exfiltration incidents, answering origin, path, and destination questions that traditional DLP cannot.</p></li><li><p><strong>AI Tool Data Governance:</strong> Monitors and governs sensitive data flowing into browser-accessed AI tools, detecting prompt leakage and unauthorized AI-mediated data movement.</p></li><li><p><strong>Departing Employee Data Exfiltration Detection:</strong> Detects and investigates data exfiltration by departing employees by tracking sensitive data movement patterns in the period leading up to departure.</p></li></ol><h3><strong>Key Takeaway / Recommendation</strong></h3><p>Cyberhaven is a strong Zone 5 data lineage platform, offering the most mature and proven browser-centric data governance capability in the market. For organizations prioritizing forensic evidence quality, insider threat investigation depth, and AI tool data flow governance, Cyberhaven provides capabilities that legacy DLP and most next-gen alternatives do not match on lineage depth. CISOs should evaluate Cyberhaven as the data lineage and evidence chain foundation of their Zone 5 stack. The key consideration is that Cyberhaven&#8217;s primary strength is lineage and forensics rather than real-time prevention; organizations requiring pre-action enforcement should layer Cyberhaven with a prevention-first enforcement vendor rather than treating it as a standalone DLP replacement.</p><h1><strong>Multi-Zone: Converged Endpoint Control and Prevention Platforms (ECPP)</strong></h1><p>Note: Vendors must be in 4 or more zones</p><h3><strong>Bay</strong></h3><h3>Vendor Profile</h3><p>Bay is an agentless, prevention-first endpoint AI security platform operating in Zone 1 through 4 of the ECP market. Its capabilities span four layers: discovery and posture management, supply chain security and application control, visibility into agentic activity, and real-time, session-aware enforcement. At the discovery layer, Bay builds a contextual entity graph of the AI agents, browser extensions, IDE extensions, MCP servers, skills, plugins, connectors, models, and packages running across the fleet, mapping permissions, entitlements, personal versus corporate account use, and toxic tool combinations, and raising posture findings. At the supply chain layer, it extracts malicious indicators and vulnerabilities from the components agents load, with centralized approve, block, and uninstall controls and application allowlisting. At the activity layer, it records agent actions end to end, from prompt to tool call to system action, for investigation and audit. Then it analyzes the agentic activities to author out-of-the-box intent-aware policies that fit any workflows and departments within the organization. <br><br>A key differentiator for Bay relative to some Zone 1 players is that it does not stop at discovery or posture reporting: enforcement is endpoint-resident and executed locally as each agent action is invoked, evaluating that action in the context of the session rather than in isolation. Bay states that once a session touches sensitive data or credentials, it closes the outbound exfiltration routes for the remainder of that session, blocking the sequence rather than only flagging it, and that on-device enforcement runs at sub-4ms p95 latency with no cloud round trip. The platform is designed to ride existing EDR/MDM and orchestration rails such as Intune and CrowdStrike, deploying an ephemeral collector rather than a net-new persistent agent, and to run across Windows, Mac, and Linux endpoints, cloud endpoints and containers. Bay frames its value around stopping incidents before they occur across the agentic supply chain rather than generating a risk report for human review, and positions itself as distinct both from pure visibility players and from EDR, which observes processes and network connections but, in Bay&#8217;s account, cannot distinguish AI activity from human activity. This makes Bay relevant to organizations seeking discovery, application control, and active enforcement of agentic activity in a single agentless deployment.</p><p><strong>Applicable ECP Zones:</strong></p><ul><li><p><strong>Zone 1</strong></p></li><li><p><strong>Zone 2</strong></p></li><li><p><strong>Zone 3</strong></p></li><li><p><strong>Zone 4</strong></p></li></ul><h3><strong>Products/Services Overview</strong></h3><ul><li><p><strong>AI Tool and Extension Discovery:</strong> Agentless continuous discovery of AI agents, extensions, MCP servers, skills, plugins, models and packages across the enterprise fleet, mapped into a contextual entity graph with risk scoring, surfacing permission overreach, personal-account use, and toxic tool combinations as posture findings.</p></li><li><p><strong>Supply Chain Security and Application Control:</strong> Malicious-indicator and vulnerability extraction across browser extensions, IDE extensions, MCP servers, packages, skills, and models, with centralized approve, block, and uninstall, and application allowlisting.</p></li><li><p><strong>Credential Exposure Remediation:</strong> Active identification and remediation of exposed secrets, API keys, and credentials embedded in extension configurations and agentic toolchains</p></li><li><p><strong>Real-Time and Session-Aware Enforcement:</strong> Endpoint-resident Allow/Ask/Deny policy enforcement via existing EDR/MDM sensors that evaluates each action locally and in session context, and closes exfiltration routes once a session touches sensitive data or credentials.</p></li><li><p><strong>Agentic Workflow Visibility &amp; Forensics:</strong> Record of agent actions with full context, human versus autonomous, prompt-to-action chain, and timestamps, used for investigation, audit, and policy tailoring.</p></li></ul><h3><strong>Core Functions</strong></h3><ul><li><p><strong>Agentless Prevention-First Posture:</strong> Discovers and risk-ranks AI tools, extensions, and agentic workflows with a patent-pending ephemeral collector via EDR/MDM with a focus on preventing incidents rather than reporting them post-hoc.</p></li><li><p><strong>Supply Chain and Application Control:</strong> Extracts malicious indicators and vulnerabilities from the components agents load, flags risky items, blocks or uninstalls them, and controls which applications and packages are permitted to run.</p></li><li><p><strong>Session-Aware Policy:</strong> Evaluates each action against session state rather than in isolation, closing exfiltration routes for the remainder of a session once credentials or sensitive data are touched.</p></li><li><p><strong>Credential and Secret Exposure Detection:</strong> Actively identifies secrets, API keys, OAuth tokens, and credentials exposed in extension configurations, agentic tool settings, and workflow artifacts.</p></li><li><p><strong>Real-Time Policy Enforcement:</strong> Enforces Allow/Ask/Deny on the device as each AI tool action is invoked, evaluating the action across files, network destinations, credential access, MCP tool calls, and shell capabilities, and combining deterministic rules with behavioral context. Bay reports sub-4ms p95 latency for on-device decisions. <strong>Agentic Workflow Governance:</strong> Captures the prompt-to-tool-call-to-system-action chain for each agent, providing a single point for forensics and the behavioral basis for tailoring policy per identity-provider group.</p></li><li><p><strong>Credential Remediation Workflows:</strong> Provides guided remediation workflows for exposed credentials, including rotation recommendations and integration with secrets management platforms.</p></li></ul><h3><strong>Use Cases and Pain Points Addressed</strong></h3><ol><li><p><strong>Credential Exposure in Agentic Toolchains:</strong> Identifies API keys, tokens, and secrets embedded in agentic configurations and extension permissions before attackers can harvest them.</p></li><li><p><strong>Prevention-First AI Tool Governance:</strong> Discovers unapproved AI tools and agentic workflows and enforces real-time allow/ask/deny policy on the device..</p></li><li><p><strong>Shadow AI and Shadow Builder Risk Reduction:</strong> Surfaces unauthorized AI tool deployments and agentic workflow configurations created by non-IT employees, enabling governance without blocking legitimate productivity.</p></li><li><p><strong>Agentic Supply Chain Exposure:</strong> Identifies malicious or vulnerable extensions, MCP servers, packages, and models, and blocks or removes them from a central point.</p></li></ol><h3><strong>Key Takeaway / Recommendation</strong></h3><p>Bay is the strongest Zone 1 option for organizations whose primary concern is credential exposure within the non-binary software and agentic toolchain layer, a specific and underserved risk that pure posture scanners address only partially. The prevention-first positioning and credential remediation capability make Bay a meaningful complement or alternative to Bloom/Pluto depending on whether credential hygiene or supply chain visibility is the primary buying criterion. CISOs should evaluate Bay alongside their existing secrets management and IdP posture (e.g., CyberArk, HashiCorp Vault integrations) to assess whether Bay&#8217;s remediation workflows integrate cleanly with incumbent tooling. As with all Zone 1 agentless players, enforcement depth for novel AI tool installations requires a complementary Zone 2 enforcement layer for complete prevention coverage.</p><p>Bay is a strong option for organizations that want more than posture reporting at the agentic endpoint layer. A principal distinction from posture-only players is an endpoint-resident, session-aware enforcement engine that acts on each AI tool action in real time, a layer those tools do not provide, and one that Bay argues EDR cannot deliver because EDR does not distinguish AI activity from human activity. That said, discovery and posture overlap materially with the incumbent scanners, so the enforcement layer is where Bay should be evaluated most closely. Two points bear on any assessment. First, prevention depends on Bay&#8217;s on-device enforcement component; a collector-only deployment runs in detection mode, so buyers should confirm which mode a given deployment is in. Second, several of the breadth claims, including scanning of skills, plugins, and models and the stated latency and cross-platform parity, are vendor-reported and would benefit from validation in a POV. CISOs evaluating Bay should scope a proof of value around the enforcement engine specifically, and confirm how its posture and activity findings integrate with existing identity, EDR, and secrets tooling.</p><h2><strong>CrowdStrike</strong></h2><h3>Vendor Profile</h3><p>CrowdStrike occupies a uniquely distinct position in the ECP market: platform convergence via acquisition and organic expansion, attempting to cover all five ECP zones simultaneously from its Falcon sensor base. Rather than a pure-play ECP startup, CrowdStrike is the incumbent EDR market leader extending its platform into the AI-era through Falcon AIDR and Falcon Secure Access (Seraphic Security acquisition of browser-layer enforcement). Falcon AIDR delivers prompt and LLM-response layer visibility, threat detection, data protection, and automated response across endpoints, SaaS, and cloud environments via Falcon Sensor integration, browser extensions, AI gateway integrations, SDK, and an MCP Proxy.</p><p>CrowdStrike&#8217;s two AIDR core use cases are workforce AI adoption governance (monitoring and controlling employee use of GenAI tools) and AI application runtime security (runtime guardrails for engineers building agents and agentic workloads). CrowdStrike&#8217;s strategic position is distribution and platform convergence: it can deliver ECP capabilities at attach rates no startup can match by embedding them into the Falcon platform already deployed across millions of endpoints. The structural vulnerability startups are exploiting is AIDR&#8217;s network-connection dependency; its prompt-layer telemetry requires network connectivity rather than operating at the local on-device inference layer.</p><p><strong>Applicable ECP Zones:</strong></p><ul><li><p><strong>All Zones</strong></p></li></ul><h3><strong>Products/Services Overview</strong></h3><ul><li><p><strong>Falcon Insight XDR:</strong> Unified endpoint detection and response (EDR) and extended detection and response (XDR) with enterprise-wide visibility to automatically detect adversary activity and respond across endpoints, identities, and cloud workloads.</p></li><li><p><strong>Falcon AIDR:</strong> Prompt- and LLM response layer AI visibility, governance, detection and response module delivering visibility, threat detection, data protection, and response spanning endpoints, SaaS, and cloud environments via Falcon Sensor integration, browser extensions, AI gateway integrations, SDK, and an MCP Proxy.</p></li><li><p><strong>Falcon Secure Access:</strong> Browser-layer enforcement capability acquired to extend Falcon into Zone 2 / App-Layer Enforcement</p></li><li><p><strong>Falcon Next-Gen SIEM:</strong> Cloud-native security data platform that unifies third-party log ingestion and long-term storage with CrowdStrike&#8217;s native telemetry and AIDR findings for AI-powered detection, investigation and response.</p></li><li><p><strong>Charlotte AI:</strong> CrowdStrike&#8217;s generative AI assistant embedded across the Falcon platform for analyst augmentation and accelerated investigation</p></li></ul><h3><strong>Core Functions</strong></h3><ul><li><p><strong>Prompt-and LLM Response Layer Visibility and Governance:</strong> Captures full prompt content (including secrets) via Falcon Sensor integrations, browser extension and API/SDK/gateway integration; maps relationships between users, prompts, models, agents, and MCP servers in a unified visibility dashboard.</p></li><li><p><strong>Access and Prompt Detection Rule Enforcement:</strong> Two rule types, Access rules which offer restrictions on attributes including user, application, LLM model, and version and Prompt detection rules (input/output checks for threats and policy violations), with response modes ranging from Report-only through Block to Replace (e.g., AWS tokens auto-redacted before prompt submission).</p></li><li><p><strong>AI Agent and MCP Server Runtime Security:</strong> Extends Falcon telemetry to AI agent workloads, MCP server interactions, and AI/API gateway traffic, providing runtime guardrails for engineering teams building and deploying agentic applications.</p></li><li><p><strong>Cross-Platform Telemetry Correlation:</strong> Feeds AIDR findings into Falcon Next-Gen SIEM for correlation with endpoint, cloud, and identity signals from across the full Falcon platform, enabling unified investigation across all telemetry sources.</p></li><li><p><strong>Browser-Layer Enforcement (via Seraphic):</strong> Extends enforcement into the browser execution context through the Seraphic acquisition, covering browser-mediated AI tool interactions and web application data flows.</p></li></ul><h3><strong>Use Cases and Pain Points Addressed</strong></h3><ol><li><p><strong>Enterprise GenAI Tool Governance at Scale:</strong> Monitors and controls employee use of ChatGPT, Claude, Copilot, and other GenAI tools across the fleet, enforcing access policies and prompt-content rules at enterprise scale.</p></li><li><p><strong>AI Application and Agentic Workload Runtime Security:</strong> Provides runtime guardrails for engineering teams building AI agents, chatbots, and agentic pipelines, detecting prompt injection, secret leakage, and policy violations within the development and production workflow.</p></li><li><p><strong>Unified SOC Triage Across Endpoint and AI Telemetry:</strong> Surfaces AI-layer threat detections (prompt injections, data leakage, policy violations) in Falcon Next-Gen SIEM alongside endpoint and identity alerts, enabling SOC analysts to correlate AI-era incidents with traditional threat telemetry in a single pane.</p></li></ol><h3><strong>Key Takeaway / Recommendation</strong></h3><p>For CISOs running CrowdStrike as their primary EDR and SIEM platform, Falcon AIDR is the lowest-friction path to baseline AI governance coverage; it deploys through the existing Falcon management plane and surfaces findings in the existing SOC workflow, requiring no net-new vendor relationships. The platform convergence advantage is real: CrowdStrike&#8217;s distribution, attach rates, and cross-telemetry correlation are structural advantages no ECP startup can match in the near term. However, buyers should treat AIDR as a strong baseline rather than a best-of-breed solution across all ECP zones.</p><h2><strong>Palo Alto Networks (Koi Security)</strong></h2><h3>Vendor Profile</h3><p>Palo Alto Networks entered the ECP Zone 1 market through its acquisition of Koi Security, a startup focused on AI and software supply chain visibility at the network and endpoint boundary. The Koi acquisition gives Palo Alto Networks a wedge into the non-binary software governance category, extending the Cortex and Prisma platforms beyond traditional process-level telemetry into the discovery and risk-ranking of browser extensions, IDE plugins, MCP servers, and agentic toolchains. Rather than building agentless posture management organically, Palo Alto Networks is using M&amp;A to accelerate its position in the category, integrating Koi&#8217;s supply-chain gateway capabilities with existing MDM and EDR integrations already present in the Cortex XDR stack for a more direct integration path. Additionally, Koi will remain available standalone, integrating with existing MDM and EDR tools regardless of vendor. The strategic bet is that Palo Alto Networks&#8217;s installed base and enterprise go-to-market can rapidly distribute a point solution into a platform-level posture capability.</p><p><strong>Applicable ECP Zones:</strong></p><ul><li><p><strong>Zone 1</strong></p></li><li><p><strong>Zone 2</strong></p></li><li><p><strong>Zone 3</strong></p></li><li><p><strong>Zone 4</strong></p></li><li><p><strong>Zone 5</strong></p></li></ul><h3><strong>Products/Services Overview</strong></h3><ul><li><p><strong>Koi Security (Standalone Today; Planned Integration into Cortex):</strong> Network supply-chain gateway providing discovery, risk-ranking and preemptive control of non-binary endpoint software, blocking installation of unauthorized MCP servers, AI models, AI agent toolchains, code packages, OS packages, IDE plugins, and browser extensions.</p></li><li><p><strong>Cortex XDR:</strong> Palo Alto Networks&#8217;s extended detection and response platform, now extended with Koi-derived supply-chain telemetry</p></li><li><p><strong>Prisma Browser / Talon (acquired):</strong> Browser-centric enforcement and visibility layer, relevant to Zone 3 Agent Runtime Observability (AI-EDR) as well.</p></li></ul><h3><strong>Core Functions</strong></h3><ul><li><p><strong>Supply Chain Discovery:</strong> Continuously discovers and inventories non-binary software (extensions, plugins, packages, MCP tooling) installed across the enterprise endpoint fleet.</p></li><li><p><strong>Risk Ranking and Posture Assessment:</strong> Scores discovered software against threat intelligence, permission scope, and behavioral signals to surface high-severity configuration liabilities before exploitation.</p></li><li><p><strong>MDM/EDR Integration:</strong> Rides existing CrowdStrike, Defender, and MDM telemetry to deliver posture findings without requiring a net-new agent footprint on every endpoint.</p></li><li><p><strong>Policy Enforcement via Network Gateway:</strong> Enforces allow/deny decisions at the network supply-chain layer, preventing installation of unauthorized toolchain components before they reach the endpoint.</p></li><li><p><strong>Policy Enforcement via Endpoint Integration:</strong> Provides real-time control of AI agent behavior at runtime on the endpoint, governing approved software and what AI agents are permitted to do as they execute.</p></li><li><p><strong>Platform Convergence:</strong> Feeds Koi-derived signals into Cortex XDR and Prisma AIRS for cross-correlation with process, identity, and cloud telemetry.</p></li></ul><h3><strong>Use Cases and Pain Points Addressed</strong></h3><ol><li><p><strong>Shadow AI Toolchain Governance:</strong> Discovers and risk-ranks unapproved non-binary software including AI tools, MCP servers, and IDE copilot plugins, browser extension, code packages, AI models, and OS packages deployed by shadow builders.</p></li><li><p><strong>Software Supply Chain Compromise Prevention:</strong> Detects compromised or malicious packages and browser extensions entering the enterprise via developer and agentic workflows.</p></li><li><p><strong>AI Agent Runtime Behavior Control:</strong> Monitors and restricts approved AI agents&#8217; actions during execution, including permission scope, access to sensitive data and credentials, deleting cloud infrastructure, or pushing code changes.</p></li><li><p><strong>Compliance and Configuration Hygiene:</strong> Ensures non-binary software meets organizational security policy (permissions, provenance, version currency) for audit and governance purposes.</p></li></ol><h3><strong>Key Takeaway / Recommendation</strong></h3><p>For CISOs with an existing Palo Alto Networks Cortex or Prisma investment, Koi Security&#8217;s integration represents the lowest-friction path to Zone 1 coverage; it leverages the incumbent agent and platform rather than adding a net-new vendor. However, buyers should scrutinize enforcement depth vs. visibility breadth as the Koi acquisition is early-stage integration, and real-time enforcement capabilities (block vs. report) may lag behind purpose-built agentless players in the near term. Palo Alto Networks&#8217;s strategic advantage is distribution and platform convergence.</p><h2><strong>SentinelOne (Singularity)</strong></h2><h3>Vendor Profile</h3><p>SentinelOne occupies a position in the ECP market as a platform convergence vendor for ECP which it achieved via organic expansion and acquisition, extending its Singularity Platform foundation across all five ECP zones simultaneously. SentinelOne&#8217;s expansion not only includes prompt-layer governance centers but also includes its Purple AI analyst layer, the Singularity Data Lake, and its growing AI Security Posture Management (AI-SPM) capabilities, extending the Singularity agent from classic endpoint telemetry into AI-era governance of workloads, agents, and data flows. SentinelOne&#8217;s strategic differentiation against CrowdStrike in the ECP context is its broad AI detection capabilities and open data architecture. Singularity Data Lake ingests native and third-party telemetry into a unified SOC triage surface, positioning SentinelOne as an integration hub for ECP point solutions rather than requiring exclusive use of SentinelOne-native capabilities. Purple AI extends the platform by surfacing AI-generated investigation narratives and autonomous response recommendations across all ingested telemetry, including AI tool governance events. SentinelOne&#8217;s AI-SPM and Prompt Security capability addresses the emerging need to discover and govern AI workloads, models, and agent pipelines deployed in cloud and endpoint environments, a Zone 1/3 adjacency that gives SentinelOne an entry point into the non-binary software governance and agent runtime observability space without a dedicated Zone 1 point solution acquisition.</p><p><strong>Applicable ECP Zones:</strong></p><ul><li><p><strong>All Zones</strong></p></li></ul><h3><strong>Products/Services Overview</strong></h3><ul><li><p><strong>Singularity Platform:</strong> Core kernel-level endpoint agent providing autonomous prevention, detection, and response in addition to process, file, network, and identity telemetry across the enterprise fleet; foundation for ECP zone expansion</p></li><li><p><strong>Purple AI:</strong> Agentic AI analyst embedded across the Singularity platform; surfaces AI-generated investigation narratives, threat hunting queries, and autonomous response recommendations across all telemetry sources</p></li><li><p><strong>Singularity Data Lake:</strong> Open, cloud-hosted telemetry lake ingesting SentinelOne-native and third-party data sources (including ECP point solutions) for unified SOC correlation and investigation</p></li><li><p><strong>AI-SPM (AI Security Posture Management):</strong> Discovery and risk assessment of AI workloads, models, agent pipelines, and cloud-deployed AI infrastructure, posture governance for the AI development and deployment lifecycle</p></li><li><p><strong>Unified Alert Management (UAM):</strong> Integration hub surfacing third-party security findings alongside SentinelOne-native detections for unified analyst triage</p></li></ul><h3><strong>Core Functions</strong></h3><ul><li><p><strong>Platform-Wide AI Analyst (Purple AI):</strong> Generates natural language investigation narratives and hunting queries from endpoint, identity, cloud, and AI governance telemetry, reducing analyst time-to-triage across ECP-relevant events.</p></li><li><p><strong>AI Workload and Model Posture Discovery (AI-SPM):</strong> Discovers AI models, agent frameworks, and AI-enabled applications deployed across cloud and endpoint environments, assessing configuration risk and permission exposure, a Zone 1 and 3 adjacent capability.</p></li><li><p><strong>Open Telemetry Ingestion (Data Lake):</strong> Ingests third-party ECP telemetry (DLP findings, identity signals, network events, EDR data, cloud workloads) into Singularity Data Lake, enabling SentinelOne customers to use purpose-built ECP point solutions without losing SOC correlation.</p></li><li><p><strong>UAM Third-Party Alert Integration:</strong> Surfaces ECP point solution findings directly in the SentinelOne analyst triage queue, eliminating the operational silo between data movement governance and endpoint detection.</p></li><li><p><strong>Behavioral AI Detection (Singularity Agent):</strong> On-agent behavioral AI detecting anomalous process and application behavior at the endpoint, with expanding coverage into AI tool interaction patterns as the Singularity agent extends up-stack.</p></li></ul><h3><strong>Use Cases and Pain Points Addressed</strong></h3><ol><li><p><strong>Unified SOC Triage Across ECP and EDR Telemetry:</strong> Ingests SentinelOne-native and ECP point solution findings into Singularity Data Lake and UAM, enabling SOC analysts to correlate AI governance events (data leakage, prompt injection, shadow AI activity) with endpoint and identity telemetry in a single investigation surface.</p></li><li><p><strong>AI Workload and Agent Posture Governance (AI-SPM):</strong> Discovers and risk-ranks AI models, agent pipelines, and AI-enabled applications deployed in cloud and endpoint environments, providing CISOs with visibility into shadow AI infrastructure that traditional EDR telemetry does not surface.</p></li><li><p><strong>Purple AI-Accelerated ECP Investigation:</strong> Applies Purple AI&#8217;s Agentic Investigation capability to ECP-sourced events, AI tool policy violations, and prompt injection detections, reducing mean time to investigate for complex multi-source AI-era incidents.</p></li><li><p><strong>Automated Response via Hyperautomation: </strong>When Purple AI verdicts, AI-SPM findings, or UAM-ingested third-party alerts confirm a threat, Hyperautomation executes response automatically across the full stack. Automate endpoint containment, identity/session revocation, or any connected tool via pre-built SaaS connectors, a no-code custom connector, or Private Network Access for on-premises automation.</p></li></ol><h3><strong>Key Takeaway / Recommendation</strong></h3><p>For CISOs running SentinelOne as their primary EDR and SIEM platform, the Singularity ecosystem provides a compelling integration hub for ECP point solutions: the open data lake architecture enables any Zone 1&#8211;5 vendor to feed SentinelOne without ripping out the incumbent. Purple AI&#8217;s agentic investigation capability is a meaningful analyst efficiency multiplier for ECP events, particularly for organizations that lack dedicated AI-era SOC expertise. Buyers should treat SentinelOne as the platform correlation and triage layer, augmented by purpose-built ECP vendors in Zones 1&#8211;4 for organizations with active agentic workloads. AI-SPM is the capability to watch for Zone 1/3 convergence as it matures.</p><h1><strong>Execution Strategy for the CISO and Security Team</strong></h1><h2>SACR Five Strategic Zone Expansion Observations</h2><ol><li><p><strong>SACR believes the zones converge into one architecture within ~3 years.</strong> Posture without enforcement is a report, enforcement without intent context is a false-positive machine and observability without prevention loses at machine speed. The winning stack is posture, inline gate, intent baseline and prevention enforcement in one user-mode agent.</p></li><li><p><strong>Local AI on the endpoint becomes a defining moat.</strong> The cloud-pipeline cost structure of incumbent EDR becomes a liability at agentic telemetry volume. CrowdStrike&#8217;s network-dependent AIDR architecture is the specific vulnerability startups are targeting, as is Bold&#8217;s on-device classifier thesis. Agentics and small language models and generative AI-enabled behavioral defenses are emerging to help defend the endpoint (eventually leading to on-endpoint agentic defense).</p></li><li><p><strong>Attribution becomes the new detection.</strong> The question shifts from &#8220;is this process malicious?&#8221; to &#8220;which prompt caused this action, and was it the user&#8217;s intent?&#8221;. Prompt and action lineage (Origin) and intent verification (like with Ent) are early versions of what becomes a required capability, the AI-era equivalent of the process tree.</p></li><li><p><strong>The agentless wedge is real but time-boxed.</strong> Vendors ride-the-EDR model wins the next 18 months on deployment friction. As enforcement (not visibility) becomes the buying criterion, API depth and real-time enforcement capabilities limits will be a deciding factor. Visibility is commoditizing, while enforcement, telemetry depth, federation and speed of context are where we see the margin settle over time.</p></li><li><p><strong>Platforms win the category, startups define it.</strong> The most likely outcome mirrors CSPM and Wiz: one or two startups (Zone 2/Zone 3 architectural natives best positioned) escape to platform scale while the rest are acquired. CrowdStrike AIDR&#8217;s attach rates prove the demand; the Koi acquisition shows platforms will buy rather than build the new zones.</p></li></ol><h1>Emerging Goal Pillars of Endpoint Control and Prevention</h1><p>The modern Endpoint Control and Prevention (ECP) framework is defined by four critical operational pillars:</p><ul><li><p><strong>App Posture &amp; Discovery:</strong> Continuous governance of the non-binary software supply chain, including extensions and plugins.</p></li><li><p><strong>AI/Agent Observability &amp; Attribution:</strong> Full traceability from natural language prompts to downstream tool execution.</p></li><li><p><strong>Intent, Identity, and Behavioral Inference:</strong> Shifting defense from binary monitoring to understanding the motivations behind user and agent actions.</p></li><li><p><strong>Real-time Policy Intervention:</strong> Surgical, inline enforcement that interrupts risky workflows mid-stream without disrupting legitimate business activity.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ieRe!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f7953a1-0c3f-401e-a96d-8febc85d87da_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ieRe!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f7953a1-0c3f-401e-a96d-8febc85d87da_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!ieRe!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f7953a1-0c3f-401e-a96d-8febc85d87da_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!ieRe!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f7953a1-0c3f-401e-a96d-8febc85d87da_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!ieRe!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f7953a1-0c3f-401e-a96d-8febc85d87da_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ieRe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f7953a1-0c3f-401e-a96d-8febc85d87da_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1f7953a1-0c3f-401e-a96d-8febc85d87da_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ieRe!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f7953a1-0c3f-401e-a96d-8febc85d87da_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!ieRe!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f7953a1-0c3f-401e-a96d-8febc85d87da_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!ieRe!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f7953a1-0c3f-401e-a96d-8febc85d87da_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!ieRe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f7953a1-0c3f-401e-a96d-8febc85d87da_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Investigation-Grade Evidence Required to Reconstruct Why, What and How</strong></h2><p>When an attack occurs, local telemetry is often the first and most detailed source of truth. However, raw endpoint logs (like standard Event IDs or process creation lines) lack the context required for sophisticated modern forensics. Endpoint agents must evolve into intelligent data collectors that correlate activities into a cohesive narrative. It isn&#8217;t enough to log that an administrative tool was run, a software or website was used; the endpoint must capture the prompt, tool, or automated workflow that triggered it. This allows SecOps to determine if a sequence of commands was executed by a human attacker, a benign developer, or an autonomous AI agent or toolchain.</p><h2><strong>Safer Enforcement: Moving Beyond Binary Decisions of Allow or Block through AI and Context Evaluation</strong></h2><p>Historically, endpoint detection and response (EDR) tools relied on binary enforcement where either a file was allowed to run, or the process was abruptly terminated and the machine isolated. This heavy-handed approach frequently breaks critical business workflows and alienates users. Modern endpoint defense requires graduated, human-centric controls integrated directly into the user interface. When a user attempts a risky but non-malicious action (e.g., running an unsigned IT tool or interacting with an unapproved API), the endpoint should inject real-time friction. This means warning the user, guiding them toward a safer alternative, or requiring a justified exception request that is immediately audited and passed to IT or GRC for review, rather than defaulting to a hard block. Contextual evaluation capabilities of LLMs have proven to reduce behavioral analysis of false positives by enabling cognitive evaluation by AI and agents, producing fewer false positives and more probabilistic-style responses.</p><h2><strong>Shifting from Posture Visibility to Proactive Posture Management and Control</strong></h2><p>The most disruptive change is the shift from endpoint security to posture security where the endpoint is no longer a boundary but a dynamic, self-optimizing component of the enterprise&#8217;s security ecosystem. The endpoint will be defined by identity, protected by identity, and continuously hardened by automated, intelligent systems. The technological building blocks are already in place: LLMs for reasoning, autonomous agents for self-healing, cloud-native and edge-native architectures for cross-platform security, and predictive posture for proactive defense. The next several years will see the convergence of these technologies into ECP, the next evolution of endpoint security. Endpoint defense must dynamically discover new micro-softwares and non-binary tools, rank their risk based on the permissions they hold (such as reading browser data, configurations, identities), evaluate source code repositories and supply chains for compromise, and apply proactive policy controls to prevent supply chain compromises arriving on endpoints.</p><h1><strong>SACR Future View: The Transition to Autonomous Endpoint Defense</strong></h1><p>By 2027, artificial intelligence and machine learning are fundamentally shifting Endpoint Detection and Response (EDR) from reactive, manual tools to proactive, autonomous, and self-healing systems conveying contextual information and telemetry in a semi-federated fashion.</p><p>The next horizon of endpoint defense is the migration of security intelligence from cloud-backend SIEM/SOAR clusters to the endpoint itself. As autonomous agents operate at machine speed, the traditional observe, export, analyze, respond cycle is becoming a structural failure point as the latency between detection and containment is now the primary attack vector.</p><p>The future of the endpoint is a self-governing runtime environment capable of endpoint and connected edge Inference. This requires a shift from passive telemetry collection to active, stateful full context defense, where endpoints utilize localized models (SLMs) and most likely include Edge services and integration with its telemetry to evaluate intent, govern non-binary software composition, and mediate agentic tool-chains in real-time, evolving from ECP to AECP over time.<br><br></p><h3><strong>ECP Zones as an Endpoint Control Plane</strong></h3><p>The architecture below presents The ECP Control Plane as a three-part architecture that moves from endpoint evidence to policy enforcement and verified outcomes. On the left, OS-layer signals, normalized endpoint context, and posture or behavioral state are consolidated into a validated endpoint evidence state. This evidence feeds a central, multi-zone enforcement model covering OS controls, software posture and supply chain governance, application-layer enforcement, agentic runtime visibility, intent and behavioral analysis, and data-centric enforcement. The model then applies zone-scoped write authority across endpoint agents, identity stores, browsers and SaaS applications, AI toolchains, and data egress layers, ultimately producing an enforced endpoint posture. A validation rail beneath the architecture logs each action, verifies the result against zone policy, preserves the evidence and authority record, and feeds the outcome back into the behavioral baseline.</p><h3>ECP Zones as an ECP Control Plane</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!n8RZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a031aa4-1471-4406-9603-907650d20e7f_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!n8RZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a031aa4-1471-4406-9603-907650d20e7f_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!n8RZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a031aa4-1471-4406-9603-907650d20e7f_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!n8RZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a031aa4-1471-4406-9603-907650d20e7f_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!n8RZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a031aa4-1471-4406-9603-907650d20e7f_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!n8RZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a031aa4-1471-4406-9603-907650d20e7f_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6a031aa4-1471-4406-9603-907650d20e7f_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!n8RZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a031aa4-1471-4406-9603-907650d20e7f_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!n8RZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a031aa4-1471-4406-9603-907650d20e7f_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!n8RZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a031aa4-1471-4406-9603-907650d20e7f_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!n8RZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a031aa4-1471-4406-9603-907650d20e7f_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>Key Requirements for Endpoint Control and Prevention</strong></h3><p>To enable autonomous Endpoint defense, security architectures must evolve to monitor these specific high-fidelity telemetry streams:</p><ul><li><p><strong>Prompt-to-Tool Lineage:</strong> Real-time tracking of input prompts, the specific tools invoked by the agent, and the associated data movement.</p></li><li><p><strong>Non-Binary Composition State:</strong> Continuous monitoring of browser extensions, IDE plugins, and dependency packages (npm, PyPI) that alter the endpoint&#8217;s function post-deployment.</p></li><li><p><strong>Local Intent Inference:</strong> Evaluation of natural language intent against security policies using lightweight, on-device models to detect semantic anomalies before execution.</p></li><li><p><strong>Identity State Context:</strong> Localized tracking of active session tokens, OAuth grants, and API keys, ensuring that sensitive identity artifacts are only accessible to authorized workflows.</p></li><li><p><strong>Dynamic Policy Enforcement:</strong> Monitoring and identification of shadow builder activity with automated, no-code and low-code workflows assembled by non-technical teams, to assess configuration and permission risks at the moment of creation.</p></li></ul><h2><strong>Market Map: Endpoint Control and Prevention</strong></h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!iXcP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f35690f-9994-4684-9c6a-ed2a1ffefd9a_2150x1200.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!iXcP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f35690f-9994-4684-9c6a-ed2a1ffefd9a_2150x1200.png 424w, https://substackcdn.com/image/fetch/$s_!iXcP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f35690f-9994-4684-9c6a-ed2a1ffefd9a_2150x1200.png 848w, https://substackcdn.com/image/fetch/$s_!iXcP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f35690f-9994-4684-9c6a-ed2a1ffefd9a_2150x1200.png 1272w, https://substackcdn.com/image/fetch/$s_!iXcP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f35690f-9994-4684-9c6a-ed2a1ffefd9a_2150x1200.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!iXcP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f35690f-9994-4684-9c6a-ed2a1ffefd9a_2150x1200.png" width="1456" height="813" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1f35690f-9994-4684-9c6a-ed2a1ffefd9a_2150x1200.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:813,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1220720,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://softwareanalyst.substack.com/i/208058321?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f35690f-9994-4684-9c6a-ed2a1ffefd9a_2150x1200.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!iXcP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f35690f-9994-4684-9c6a-ed2a1ffefd9a_2150x1200.png 424w, https://substackcdn.com/image/fetch/$s_!iXcP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f35690f-9994-4684-9c6a-ed2a1ffefd9a_2150x1200.png 848w, https://substackcdn.com/image/fetch/$s_!iXcP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f35690f-9994-4684-9c6a-ed2a1ffefd9a_2150x1200.png 1272w, https://substackcdn.com/image/fetch/$s_!iXcP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f35690f-9994-4684-9c6a-ed2a1ffefd9a_2150x1200.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><h2>Future View: Endpoint Control and Prevention (ECP)</h2><p>The integration of advanced AI and capabilities such as model context protocol driving the federation of agent-driven integrations are driving several major transformations in how EDR operates:</p><p>&#9; &#9;<br><strong>The Rise of Autonomous Agents</strong></p><p>Endpoint security is entering its fifth generation, characterized by autonomous security agents. Instead of simply alerting human analysts, agentic AI is being deeply embedded into daily security operations, allowing systems to analyze massive volumes of heterogeneous data, make independent decisions about threat severity, and automatically trigger defensive reactions. This drastically reduces the mean time to respond (MTTR) from hours or days to just minutes, which is critical for containing fast-moving threats like ransomware.</p><p><strong>New Attack Vectors Targeting AI</strong></p><p>As AI becomes central to ECP, the AI models and agents themselves become high-value targets. Security teams must now defend against adversarial machine learning, where attackers manipulate input data to deceive AI detection algorithms. Because AI agents can crawl data and execute shell commands, they are vulnerable to indirect prompt injection attacks hidden within files or web pages. Modern ECP platforms are expanding to monitor AI usage, protect against data leakage, and secure the underlying AI infrastructure.</p><p><strong>Advanced Behavioral Detection and LLM Integration</strong></p><p>AI is replacing outdated signature-based detection with sophisticated behavioral analytics. EDR platforms are leveraging a combination of supervised learning, unsupervised learning, reinforcement learning (RL), and deep learning (DL) neural networks to recognize complex, novel attack patterns that traditional tools miss. Furthermore, Large Language Models (LLMs) are being deployed to parse massive amounts of unstructured data, such as chat logs, security logs, and emails to classify anomalies and conduct post-incident analysis by revealing an attacker&#8217;s motives and methods.<br><br></p><p><strong>Self-Healing Endpoints and Automated Remediation</strong></p><p>Perhaps the most significant advancement is the introduction of self-healing capabilities. When an endpoint is compromised, AI-driven ECP can automatically isolate the device, notify identity systems and backend telemetry via model context protocol (MCP), terminate malicious processes, remove persistence mechanisms, and roll back unauthorized system changes or encrypted files to a known-good, pre-infection state. This automated remediation and contextual sharing and response limits the blast radius of an attack and dramatically cuts down on the need to manually re-image devices.</p><p><strong>Adaptive Security Policies</strong></p><p>Rather than relying on rigid, static rules, AI empowers EDR and cloud security systems with continuous self-learning. These systems can dynamically adjust access controls, firewall settings, and anomaly thresholds in real time based on evolving attack patterns, ensuring resilience against zero-day exploits and environmental changes.</p><p><strong>Human-Machine Collaboration</strong></p><p>Despite the push for autonomy, a major theme for 2026 is balancing AI with human control so that algorithms do not go unchecked. The most effective SOCs utilize a collaborative model: autonomous systems handle routine threat containment and initial data correlation, while escalating the most sophisticated attacks to skilled human analysts. Human analysts then provide feedback that is used to continuously train and refine the machine learning models, improving future detection accuracy and reducing false positives.</p><p><strong>Future View: Agentic Endpoint Control and Prevention (A-ECP)</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5UsP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faad2bcff-aa39-441c-ad07-a864a893b006_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5UsP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faad2bcff-aa39-441c-ad07-a864a893b006_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!5UsP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faad2bcff-aa39-441c-ad07-a864a893b006_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!5UsP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faad2bcff-aa39-441c-ad07-a864a893b006_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!5UsP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faad2bcff-aa39-441c-ad07-a864a893b006_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5UsP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faad2bcff-aa39-441c-ad07-a864a893b006_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/aad2bcff-aa39-441c-ad07-a864a893b006_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!5UsP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faad2bcff-aa39-441c-ad07-a864a893b006_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!5UsP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faad2bcff-aa39-441c-ad07-a864a893b006_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!5UsP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faad2bcff-aa39-441c-ad07-a864a893b006_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!5UsP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faad2bcff-aa39-441c-ad07-a864a893b006_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Implications for CISOs / Buyers: 30/90 Day Plan</strong></h2><p>Buyer strategy should assume rapid convergence: incumbent EDR will add more app-layer posture and identity context, while posture/agent-control vendors will add response and evidence features. CISOs should leverage the SACR 5 Zones framework as the primary architectural tool for identifying coverage gaps and mapping their infrastructure needs. The practical evaluation lens is: evidence quality, intervention safety, and measurable exposure reduction.</p><h3><strong>30 Days: Assess and Baseline</strong></h3><ol><li><p><strong>Audit existing security coverage against the SACR 5 Zones framework</strong> to identify specific architectural coverage gaps and avoid redundant tooling.</p></li><li><p><strong>Treat classic EDR as baseline plumbing, not the strategic differentiator.</strong> Reallocate budget and evaluation energy toward application-layer posture, agent observability, and intervention safety.</p></li><li><p><strong>Run privacy and governance diligence early.</strong> Recognize that intent layers require new, sensitive telemetry (e.g., interaction traces). Validate your organization&#8217;s standards for minimization, purpose limitation, and auditability.</p></li><li><p><strong>Track pricing/model changes as a strategic signal.</strong> Monitor endpoint per-seat pricing compression, which signals detection commoditization. Look for consumption/usage models that better align with modern, bursty agentic workflows.</p></li></ol><h3><strong>90 Days: Validate and Operationalize</strong></h3><ol start="5"><li><p><strong>Demand prompt-to-action attribution in any agentic tooling environment.</strong> Ensure any selected vendor can connect intent/prompt &#8594; action trace; without this, investigations will fail at machine speed.</p></li><li><p><strong>Prioritize enforcement primitives that are surgical.</strong> Shift away from blanket block/allow strategies. Evaluate flow-level, policy-based interventions and exceptional UX that won&#8217;t break critical business workflows.</p></li><li><p><strong>Evaluate autonomy. </strong>Evaluate autonomy as an operations capability, emphasizing the integration of new ECP signals into existing SOC workflows rather than mere validation. Ensure that these signals are actionable in your current incident response processes.</p></li><li><p><strong>Prepare for category convergence.</strong> As EAPM/posture vendors add interventions and intent vendors add posture, focus your final evaluation criteria on the quality of control primitives and evidence.</p></li></ol><p></p><div><hr></div><p></p><h3><strong>SACR Key Takeaway:</strong></h3><p>For CISOs, the transition to Endpoint Control and Prevention (ECP) is not merely a tool upgrade but a strategic necessity to reclaim visibility in an era of AI-driven, machine-speed threats. As the center of gravity shifts from process-based detection to interaction-centric governance, the key takeaway is that your endpoint strategy must prioritize prompt-to-action attribution and granular, surgical enforcement over legacy, binary blocking. </p><p>By pivoting to an ECP-ready/AI oriented architecture, focused on software supply chain posture, identity-centric context, and autonomous behavioral inference, you can effectively reduce the blast radius of agentic workflows while ensuring your security posture remains resilient against industrialized, high-speed exploitation.</p><div><hr></div><h2><strong>References</strong></h2><ul><li><p><a href="https://www.deepwatch.com/labs/nx-breach-a-story-of-supply-chain-compromise-and-ai-agent-betrayal/">Deepwatch </a></p></li><li><p><a href="https://www.kiteworks.com/cybersecurity-risk-management/ai-supply-chain-breach-pattern/">Kiteworks</a></p></li><li><p><a href="https://softwareanalyst.substack.com/t/data-and-ai-security">SACR Data &amp; AI security </a></p></li><li><p><a href="https://purplesec.us/resources/ai-security-glossary/ai-supply-chain-compromise/">Supply Chain Compromise</a></p></li></ul><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Software Analyst Cyber Research! Subscribe for free to receive new cybersecurity research and analysis on emerging categories.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div class="directMessage button" data-attrs="{&quot;userId&quot;:6770950,&quot;userName&quot;:&quot;SACR&quot;,&quot;canDm&quot;:null,&quot;dmUpgradeOptions&quot;:null,&quot;isEditorNode&quot;:true}" data-component-name="DirectMessageToDOM"></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&quot;,&quot;text&quot;:&quot;Share Software Analyst Cyber Research&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share Software Analyst Cyber Research</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/p/the-ciso-guide-to-endpoint-control/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/p/the-ciso-guide-to-endpoint-control/comments"><span>Leave a comment</span></a></p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/p/the-ciso-guide-to-endpoint-control?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading Software Analyst Cyber Research! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/p/the-ciso-guide-to-endpoint-control?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/p/the-ciso-guide-to-endpoint-control?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><p></p>]]></content:encoded></item><item><title><![CDATA[The Next Evolution of Cyber Deception in SecOps]]></title><description><![CDATA[Why SecOps teams are exploring adaptive defenses that shape attacker decisions before compromise escalates. How security teams can disrupt reconnaissance, and reduce attacker certainty]]></description><link>https://softwareanalyst.substack.com/p/the-next-evolution-of-cyber-deception</link><guid isPermaLink="false">https://softwareanalyst.substack.com/p/the-next-evolution-of-cyber-deception</guid><dc:creator><![CDATA[SACR]]></dc:creator><pubDate>Mon, 20 Jul 2026 16:23:43 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!ppc2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f379c71-43dc-40a3-a16e-107edd508742_1456x738.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h1><span>Executive Summary</span></h1><p><span>Cybersecurity is entering a new phase where defensive advantage may depend less on detecting attackers and more on influencing them. As AI compresses attack timelines and organizations deploy growing numbers of autonomous systems, security architectures built around human investigation and response are coming under increasing pressure. A new generation of deception technologies is emerging to address this shift by moving beyond static decoys toward adaptive systems designed to shape attacker behavior in real time.</span></p><p><span>This report argues that agentic deception represents more than an incremental evolution of traditional deception technologies. It reflects a broader architectural shift from passive observation toward active environmental influence. Instead of waiting to detect malicious activity after it has begun, agentic deception seeks to manipulate the information, context, and decision-making processes that attackers, whether human or autonomous, rely upon throughout an intrusion. While the category remains in its early stages, it introduces an important question for security leaders: if offensive operations continue to accelerate, should defensive architectures evolve from observing attacks to actively shaping them?</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ppc2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f379c71-43dc-40a3-a16e-107edd508742_1456x738.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ppc2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f379c71-43dc-40a3-a16e-107edd508742_1456x738.webp 424w, https://substackcdn.com/image/fetch/$s_!ppc2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f379c71-43dc-40a3-a16e-107edd508742_1456x738.webp 848w, https://substackcdn.com/image/fetch/$s_!ppc2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f379c71-43dc-40a3-a16e-107edd508742_1456x738.webp 1272w, https://substackcdn.com/image/fetch/$s_!ppc2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f379c71-43dc-40a3-a16e-107edd508742_1456x738.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ppc2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f379c71-43dc-40a3-a16e-107edd508742_1456x738.webp" width="1456" height="738" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8f379c71-43dc-40a3-a16e-107edd508742_1456x738.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:738,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:79080,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://softwareanalyst.substack.com/i/207459237?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f379c71-43dc-40a3-a16e-107edd508742_1456x738.webp&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ppc2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f379c71-43dc-40a3-a16e-107edd508742_1456x738.webp 424w, https://substackcdn.com/image/fetch/$s_!ppc2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f379c71-43dc-40a3-a16e-107edd508742_1456x738.webp 848w, https://substackcdn.com/image/fetch/$s_!ppc2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f379c71-43dc-40a3-a16e-107edd508742_1456x738.webp 1272w, https://substackcdn.com/image/fetch/$s_!ppc2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f379c71-43dc-40a3-a16e-107edd508742_1456x738.webp 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>The report examines this emerging category through the lens of Acalvio, one of several vendors exploring adaptive deception across identity, cloud, and AI-enabled environments. Acalvio&#8217;s platform serves as a case study for understanding how deception technologies are evolving, where they may offer strategic value, and which questions remain unresolved as the market matures. The premise underlying this category is that in a machine-speed environment, visibility alone arrives too late to change outcomes. If that premise holds, advantage shifts toward organizations that can actively shape what an attacker perceives, not merely observe what an attacker does.</span></p><h2><span>Key Takeaways For Readers </span></h2><ul><li><p><span>Agentic deception represents an architectural shift, extending deception from static assets toward adaptive systems that can influence attacker behavior during reconnaissance and early intrusion stages.</span></p></li><li><p><span>AI changes both sides of the security equation. Organizations must defend not only against autonomous attackers but also protect rapidly expanding AI-enabled enterprise environments.</span></p></li><li><p><span>Environmental influence is emerging as a complementary security control. Deception should be evaluated alongside detection, response, identity, and runtime protections rather than as a replacement for them.</span></p></li><li><p><span>The market remains early. While platforms such as Acalvio demonstrate how adaptive deception may evolve, organizations should prioritize measurable operational outcomes, independent validation, and integration with existing security architectures over visionary claims alone.</span></p></li></ul><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Software Analyst Cyber Research! Subscribe for free to receive new cybersecurity reports across SecOps, Identity, Cloud and Data/AI</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><div><hr></div><h2><span>What Security Leaders Should Do</span></h2><p><span>Security leaders should begin evaluating deception as an architectural capability instead of a niche point product. As part of that evaluation, organizations should:</span></p><ul><li><p><span>Assess whether existing security controls can operate effectively against automated attacks.</span></p></li><li><p><span>Determine where adaptive deception can complement existing detection, identity, and response capabilities.</span></p></li><li><p><span>Evaluate how deception platforms integrate across cloud, identity, and AI-enabled environments.</span></p></li><li><p><span>Request independent evidence of operational effectiveness, including customer deployments, MITRE ATT&amp;CK or ATLAS mappings, and measurable production outcomes.</span></p></li><li><p><span>Consider deception as one component of a broader strategy for reducing attacker certainty rather than simply increasing defensive visibility.</span></p></li></ul><p></p><p></p><div><hr></div><h1><strong><span>Why Deception Is Returning</span></strong></h1><p><span>For much of the past decade, deception occupied a relatively specialized place within enterprise security architectures. Honeypots, honeytokens, and decoy systems proved valuable for generating high-confidence alerts and exposing attacker behavior, but they were often deployed selectively, required ongoing maintenance, and rarely became foundational components of security programs. As organizations invested heavily in prevention, detection, and response technologies, deception remained an effective but niche capability.</span></p><p><span>That context is beginning to change.</span></p><p><span>Two parallel shifts are reshaping how defenders think about the role of deception. The first is the rapid acceleration of offensive operations through automation and AI. Recent industry reports indicate the time to detect an active breach remains substantial, approximately eight months (241 days) on average, per IBM&#8217;s 2025 report, underscoring how wide the gap remains between attacker speed and defender response time. The luxury of time, the days or weeks defenders once used for investigation, has diminished significantly. Machine-speed attacks have compressed the window of opportunity. The 2026 Verizon DBIR further corroborates this trend, as does the graph below. This graph from Zero Day Clock depicts the vast change of pace of vulnerability and exploit weaponization. This is one of the key drivers to moving to new defensive measures. Note: 2026 data reflects partial-year findings as of July 2026.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ygh6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf0f0e75-89d7-475d-a2a8-0e399a2519c4_1023x870.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ygh6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf0f0e75-89d7-475d-a2a8-0e399a2519c4_1023x870.png 424w, https://substackcdn.com/image/fetch/$s_!ygh6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf0f0e75-89d7-475d-a2a8-0e399a2519c4_1023x870.png 848w, https://substackcdn.com/image/fetch/$s_!ygh6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf0f0e75-89d7-475d-a2a8-0e399a2519c4_1023x870.png 1272w, https://substackcdn.com/image/fetch/$s_!ygh6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf0f0e75-89d7-475d-a2a8-0e399a2519c4_1023x870.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ygh6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf0f0e75-89d7-475d-a2a8-0e399a2519c4_1023x870.png" width="1023" height="870" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/df0f0e75-89d7-475d-a2a8-0e399a2519c4_1023x870.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:870,&quot;width&quot;:1023,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ygh6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf0f0e75-89d7-475d-a2a8-0e399a2519c4_1023x870.png 424w, https://substackcdn.com/image/fetch/$s_!ygh6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf0f0e75-89d7-475d-a2a8-0e399a2519c4_1023x870.png 848w, https://substackcdn.com/image/fetch/$s_!ygh6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf0f0e75-89d7-475d-a2a8-0e399a2519c4_1023x870.png 1272w, https://substackcdn.com/image/fetch/$s_!ygh6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf0f0e75-89d7-475d-a2a8-0e399a2519c4_1023x870.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Source: <em>Image from zerodayclock.com. </em></figcaption></figure></div><p><span>The significance of this trend is not in any specific data point. The significance is the trajectory: a time-to-exploit window that has collapsed from years to hours highlights a future in which portions of the attack lifecycle operate at machine speed. As attack timelines compress, the effectiveness of defensive models built around human investigation and decision-making may come under increasing pressure. This dynamic sits at the center of the broader discussion surrounding adaptive defense, autonomous response, and agentic deception.</span></p><p><span>The second shift is occurring inside the enterprise itself. Organizations are rapidly deploying AI assistants, autonomous workflows, retrieval-augmented generation (RAG) systems, and Model Context Protocol (MCP) environments to improve productivity and automate business processes. These systems create a fundamentally different attack surface. Instead of exploiting software vulnerabilities alone, adversaries may seek to manipulate prompts, poison context, abuse connected tools, or influence autonomous decision-making. As AI becomes embedded throughout enterprise operations, security teams must consider not only how to protect traditional infrastructure, but also how to protect systems that reason, retrieve information, and act on behalf of users.</span></p><p><span>Taken together, these trends are changing the assumptions that have guided cybersecurity for decades. Security architectures have historically focused on preventing compromise where possible, detecting malicious activity when prevention fails, and responding before attackers achieve their objectives. That sequence assumes defenders have sufficient time to observe events, investigate them, and coordinate a response. As attack timelines continue to compress, that assumption becomes difficult to sustain.</span></p><p><strong><span>The New Security Reality</span></strong></p><p><span>Defenders must now manage a future where three distinct elements coexist:</span></p><ul><li><p><strong><span>Autonomous Attackers:</span></strong><span> AI systems that can execute exploits at scale.</span></p></li><li><p><strong><span>Autonomous Enterprise Systems:</span></strong><span> The AI tools that power our business processes.</span></p></li><li><p><strong><span>Automated Security Controls:</span></strong><span> The defense mechanisms attempting to keep pace.</span></p></li></ul><p><span>The remainder of this note focuses on the interaction between the first two, and on whether the third category can evolve from passive detection into active environmental influence.</span></p><p><strong><span>Why Visibility Isn&#8217;t Enough</span></strong></p><p><span>While it remains unclear whether the future of defense lies in deception, autonomous response, or adaptive security, one truth is emerging: Cybersecurity is shifting. In this new world, speed, adaptability, and active decision-making are as critical as visibility.</span></p><p><span>The core question for future security architecture is simple: Can we build mechanisms that not only detect and respond to threats, but actively influence the environment, data, and decisions that adversaries rely on?</span></p><p><span>This does not mean detection and response are becoming obsolete. Visibility, investigation, and remediation remain essential components of every mature security program. However, organizations are exploring whether additional controls can operate earlier in the attack lifecycle, reducing attacker confidence and influencing outcomes before a compromise is fully established.</span></p><p><span>This renewed interest has brought deception technologies back into focus.</span></p><p><span>Unlike traditional security controls, deception is designed to influence what attackers perceive about an environment. Rather than simply identifying malicious activity after it occurs, deception seeks to shape reconnaissance, redirect adversary behavior, and introduce uncertainty into the information attackers rely upon to make decisions. In an era where both attackers and enterprise systems are becoming more autonomous, that ability to influence the environment may become an valuable complement to detection and response.</span></p><p><span>Whether adaptive deception ultimately becomes a foundational component of enterprise security remains an open question. The category is still maturing, and many of its architectural claims require broader operational validation. What is becoming clear, however, is that deception is no longer being evaluated solely as a collection of honeypots or decoy credentials. It is increasingly being considered as part of a broader discussion about how defensive architectures must evolve as automation transforms both sides of the cybersecurity equation.</span></p><h1><strong><span>From Honeypots to Agentic Deception</span></strong></h1><p><span>Deception is one of cybersecurity&#8217;s oldest defensive concepts. Long before today&#8217;s discussions of AI-native security, organizations deployed honeypots, decoy services, and honeytokens to expose attacker activity that would otherwise remain invisible. Their value stemmed from a simple principle: legitimate users should never interact with deceptive assets. When they did, defenders gained a high-confidence signal that malicious reconnaissance or unauthorized access was underway.</span></p><p><span>Despite these strengths, deception remained a specialized capability for much of the last two decades. Traditional deployments often required careful planning, manual placement, and ongoing maintenance to remain believable as production environments evolved. As cloud adoption accelerated and enterprise infrastructure became dynamic, maintaining realistic deception environments grew more operationally intensive. Many organizations concluded that deception was valuable for targeted use cases, but difficult to operate as a broad architectural control.</span></p><p><span>Today, several trends are prompting a reassessment of that conclusion.</span></p><p><span>Enterprise environments have become significantly more distributed across cloud platforms, SaaS applications, identity providers, and hybrid infrastructure. At the same time, attackers have become more reliant on automation to accelerate reconnaissance, privilege discovery, and lateral movement. Instead of manually exploring environments over days or weeks, adversaries can now leverage automation to identify relationships, enumerate identities, and discover attack paths at a pace that challenges traditional investigative workflows.</span></p><p><span>This convergence changes the requirements for deception itself. Static decoys that are updated periodically may no longer be sufficient in environments that change continuously. In light of this, organizations are asking whether deception can become adaptive, automatically reflecting changes in infrastructure, identities, cloud resources, and AI-enabled workflows without extensive manual intervention.</span></p><p><span>The evolution of deception can therefore be understood as a progression through several architectural stages.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!O86J!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc755a9d8-a5bb-47c1-9259-3e187e6e3972_1792x1112.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!O86J!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc755a9d8-a5bb-47c1-9259-3e187e6e3972_1792x1112.png 424w, https://substackcdn.com/image/fetch/$s_!O86J!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc755a9d8-a5bb-47c1-9259-3e187e6e3972_1792x1112.png 848w, https://substackcdn.com/image/fetch/$s_!O86J!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc755a9d8-a5bb-47c1-9259-3e187e6e3972_1792x1112.png 1272w, https://substackcdn.com/image/fetch/$s_!O86J!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc755a9d8-a5bb-47c1-9259-3e187e6e3972_1792x1112.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!O86J!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc755a9d8-a5bb-47c1-9259-3e187e6e3972_1792x1112.png" width="1456" height="904" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c755a9d8-a5bb-47c1-9259-3e187e6e3972_1792x1112.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:904,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!O86J!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc755a9d8-a5bb-47c1-9259-3e187e6e3972_1792x1112.png 424w, https://substackcdn.com/image/fetch/$s_!O86J!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc755a9d8-a5bb-47c1-9259-3e187e6e3972_1792x1112.png 848w, https://substackcdn.com/image/fetch/$s_!O86J!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc755a9d8-a5bb-47c1-9259-3e187e6e3972_1792x1112.png 1272w, https://substackcdn.com/image/fetch/$s_!O86J!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc755a9d8-a5bb-47c1-9259-3e187e6e3972_1792x1112.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>This progression reflects more than incremental product development. It illustrates a broader shift in defensive philosophy. Earlier deception technologies focused primarily on </span><strong><span>revealing attacker activity</span></strong><span>. Emerging approaches seek to </span><strong><span>shape attacker decision-making</span></strong><span> by manipulating the information available during reconnaissance, credential discovery, and lateral movement.</span></p><p><span>Importantly, agentic deception should not be viewed as a replacement for existing security controls. Organizations still require prevention, detection, investigation, and response capabilities to manage modern cyber risk. Instead, deception is being evaluated as an additional architectural layer that operates earlier in the attack lifecycle, complementing identity security, endpoint detection and response (EDR), extended detection and response (XDR), and cloud security by influencing attacker behavior before objectives are achieved.</span></p><p><span>Not every vendor defines this evolution in the same way. Some continue to emphasize high-confidence detection through deception. Others focus on attack path disruption, moving target defense, or identity-centric deception. More recently, several vendors have begun extending deception into AI-enabled environments, including agent frameworks, retrieval systems, and Model Context Protocol (MCP) deployments. While implementation strategies differ, they share a common objective: reducing attacker certainty and increasing the cost of successful reconnaissance.</span></p><p><span>Viewed through this broader lens, agentic deception is best understood not as a single product category, but as one possible direction in the evolution of adaptive cyber defense. Whether it ultimately becomes a foundational component of enterprise security will depend on its ability to demonstrate measurable operational value at scale.</span></p><p></p><p><span>The market for deception technologies is still undergoing a period of architectural convergence. While vendors use terms such as </span><em><span>adaptive</span></em><span>, </span><em><span>dynamic</span></em><span>, or </span><em><span>agentic</span></em><span> deception, there is no universally accepted definition of these concepts, and implementation maturity varies considerably across the market. Organizations should therefore evaluate vendor claims based on demonstrable operational outcomes rather than terminology alone. The defining characteristic of this emerging category is not the presence of AI, but the extent to which deception can adapt to changing environments, integrate with existing security operations, and measurably influence attacker behavior without introducing prohibitive operational overhead.</span></p><div><hr></div><p></p><h1><strong><span>Defining the Agentic Deception Category</span></strong></h1><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!sc3P!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d3b04d4-e638-4e45-8cb9-d0b2c2eed3a9_1456x819.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!sc3P!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d3b04d4-e638-4e45-8cb9-d0b2c2eed3a9_1456x819.png 424w, https://substackcdn.com/image/fetch/$s_!sc3P!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d3b04d4-e638-4e45-8cb9-d0b2c2eed3a9_1456x819.png 848w, https://substackcdn.com/image/fetch/$s_!sc3P!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d3b04d4-e638-4e45-8cb9-d0b2c2eed3a9_1456x819.png 1272w, https://substackcdn.com/image/fetch/$s_!sc3P!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d3b04d4-e638-4e45-8cb9-d0b2c2eed3a9_1456x819.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!sc3P!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d3b04d4-e638-4e45-8cb9-d0b2c2eed3a9_1456x819.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3d3b04d4-e638-4e45-8cb9-d0b2c2eed3a9_1456x819.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!sc3P!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d3b04d4-e638-4e45-8cb9-d0b2c2eed3a9_1456x819.png 424w, https://substackcdn.com/image/fetch/$s_!sc3P!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d3b04d4-e638-4e45-8cb9-d0b2c2eed3a9_1456x819.png 848w, https://substackcdn.com/image/fetch/$s_!sc3P!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d3b04d4-e638-4e45-8cb9-d0b2c2eed3a9_1456x819.png 1272w, https://substackcdn.com/image/fetch/$s_!sc3P!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d3b04d4-e638-4e45-8cb9-d0b2c2eed3a9_1456x819.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>Cybersecurity categories often evolve faster than the language used to describe them. Terms such as </span><em><span>AI-native security</span></em><span>, </span><em><span>adaptive defense</span></em><span>, </span><em><span>runtime protection</span></em><span>, and </span><em><span>agentic security</span></em><span> are appearing in vendor messaging, yet they frequently describe overlapping capabilities and not clearly defined markets. Deception technologies are experiencing a similar transition. While many vendors now position their platforms as adaptive or autonomous, there is not yet a widely accepted definition of what distinguishes </span><strong><span>agentic deception</span></strong><span> from earlier generations of deception technology.</span></p><p><span>SACR defines </span><strong><span>agentic deception</span></strong><span> as:</span></p><blockquote><p><strong><span>An adaptive security architecture that continuously modifies deceptive assets, environmental signals, and engagement pathways to influence attacker behavior throughout the attack lifecycle.</span></strong></p></blockquote><p><span>Unlike traditional deception technologies, which primarily function as detection mechanisms, agentic deception seeks to shape the attacker&#8217;s understanding of the environment itself. Its objective is not simply to identify malicious activity after reconnaissance has begun, but to reduce the accuracy of the information an adversary uses to make decisions. In this model, deception becomes an active participant in the engagement rather than a passive tripwire waiting to be triggered.</span></p><p><span>This distinction is particularly important as enterprise environments become more dynamic. Cloud infrastructure changes continuously. Identity relationships evolve. AI agents interact with external tools and data sources. In these environments, static deception assets can lose relevance if they fail to reflect operational reality. Agentic deception attempts to address this challenge by continuously adapting deceptive resources and engagement strategies as the environment and attacker behavior change.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Szp9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf7c4190-33d4-4de4-8e37-bda782270641_1672x941.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Szp9!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf7c4190-33d4-4de4-8e37-bda782270641_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!Szp9!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf7c4190-33d4-4de4-8e37-bda782270641_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!Szp9!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf7c4190-33d4-4de4-8e37-bda782270641_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!Szp9!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf7c4190-33d4-4de4-8e37-bda782270641_1672x941.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Szp9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf7c4190-33d4-4de4-8e37-bda782270641_1672x941.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bf7c4190-33d4-4de4-8e37-bda782270641_1672x941.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Szp9!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf7c4190-33d4-4de4-8e37-bda782270641_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!Szp9!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf7c4190-33d4-4de4-8e37-bda782270641_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!Szp9!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf7c4190-33d4-4de4-8e37-bda782270641_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!Szp9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf7c4190-33d4-4de4-8e37-bda782270641_1672x941.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>At a conceptual level, agentic deception combines several established security disciplines:</span></p><ul><li><p><strong><span>Deception technology</span></strong><span>, to create believable but controlled assets that reveal malicious activity.</span></p></li><li><p><strong><span>Moving target defense</span></strong><span>, to reduce attacker confidence by limiting the reliability of environmental observations.</span></p></li><li><p><strong><span>Threat intelligence</span></strong><span>, to increase the realism and relevance of deceptive environments.</span></p></li><li><p><strong><span>Automation and AI</span></strong><span>, to continuously adapt deception without requiring extensive manual administration.</span></p></li></ul><p><span>None of these capabilities is entirely new on its own. The architectural shift lies in bringing them together as a coordinated system designed to influence adversary decision-making throughout an engagement rather than performing isolated security functions.</span></p><h2><strong><span>What Agentic Deception Is Not</span></strong></h2><p><span>As the category develops, it is equally important to define what agentic deception does </span><strong><span>not</span></strong><span> encompass.</span></p><ul><li><p><span>It is </span><strong><span>not</span></strong><span> a replacement for endpoint detection and response (EDR), extended detection and response (XDR), or security information and event management (SIEM). Those platforms remain essential for telemetry collection, investigation, correlation, and incident response.</span></p></li><li><p><span>It is </span><strong><span>not</span></strong><span> security orchestration, automation, and response (SOAR), which focuses on automating defensive workflows after alerts have been generated.</span></p></li><li><p><span>It is </span><strong><span>not</span></strong><span> breach and attack simulation (BAS), whose primary objective is to assess defensive readiness through controlled testing and not just influence live adversary behavior.</span></p></li></ul><p><span>Nor should it be viewed as a substitute for identity security, cloud security, or AI runtime protections. Instead, agentic deception is best understood as an architectural layer that complements these capabilities by introducing uncertainty into the reconnaissance and decision-making processes that precede many successful attacks.</span></p><p><strong><span>Where Agentic Deception Fits</span></strong></p><p><em><span>Rather than replacing existing security controls, agentic deception introduces an adaptive layer designed to influence attacker behavior before traditional detection and response processes become necessary.</span></em></p><p><strong><span>Why This Matters for Security Leaders</span></strong></p><p><span>The emergence of agentic deception reflects a broader shift in how security leaders are thinking about defensive architecture. Historically, organizations have measured the effectiveness of security controls by their ability to prevent compromise, detect malicious activity, or accelerate response. Historically, cybersecurity has optimized for visibility. However, visibility alone arrives too late to change outcomes. Adaptive deception introduces a second optimization objective: attacker uncertainty. Security architectures that maximize visibility without affecting attacker confidence will struggle against autonomous adversaries capable of making decisions at machine speed.</span></p><p><span>Whether this architectural approach ultimately becomes a standard component of enterprise security remains uncertain. The market is still early, terminology continues to evolve, and independent operational validation remains limited. Nevertheless, the underlying concept, influencing attacker behavior and not just simply observing it, represents a meaningful evolution in defensive thinking and provides a useful framework for evaluating the next generation of deception platforms.</span></p><p><strong><span>SACR Analysis</span></strong></p><p><span>The defining characteristic of agentic deception is </span><strong><span>not the use of AI</span></strong><span>. Many security products now incorporate AI-assisted analytics or automation without fundamentally changing how they influence attacker behavior. What distinguishes this emerging category is the combination of continuous adaptation, environmental awareness, and behavioral influence into a unified defensive architecture.</span></p><p><span>Organizations evaluating vendor claims should therefore focus less on whether a platform is marketed as </span><em><span>agentic</span></em><span> and more on whether it demonstrably adapts to changing environments, integrates with existing security operations, and measurably alters attacker outcomes. As with many emerging cybersecurity categories, marketing terminology has evolved faster than common industry definitions. Buyers should evaluate architectural capabilities and operational evidence and not just product labels.</span></p><h1><strong><span>Architectural Principles of Adaptive Deception</span></strong></h1><p><span>As deception technologies evolve beyond static decoys, they are being designed around a different objective. Instead of functioning solely as isolated detection mechanisms, emerging platforms seek to influence how attackers perceive, interpret, and navigate enterprise environments. While implementations vary across vendors, several architectural principles are beginning to define this new generation of adaptive deception.</span></p><p><span>These principles represent a shift in defensive philosophy rather than a single product architecture. Organizations evaluating deception platforms should consider how effectively vendors operationalize each capability, regardless of whether they use identical terminology.</span></p><p><strong><span>Environmental Influence, Not Passive Observation</span></strong></p><p><span>Traditional security architectures are designed to observe malicious activity as accurately and as early as possible. Firewalls block unauthorized access, endpoint agents generate telemetry, and SIEM platforms aggregate evidence for investigation. Each control contributes to understanding what has occurred.</span></p><p><span>Adaptive deception introduces a complementary objective: influencing what attackers believe about the environment before they achieve their objectives.</span></p><p><span>Instead of treating reconnaissance as a precursor to compromise, adaptive deception treats it as an opportunity to shape attacker perception. By presenting carefully controlled environmental signals, deceptive credentials, services, identities, or infrastructure, defenders can reduce the reliability of the information attackers depend upon to make decisions.</span></p><p><span>This does not eliminate the need for detection or response. Instead, it seeks to improve defensive outcomes by reducing attacker certainty earlier in the engagement.</span></p><p><strong><span>Reconnaissance Becomes a Defensive Opportunity</span></strong></p><p><span>Reconnaissance has historically favored the attacker. Service banners, Active Directory relationships, cloud metadata, API responses, storage locations, and identity relationships all contribute to an ever more accurate understanding of the target environment. Every successful observation improves the attacker&#8217;s ability to prioritize exploitation and lateral movement.</span></p><p><span>Adaptive deception attempts to invert that advantage, instead of allowing reconnaissance to function solely as an intelligence-gathering activity, deception introduces controlled uncertainty into the process. If attackers cannot reliably distinguish production assets from deceptive ones, the quality of their intelligence begins to degrade. The objective is not to prevent reconnaissance entirely, but to reduce its usefulness.</span></p><p><span>Every interaction becomes an opportunity to gather intelligence, influence attacker decision-making, and improve future defensive responses.</span></p><p><strong><span>Adaptation Becomes More Important Than Static Coverage</span></strong></p><p><span>One of the historical limitations of deception has been operational maintenance. Static deception environments often require administrators to manually deploy and update decoys as infrastructure changes. In modern enterprises, where cloud resources, identities, workloads, and AI services evolve continuously, manually maintaining believable deception assets becomes yet more difficult.</span></p><p><span>Adaptive deception seeks to address this challenge by automating portions of the deception lifecycle. Rather than relying on periodically refreshed assets, platforms attempt to adjust deception in response to environmental changes, infrastructure updates, or observed attacker behavior. The degree of automation varies significantly across vendors, but the underlying objective remains consistent: deception should evolve alongside the environment it is intended to protect.</span></p><p><span>This capability is particularly important in cloud-native environments, where infrastructure may be created and retired in minutes instead of months.</span></p><p><strong><span>Identity and AI Expand the Scope of Deception</span></strong></p><p><span>Traditional deception focused primarily on servers, endpoints, and network infrastructure. Modern attack paths center on identities, cloud services, APIs, privileged access, and AI-enabled workflows. As enterprises adopt AI assistants, retrieval-augmented generation (RAG) systems, and Model Context Protocol (MCP) ecosystems, the environments attackers seek to manipulate extend well beyond conventional infrastructure.</span></p><p><span>Consequently, deception is expanding into these operational domains. Emerging platforms are beginning to deploy deceptive identities, cloud artifacts, configuration data, AI-specific resources, and contextual information designed to reveal or influence malicious activity targeting modern enterprise environments.</span></p><p><span>Whether these approaches prove effective at scale remains an open question. However, they reflect an important shift: deception now follows the attacker instead of remaining confined to traditional infrastructure.</span></p><p><strong><span>Intelligence Becomes a Two-Way Process</span></strong></p><p><span>Many security controls rely primarily on external intelligence.</span></p><p><span>Threat intelligence feeds, vulnerability databases, and indicators of compromise help organizations understand threats that have already been observed elsewhere.</span></p><p><span>Deception introduces an additional source of intelligence generated inside the organization itself.</span></p><p><span>Interactions with deceptive assets can reveal attacker objectives, reconnaissance techniques, privilege assumptions, and lateral movement strategies that are specific to the protected environment. Because legitimate users should rarely interact with deception assets, these engagements often produce higher-confidence signals than traditional telemetry alone.</span></p><p><span>This intelligence can improve investigations, refine detection logic, support incident response, and provide greater visibility into how adversaries operate within the organization&#8217;s own environment.</span></p><p><strong><span>Analyst Perspective: The Shift Is Architectural</span></strong></p><p><span>The significance of adaptive deception lies less in any individual capability than in how these capabilities work together.</span></p><p><span>Traditional deception sought to answer a relatively narrow question of </span><em><span>whether an attacker has interacted with something they should never have touched.</span></em></p><p><span>Adaptive deception asks a broader one, of whether</span><em><span> the environment itself can become an active participant in the defensive process.</span></em></p><p><span>That distinction reflects an architectural shift and not simply a product enhancement. The market is moving from isolated deception assets toward systems that continuously adapt, generate intelligence, and influence attacker behavior across increasingly dynamic enterprise environments.</span></p><p><span>Whether this transition ultimately reshapes enterprise security remains uncertain. Independent validation is still limited, terminology has yet to converge, and vendors vary significantly in implementation maturity. Even so, the broader direction reflects a growing recognition that defensive advantage may depend not only on observing attacks, but on influencing the conditions under which they unfold.</span></p><h1><strong><span>Case Study: Acalvio&#8217;s Approach to Agentic Deception</span></strong></h1><p><span>While the principles outlined in the previous sections describe the broader direction of adaptive deception, vendors are implementing those concepts in different ways. Some emphasize identity-centric deception, others focus on cloud infrastructure or attack-path disruption, while others extend deception into AI-enabled environments. The market remains early, and there is no single architectural model that has yet emerged as the industry standard.</span></p><p><span>Among the vendors shaping this evolution, </span><strong><span>Acalvio</span></strong><span> has articulated one of the more comprehensive visions for adaptive deception. Instead of positioning deception as an isolated detection capability, the company frames it as an operational layer that continuously adapts to attacker behavior, generating intelligence while attempting to influence adversary decision-making throughout an engagement.</span></p><p><span>SACR views Acalvio not as representative of the entire category, but as a useful case study for understanding how agentic deception may develop over the coming years. The following assessment is based on product demonstrations, technical briefings, publicly available documentation, and analyst evaluation. Architectural capabilities discussed below should be interpreted as vendor-stated implementations unless otherwise noted.</span></p><p><strong><span>Architectural Overview</span></strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!UzGt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb61cedbd-3809-4748-9c36-bf4157ce81bc_1456x819.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!UzGt!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb61cedbd-3809-4748-9c36-bf4157ce81bc_1456x819.png 424w, https://substackcdn.com/image/fetch/$s_!UzGt!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb61cedbd-3809-4748-9c36-bf4157ce81bc_1456x819.png 848w, https://substackcdn.com/image/fetch/$s_!UzGt!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb61cedbd-3809-4748-9c36-bf4157ce81bc_1456x819.png 1272w, https://substackcdn.com/image/fetch/$s_!UzGt!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb61cedbd-3809-4748-9c36-bf4157ce81bc_1456x819.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!UzGt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb61cedbd-3809-4748-9c36-bf4157ce81bc_1456x819.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b61cedbd-3809-4748-9c36-bf4157ce81bc_1456x819.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!UzGt!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb61cedbd-3809-4748-9c36-bf4157ce81bc_1456x819.png 424w, https://substackcdn.com/image/fetch/$s_!UzGt!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb61cedbd-3809-4748-9c36-bf4157ce81bc_1456x819.png 848w, https://substackcdn.com/image/fetch/$s_!UzGt!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb61cedbd-3809-4748-9c36-bf4157ce81bc_1456x819.png 1272w, https://substackcdn.com/image/fetch/$s_!UzGt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb61cedbd-3809-4748-9c36-bf4157ce81bc_1456x819.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><ul><li><p><strong><span>Threat Exposure and Attack Path Analysis: </span></strong><span>Acalvio automates threat exposure and attack path analysis, evaluating assets, privilege relationships, and likely attack routes to determine where deception can have the greatest strategic impact. Rather than placing decoys manually, the platform positions deception assets along the paths an adversary is most likely to take. This analysis forms the foundation for the platform&#8217;s downstream deception and engagement activities.</span></p></li><li><p><strong><span>Autonomous Deception Creation (Generative Deceptions): </span></strong><span> To address the operational challenge of scale, Acalvio automates the creation of deception assets instead of requiring manual builds for every decoy, generating systems, credentials, cloud resources, and identity artifacts designed to align with the protected environment. SACR refers to this as generative deception creation:  a capability that targets a real bottleneck in traditional deployments, though it has not yet been demonstrated at production scale.</span></p></li><li><p><strong><span>Identity-Centric Deception: </span></strong><span>Because identity has become one of the most valuable control planes for attackers, Acalvio extends deception into identity-centric attack paths through deceptive credentials, privileged account artifacts, and access relationships designed to appear operationally relevant while remaining isolated from production resources. This gives the platform a mechanism for detecting and influencing credential-based lateral movement specifically, not relying on network-level deception alone.</span></p></li><li><p><strong><span>Cloud-Native Deception:  </span></strong><span>Acalvio extends deception into cloud control planes by generating deceptive cloud resources, credentials, and storage artifacts that mirror the API-driven, identity-dependent nature of cloud infrastructure. This follows attackers into management planes and storage services where much of today&#8217;s critical infrastructure resides, not just confining deception to endpoints and network infrastructure.</span></p></li><li><p><strong><span>Targeted Threat Intelligence: </span></strong><span>Acalvio&#8217;s targeted threat intelligence capability synchronizes deception content with the tactics, techniques, and behaviors most likely to target a specific enterprise, rather than relying on generic decoys. This contextual relevance is intended to make deception assets more believable and therefore more effective at attracting engagement, forming a feedback loop between threat intelligence, environmental visibility, and decoy deployment.</span></p></li><li><p><strong><span>AI Infrastructure Protection: </span></strong><span>Acalvio extends deception into AI-enabled environments, agent frameworks, retrieval systems, and MCP deployments, creating visibility into attack surfaces that fall outside traditional infrastructure. The specific mechanisms here (MCP decoys, deceptive tools, configuration breadcrumbs) are detailed under &#8220;MCP Decoys and AI Infrastructure Deception&#8221; later in this case study, where they connect to the MITRE ATLAS-mapped operational demo.</span></p></li></ul><p><span>Acalvio&#8217;s ShadowPlex platform is designed around a continuous feedback loop in which deception assets evolve alongside both the protected environment and observed attacker behavior. Instead of deploying static decoys that require periodic maintenance, the platform attempts to automate the creation, placement, and adaptation of deceptive resources across identity systems, cloud infrastructure, enterprise networks, and emerging AI-enabled environments.</span></p><p><strong><span>Operational Value</span></strong></p><p><span>Individually, these six modules address distinct operational gaps: attack path analysis improves decoy placement, automated generation addresses scale, identity and cloud deception extend coverage into modern control planes, targeted threat intelligence improves realism, and AI infrastructure protection extends deception into emerging environments. Collectively, they form the foundation for the continuously adapting system described below.</span></p><p></p><h3><strong><span>The Acalvio Workflow: A Continuous Loop of Influence</span></strong></h3><h4><span>At a conceptual level, the workflow can be summarized as a continuous cycle:</span></h4><p><strong><span>Detect &#8594; Redirect &#8594; Deceive &#8594; Learn &#8594; Adapt</span></strong></p><p><span>The platform seeks to connect these functions into an ongoing operational process. Information gathered during reconnaissance, credential access attempts, or lateral movement is intended to inform subsequent adjustments to the deception environment, creating a feedback loop that evolves as new activity is observed.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!BI7q!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82efb29e-ac33-4d32-bb26-143d1f122745_1672x941.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!BI7q!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82efb29e-ac33-4d32-bb26-143d1f122745_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!BI7q!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82efb29e-ac33-4d32-bb26-143d1f122745_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!BI7q!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82efb29e-ac33-4d32-bb26-143d1f122745_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!BI7q!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82efb29e-ac33-4d32-bb26-143d1f122745_1672x941.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!BI7q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82efb29e-ac33-4d32-bb26-143d1f122745_1672x941.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/82efb29e-ac33-4d32-bb26-143d1f122745_1672x941.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!BI7q!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82efb29e-ac33-4d32-bb26-143d1f122745_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!BI7q!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82efb29e-ac33-4d32-bb26-143d1f122745_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!BI7q!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82efb29e-ac33-4d32-bb26-143d1f122745_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!BI7q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82efb29e-ac33-4d32-bb26-143d1f122745_1672x941.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong><span>ShadowPlex as an Implementation of Adaptive Environmental Control</span></strong></h2><p><span>One of the distinguishing characteristics of Acalvio&#8217;s ShadowPlex architecture is that it treats deception not as a collection of individual decoys, but as a continuously operating defensive layer that evolves alongside the enterprise environment. This reflects a broader architectural shift discussed throughout this report: deception is moving from a static detection capability toward an adaptive environmental control designed to influence attacker behavior before traditional response processes begin.</span></p><p><span>Historically, most deception platforms have focused on placing believable but isolated artifacts throughout enterprise environments. Decoy systems, deceptive credentials, honeytokens, and fake services generated valuable telemetry when accessed by an adversary, but they generally remained passive until triggered. Their primary purpose was to reveal malicious activity after reconnaissance had already reached a deceptive asset.</span></p><p><span>ShadowPlex approaches the problem differently. Rather than treating deception as a discrete collection of traps, the platform attempts to model the surrounding environment and continuously adapt deceptive assets as identities, infrastructure, cloud resources, and attack paths evolve. In this model, deception becomes part of the operating environment itself and not just an isolated security capability deployed alongside it.</span></p><p><span>From an architectural perspective, this distinction is significant.  Modern enterprise environments are increasingly dynamic. Cloud infrastructure scales automatically, identities gain and lose privileges, workloads migrate across platforms, and AI-enabled systems establish new relationships with enterprise data and external services. Static deception assets become progressively less believable if they fail to evolve alongside these changes. An adaptive control layer attempts to preserve realism by continuously aligning deceptive resources with the operational characteristics of the environment they are intended to emulate.</span></p><p><span>This shift also changes the defensive objective. Traditional deception platforms primarily sought to answer a binary question: </span><strong><span>Has an attacker interacted with an asset that should never have been accessed?</span></strong><span> Adaptive environmental control introduces a broader objective: </span><strong><span>Can the environment itself shape how an attacker understands, prioritizes, and navigates the enterprise before critical objectives are achieved?</span></strong></p><p><span>In practical terms, this means deception is no longer evaluated solely by the alerts it produces. Its value depends on whether it can influence reconnaissance quality, alter attacker decision-making, generate higher-confidence operational intelligence, and create additional opportunities for defenders to intervene earlier in the intrusion lifecycle.</span></p><p><span>ShadowPlex illustrates one implementation of this architectural philosophy through a continuous operational cycle in which environmental observation informs deception generation, attacker interaction produces intelligence, and that intelligence contributes to subsequent adaptation. Rather than treating these activities as independent workflows, the platform seeks to integrate them into an ongoing feedback loop that evolves as both the protected environment and attacker behavior change.</span></p><p><span>This architecture aligns with a prevalent trend visible across multiple areas of cybersecurity. Identity security platforms now adjust trust decisions based on context. Cloud security continuously evaluates infrastructure posture as environments change. AI runtime security adapts policies according to agent behavior and data access patterns. Within this wider movement toward adaptive security, deception is evolving in a similar direction, from static artifacts toward continuously managed environmental controls.</span></p><p><span>Whether this architectural model ultimately becomes the dominant approach to deception remains an open question. Organizations should continue evaluating claims of autonomous adaptation through independent validation, production deployments, and measurable operational outcomes. Nevertheless, ShadowPlex demonstrates how deception can be reimagined as an adaptive security capability and not just an alert-generation mechanism. In doing so, it provides a useful illustration of the broader transition from passive observation toward active environmental influence that is reshaping this emerging category. The environment is not treated as static infrastructure but as a continuously evolving defensive surface.</span></p><p><strong><span>How Acalvio Applies the Principles of Adaptive Deception</span></strong></p><p><span>The platform demonstrates several of the architectural principles discussed earlier in this report.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!EEJM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f8650ec-b3bd-46e4-945e-04fa5065c2a9_1672x941.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!EEJM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f8650ec-b3bd-46e4-945e-04fa5065c2a9_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!EEJM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f8650ec-b3bd-46e4-945e-04fa5065c2a9_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!EEJM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f8650ec-b3bd-46e4-945e-04fa5065c2a9_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!EEJM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f8650ec-b3bd-46e4-945e-04fa5065c2a9_1672x941.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!EEJM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f8650ec-b3bd-46e4-945e-04fa5065c2a9_1672x941.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8f8650ec-b3bd-46e4-945e-04fa5065c2a9_1672x941.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!EEJM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f8650ec-b3bd-46e4-945e-04fa5065c2a9_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!EEJM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f8650ec-b3bd-46e4-945e-04fa5065c2a9_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!EEJM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f8650ec-b3bd-46e4-945e-04fa5065c2a9_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!EEJM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f8650ec-b3bd-46e4-945e-04fa5065c2a9_1672x941.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><span>Degrading Intelligence: Reconnaissance Redirection and Steering</span></h2><p><span>Traditional environments often reveal valuable information through negative responses. Closed ports, rejected connections, unavailable services, and error messages all help attackers build accurate maps of a target environment.</span></p><p><span>Acalvio&#8217;s approach converts unused infrastructure from a source of negative responses into an instrument of influence. By redirecting probes into controlled environments, the platform is designed to poison the attacker&#8217;s reconnaissance; if effective, the adversary&#8217;s model of the target is inaccurate from the first packet. Acalvio claims this degrades the quality of attacker intelligence in real time.</span></p><p><span>The strategic objective is not merely detection. It is the degradation of reconnaissance quality.</span></p><p><span>Every probe becomes an opportunity to influence what an attacker believes to be true about the environment. Rather than collecting intelligence passively, the environment begins participating in the engagement itself.</span></p><h2><span>Undermining Trust: Response Morphing</span></h2><p><span>Attackers rely heavily on consistency when building an understanding of a target environment. Service banners, operating system fingerprints, protocol responses, and configuration details all contribute to an attacker&#8217;s model of the environment.</span></p><p><span>Response morphing seeks to undermine that process.</span></p><p><span>During the briefing, Acalvio demonstrated how environmental signals could be dynamically altered to create uncertainty. For example, infrastructure that appears to belong to one platform may respond in a manner consistent with another. The information remains believable, but its accuracy becomes less reliable.</span></p><p><span>Consistency is an attacker&#8217;s greatest asset. The company argues that response morphing aims to disrupt that consistency. By dynamically altering service banners, fingerprints, and protocol responses, the platform aims to make environmental signals untrustworthy; replacing accuracy with believable friction intended to push the adversary and their autonomous agents toward indecision. Whether sophisticated adversaries adapt to this technique over repeated exposure is an open question, one SACR flags in the fingerprinting risk below.</span></p><h2><span>Dynamic Defense: Machine-Speed Adaptation</span></h2><p><span>The most significant aspect of the ShadowPlex architecture is the continuous reprogramming of deception based on observed activity. As Acalvio observes credential attempts or lateral movement, it adjusts deception assets in real-time to match inferred goals. This intent-driven adaptation is designed to ensure that attackers encounter an environment changing faster than it can be modeled, positioning deception as a primary security control that meets compressed attack timelines with equivalent speed.</span></p><p><span>Every action reveals information. Reconnaissance activity identifies areas of interest. Credential access attempts suggest objectives. Lateral movement activity reveals assumptions regarding network structure and available resources. Rather than treating these activities as isolated events, the platform incorporates them into an evolving threat model.</span></p><p><span>The underlying design principle is that the environment must be tailored to the attacker, and re-tailored continuously as the attacker&#8217;s inferred goals evolve.</span></p><h2><span>Environmental Guardrails</span></h2><p><span>Much of the current discussion surrounding AI security focuses on controls that operate inside the model itself, such as alignment training, safety tuning, prompt filtering, and policy enforcement.</span></p><p><span>Acalvio&#8217;s approach introduces a complementary concept: environmental guardrails.</span></p><p><span>Instead of relying exclusively on model-level controls, environmental guardrails focus on influencing behavior through the surrounding environment. Context, access paths, resources, tools, and operational workflows can all be monitored, constrained, or manipulated to reduce risk.</span></p><p><span>This approach reflects a broader security principle. Organizations have historically relied on multiple layers of defense, not merely trusting any single control. Environmental guardrails extend that philosophy into AI-enabled environments.</span></p><p><span>As autonomous systems become more deeply integrated into enterprise operations, runtime controls may become important alongside model-level protections.</span></p><h2><span>MCP Decoys and AI Infrastructure Deception</span></h2><p><span>One of the more forward-looking aspects of the architecture is its application to emerging AI ecosystems.</span></p><p><span>As organizations deploy AI agents, tool frameworks, retrieval systems, and Model Context Protocol (MCP) environments, entirely new attack surfaces are being created. These systems introduce opportunities for attackers seeking to manipulate workflows, poison context, abuse tools, or influence agent behavior.</span></p><p><span>Acalvio extends deception directly into these environments through concepts such as MCP decoys, deceptive tools, configuration breadcrumbs, and AI-focused deception assets.</span></p><p><span>The objective is to identify malicious activity earlier in the attack lifecycle while generating intelligence regarding how adversaries interact with AI-enabled systems.</span></p><p><span>This represents an important expansion of traditional deception. Historically, deception focused on networks, endpoints, and applications. Agentic deception extends those concepts into the infrastructure supporting autonomous systems themselves.</span></p><p><span>Viewed collectively, these mechanisms illustrate a broader shift in defensive philosophy. Rather than focusing exclusively on observing attackers, the architecture attempts to influence what attackers see, what they believe, and ultimately how they behave.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!9-cq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3e14caf-07f9-4178-989c-fd80f3d2b974_1672x941.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9-cq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3e14caf-07f9-4178-989c-fd80f3d2b974_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!9-cq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3e14caf-07f9-4178-989c-fd80f3d2b974_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!9-cq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3e14caf-07f9-4178-989c-fd80f3d2b974_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!9-cq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3e14caf-07f9-4178-989c-fd80f3d2b974_1672x941.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9-cq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3e14caf-07f9-4178-989c-fd80f3d2b974_1672x941.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a3e14caf-07f9-4178-989c-fd80f3d2b974_1672x941.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!9-cq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3e14caf-07f9-4178-989c-fd80f3d2b974_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!9-cq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3e14caf-07f9-4178-989c-fd80f3d2b974_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!9-cq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3e14caf-07f9-4178-989c-fd80f3d2b974_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!9-cq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3e14caf-07f9-4178-989c-fd80f3d2b974_1672x941.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong><span>Where Acalvio Appears Differentiated</span></strong></p><p><span>Based on SACR&#8217;s evaluation, several aspects of the platform stand out relative to the broader direction of the deception market.</span></p><p><strong><span>Integration across multiple control planes.</span></strong><span> Instead of treating deception as a network-centric capability, the platform extends into identity, cloud, and AI-enabled environments.</span></p><p><strong><span>Operational automation.</span></strong><span> The emphasis on automating deception generation and lifecycle management addresses one of the historical barriers to enterprise adoption.</span></p><p><strong><span>Forward-looking AI strategy.</span></strong><span> Acalvio has invested early in deception techniques targeting AI-native environments, particularly MCP-based workflows and agent ecosystems. Although this area remains immature across the industry, it reflects a recognition that enterprise attack surfaces are expanding beyond conventional infrastructure.</span></p><p><span>These differentiators should be viewed within the context of a rapidly evolving market. Competing vendors are pursuing similar objectives through different architectural approaches, and the long-term competitive landscape has yet to stabilize.</span></p><p><strong><span>Areas Buyers Should Validate</span></strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!GheK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F097c918f-378a-4d35-a6d1-33d9b42b3242_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!GheK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F097c918f-378a-4d35-a6d1-33d9b42b3242_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!GheK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F097c918f-378a-4d35-a6d1-33d9b42b3242_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!GheK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F097c918f-378a-4d35-a6d1-33d9b42b3242_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!GheK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F097c918f-378a-4d35-a6d1-33d9b42b3242_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!GheK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F097c918f-378a-4d35-a6d1-33d9b42b3242_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/097c918f-378a-4d35-a6d1-33d9b42b3242_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!GheK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F097c918f-378a-4d35-a6d1-33d9b42b3242_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!GheK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F097c918f-378a-4d35-a6d1-33d9b42b3242_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!GheK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F097c918f-378a-4d35-a6d1-33d9b42b3242_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!GheK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F097c918f-378a-4d35-a6d1-33d9b42b3242_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>As with any emerging cybersecurity category, architectural vision should be accompanied by operational validation.</span></p><p><span>Organizations evaluating Acalvio should seek evidence in several areas:</span></p><ul><li><p><span>How effectively does continuous adaptation perform in large, dynamic enterprise environments?</span></p></li><li><p><span>Can deception assets resist fingerprinting during repeated engagements?</span></p></li><li><p><span>What measurable impact does adaptive deception have on attacker decision-making and incident outcomes?</span></p></li><li><p><span>How much operational overhead is required to maintain believable deception at scale?</span></p></li><li><p><span>How seamlessly does platform-generated intelligence integrate with existing SIEM, XDR, identity, and cloud security workflows?</span></p></li><li><p><span>What independent customer evidence supports the platform&#8217;s claims?</span></p></li></ul><p><span>These questions are not unique to Acalvio. They represent broader evaluation criteria for the agentic deception category as a whole and should form part of any procurement process.</span></p><p><strong><span>SACR Assessment</span></strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!po4V!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc1b0063-21ed-4c22-80c3-8b34b5de047c_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!po4V!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc1b0063-21ed-4c22-80c3-8b34b5de047c_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!po4V!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc1b0063-21ed-4c22-80c3-8b34b5de047c_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!po4V!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc1b0063-21ed-4c22-80c3-8b34b5de047c_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!po4V!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc1b0063-21ed-4c22-80c3-8b34b5de047c_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!po4V!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc1b0063-21ed-4c22-80c3-8b34b5de047c_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fc1b0063-21ed-4c22-80c3-8b34b5de047c_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!po4V!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc1b0063-21ed-4c22-80c3-8b34b5de047c_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!po4V!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc1b0063-21ed-4c22-80c3-8b34b5de047c_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!po4V!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc1b0063-21ed-4c22-80c3-8b34b5de047c_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!po4V!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc1b0063-21ed-4c22-80c3-8b34b5de047c_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>Overall, SACR views Acalvio as one of the more innovative vendors shaping the future of deception. While the broader category is still emerging, the company&#8217;s emphasis on adaptive defense, environmental influence, and AI-aware deception reflects where cybersecurity architectures are likely to evolve as organizations confront autonomous attackers and AI-enabled enterprise environments. For organizations exploring next-generation defensive strategies, Acalvio offers a differentiated vision that extends beyond traditional detection toward actively influencing attacker behavior.</span></p><p><span>Whether agentic deception ultimately becomes a foundational security category remains uncertain. However, the underlying direction is compelling. As organizations continue adopting automation and autonomous systems, defensive architectures may benefit from controls that do more than observe activity; they may also need to shape the conditions under which that activity occurs. Within that context, Acalvio offers a credible and differentiated vision of what adaptive cyber defense could look like in the years ahead.</span></p><h1><strong><span>Procurement Considerations for Security Leaders</span></strong></h1><p><span>The emergence of adaptive deception does not fundamentally change how organizations should evaluate security technologies. Rather, it expands the set of architectural questions security leaders should be asking as enterprise environments become dynamic and AI-enabled.</span></p><p><span>For many organizations, deception is unlikely to replace existing investments in identity security, endpoint protection, detection and response, or cloud security. Its value lies in complementing those controls by introducing additional opportunities to influence attacker behavior before critical objectives are achieved.</span></p><p><span>Security leaders evaluating deception platforms should therefore focus less on individual product features and more on how effectively those capabilities integrate into broader security operations.</span></p><h2><strong><span>Evaluate the Architecture, Not the Marketing</span></strong></h2><p><span>As the category matures, terminology is evolving rapidly. Vendors describe their platforms using terms such as </span><em><span>adaptive</span></em><span>, </span><em><span>autonomous</span></em><span>, </span><em><span>AI-native</span></em><span>, or </span><em><span>agentic</span></em><span>. While these labels may reflect genuine architectural innovation, they are not substitutes for demonstrable operational capabilities.</span></p><p><span>Instead, organizations should evaluate whether platforms can:</span></p><ul><li><p><span>adapt to changing enterprise environments with minimal manual effort;</span></p></li><li><p><span>integrate across identity, cloud, endpoint, and AI-enabled ecosystems;</span></p></li><li><p><span>generate actionable intelligence that improves broader security operations; and</span></p></li><li><p><span>demonstrate measurable defensive outcomes beyond proof-of-concept environments.</span></p></li></ul><p><span>Architectural maturity should ultimately be measured by operational effectiveness and not just product messaging.</span></p><p><strong><span>Prioritize Operational Integration</span></strong></p><p><span>Deception should strengthen existing security programs, integrating with them as a well-rounded capability.</span></p><p><span>Organizations should understand how deception-generated intelligence integrates with existing investments in SIEM, XDR, SOAR, identity security, cloud security, and incident response workflows. High-confidence detections are valuable only if they improve investigation, accelerate decision-making, and reduce operational complexity.</span></p><p><span>Similarly, adaptive deception should be evaluated within the broader security operating model. The technology is unlikely to deliver meaningful value if it introduces additional management overhead or requires extensive manual administration to remain effective.</span></p><p><strong><span>Validate Adaptation, Not Just Detection</span></strong></p><p><span>Many deception technologies have historically demonstrated their value by generating accurate alerts with relatively low false-positive rates.</span></p><p><span>Adaptive deception introduces a different claim: that the environment itself evolves as attackers interact with it.</span></p><p><span>This capability represents one of the most significant architectural shifts discussed throughout this report, but it is also one of the areas requiring the greatest scrutiny.</span></p><p><span>Organizations should therefore request evidence demonstrating:</span></p><ul><li><p><span>how deception adapts over time;</span></p></li><li><p><span>how those adaptations improve defensive outcomes;</span></p></li><li><p><span>whether adaptive behaviors remain effective against sophisticated adversaries; and</span></p></li><li><p><span>how platform performance changes across large, dynamic enterprise environments.</span></p></li></ul><p><span>The distinction between static automation and meaningful adaptation is likely to become an important differentiator as the market matures.</span></p><p><strong><span>Consider AI as Part of a Broader Security Strategy</span></strong></p><p><span>The rapid adoption of AI assistants, retrieval systems, autonomous workflows, and agent frameworks is expanding enterprise attack surfaces in ways that traditional security architectures were not designed to address.</span></p><p><span>While deception may provide useful visibility into these environments, it should be evaluated as one component of a broader AI security strategy that also includes governance, identity, runtime controls, application security, and data protection.</span></p><p><span>Organizations should avoid viewing any single technology as sufficient for securing AI-enabled environments. Instead, the objective should be to combine complementary controls that reduce both the likelihood and impact of autonomous attacks.</span></p><p><strong><span>Questions Every Buyer Should Ask</span></strong></p><p><span>Before selecting an adaptive deception platform, CISOs should be able to answer several practical questions.</span></p><ul><li><p><span>What operational problem is this platform solving that existing controls do not?</span></p></li><li><p><span>How does it integrate with the organization&#8217;s current security architecture?</span></p></li><li><p><span>Can it demonstrate measurable improvements in detection quality, attacker disruption, or investigation efficiency?</span></p></li><li><p><span>How much operational effort is required to maintain realistic deception environments?</span></p></li><li><p><span>What independent customer evidence supports the vendor&#8217;s architectural claims?</span></p></li><li><p><span>How effectively does the platform extend across cloud, identity, and AI-enabled environments?</span></p></li><li><p><span>What metrics will be used to determine whether the deployment has been successful?</span></p></li></ul><p><span>These questions are ultimately more important than any individual capability. As with many emerging cybersecurity categories, long-term value will depend on operational outcomes, not architectural ambition alone.</span></p><p><strong><span>Final Assessment</span></strong></p><p><span>The renewed interest in deception reflects a broader transformation occurring across enterprise cybersecurity. As organizations deploy autonomous systems and attackers continue to automate reconnaissance, exploitation, and decision-making, security architectures built primarily around human-speed detection and response are being reevaluated.</span></p><p><span>Agentic deception represents one response to that shift.</span></p><p><span>Rather than focusing exclusively on identifying malicious activity after it has begun, adaptive deception explores whether defenders can influence the information, context, and environmental conditions that attackers rely upon throughout an engagement. Whether this approach ultimately becomes a foundational component of enterprise security remains uncertain. The category is still evolving, independent validation remains limited, and implementation maturity varies considerably across vendors.</span></p><p><span>Nevertheless, the underlying architectural direction is significant.</span></p><p><span>The future of cyber defense is unlikely to be defined by a single technology category. Instead, organizations will move towards combining identity security, runtime protection, cloud security, AI governance, detection and response, and adaptive controls into integrated security architectures capable of operating continuously across highly dynamic environments.</span></p><p><span>Within that broader evolution, deception appears to be moving beyond its historical role as a niche detection capability toward a more strategic function focused on environmental influence and operational intelligence.</span></p><p><span>Among the vendors contributing to this transition, </span><strong><span>Acalvio</span></strong><span> presents one of the more comprehensive implementations currently available. Its emphasis on continuous adaptation, identity- and cloud-centric deception, and AI-enabled environments aligns closely with several of the architectural trends shaping the market. While many of its longer-term claims remain to be validated through broader enterprise adoption, the platform provides a credible illustration of how adaptive deception may evolve over the coming years.</span></p><p><span>The strategic importance of deception in that environment is that it targets one of the most critical dependencies shared by both humans and machines: information. Ultimately, the significance of agentic deception lies less in any individual implementation than in the question it asks of modern security architecture:</span></p><blockquote><p><strong><span>If attackers rely on autonomous systems to understand and navigate enterprise environments, should defenders continue focusing solely on observing those systems, or should they also seek to influence what those systems perceive?</span></strong></p></blockquote><p><span>The answer will vary across organizations and will continue to evolve alongside the technology itself. What appears likely, however, is that the next generation of enterprise security will place greater emphasis not only on detecting attacks, but on shaping the conditions under which they unfold.</span></p><p><strong><span>Disclosure: </span></strong><span>This report is commissioned and sponsored by Acalvio. SACR retains full editorial control, independence, and objectivity. Acalvio&#8217;s role is limited to providing briefing access, customer contacts, and factual review. Sponsorship does not influence SACR&#8217;s findings, competitive analysis, or recommendations.</span></p><h3><strong><span>Sources &amp; Further Reading</span></strong></h3><h4><strong>Vendor Briefings and Product Materials</strong></h4><ul><li><p>Acalvio product demonstrations (2026)</p></li><li><p>Acalvio technical briefings</p></li><li><p>Acalvio ShadowPlex architecture documentation</p></li><li><p>Acalvio MCP operational demonstration</p></li><li><p>Acalvio solution documentation</p></li></ul><p><strong><span>Research &amp; Standards</span></strong></p><ul><li><p><span>IBM. </span><a href="https://www.ibm.com/reports/data-breach"><span>Cost of a Data Breach Report 2025</span></a><span>. </span></p></li><li><p><span>Verizon Business. </span><a href="https://www.verizon.com/business/resources/reports/dbir/"><span>2026 Data Breach Investigations Report (DBIR)</span></a><span>. </span></p></li><li><p><span>MITRE Corporation. </span><a href="https://attack.mitre.org/"><span>MITRE ATT&amp;CK Framework.</span></a><span> </span></p></li><li><p><span>MITRE Corporation. </span><a href="https://engage.mitre.org/"><span>MITRE Engage</span></a><span>.</span></p></li><li><p><span>National Institute of Standards and Technology. </span><a href="https://www.nist.gov/itl/ai-risk-management-framework"><span>AI Risk Management Framework (NIST AI RMF 1.0)</span></a><span>. </span></p></li><li><p><span>OWASP Foundation. </span><a href="https://genai.owasp.org/llm-top-10/"><span>OWASP Top 10 for Large Language Model (LLM) Applications</span></a><span>. </span></p></li><li><p><span>Microsoft. </span><a href="https://www.microsoft.com/en-us/security/security-insider/microsoft-digital-defense-report"><span>Microsoft Digital Defence Report</span></a><span>. </span></p></li><li><p><span>From Vulnerability to </span><a href="https://zerodayclock.com"><span>Exploitation &#8211; time-to-exploit dataset.</span></a><span> </span></p><p></p></li></ul><div><hr></div><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Software Analyst Cyber Research! Subscribe for free to receive new cybersecurity reports</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><p></p><div class="directMessage button" data-attrs="{&quot;userId&quot;:6770950,&quot;userName&quot;:&quot;SACR&quot;,&quot;canDm&quot;:null,&quot;dmUpgradeOptions&quot;:null,&quot;isEditorNode&quot;:true}" data-component-name="DirectMessageToDOM"></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/p/the-next-evolution-of-cyber-deception/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/p/the-next-evolution-of-cyber-deception/comments"><span>Leave a comment</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&quot;,&quot;text&quot;:&quot;Share Software Analyst Cyber Research&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share Software Analyst Cyber Research</span></a></p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/p/the-next-evolution-of-cyber-deception?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading Software Analyst Cyber Research! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/p/the-next-evolution-of-cyber-deception?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/p/the-next-evolution-of-cyber-deception?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><p></p>]]></content:encoded></item><item><title><![CDATA[ARMCF: Introducing A Practitioner Control Framework for AI and Agentic Risk Management ]]></title><description><![CDATA[SACR is pleased to introduce a practical operating model for securing, monitoring, and managing agentic AI risk for governance, and security teams]]></description><link>https://softwareanalyst.substack.com/p/armcf-introducing-a-practitioner</link><guid isPermaLink="false">https://softwareanalyst.substack.com/p/armcf-introducing-a-practitioner</guid><dc:creator><![CDATA[SACR]]></dc:creator><pubDate>Mon, 13 Jul 2026 15:43:49 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!heZC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaaf4be8-c02c-46ca-8093-c77c5539e1f1_1456x830.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h1><strong><span>Executive Summary</span></strong></h1><p>Today, organizations are forced to adopt AI faster than their governance, procurement, and security assurance models can adapt. Existing AI security standards provide strong foundations, but organizations still face a translation problem. Many AI governance frameworks describe sound principles but often stop short of the technical enforcement and SecOps integration that operational teams need. </p><p>SACR developed the AI and Agentic Risk Management and Control Framework, or ARMCF, to help close that gap.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!heZC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaaf4be8-c02c-46ca-8093-c77c5539e1f1_1456x830.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!heZC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaaf4be8-c02c-46ca-8093-c77c5539e1f1_1456x830.webp 424w, https://substackcdn.com/image/fetch/$s_!heZC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaaf4be8-c02c-46ca-8093-c77c5539e1f1_1456x830.webp 848w, https://substackcdn.com/image/fetch/$s_!heZC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaaf4be8-c02c-46ca-8093-c77c5539e1f1_1456x830.webp 1272w, https://substackcdn.com/image/fetch/$s_!heZC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaaf4be8-c02c-46ca-8093-c77c5539e1f1_1456x830.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!heZC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaaf4be8-c02c-46ca-8093-c77c5539e1f1_1456x830.webp" width="1456" height="830" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/caaf4be8-c02c-46ca-8093-c77c5539e1f1_1456x830.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:830,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:48718,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://softwareanalyst.substack.com/i/206437801?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaaf4be8-c02c-46ca-8093-c77c5539e1f1_1456x830.webp&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!heZC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaaf4be8-c02c-46ca-8093-c77c5539e1f1_1456x830.webp 424w, https://substackcdn.com/image/fetch/$s_!heZC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaaf4be8-c02c-46ca-8093-c77c5539e1f1_1456x830.webp 848w, https://substackcdn.com/image/fetch/$s_!heZC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaaf4be8-c02c-46ca-8093-c77c5539e1f1_1456x830.webp 1272w, https://substackcdn.com/image/fetch/$s_!heZC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaaf4be8-c02c-46ca-8093-c77c5539e1f1_1456x830.webp 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>ARMCF is a practitioner-oriented operating framework for governing, securing, monitoring, responding to and recovering AI and agentic systems. It applies the familiar six-function lifecycle of NIST CSF 2.0: GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND and RECOVER to the specific risks created by AI systems with access to data, identities, tools and downstream actions.</p><p>The framework helps organizations:</p><ol><li><p>Maintain visibility into sanctioned and shadow AI systems.</p></li><li><p>Define risk appetite, accountability and acceptable levels of autonomy.</p></li><li><p>Assess data flows, dependencies and potential blast radius.</p></li><li><p>Preserve evidence, restore systems safely and improve controls after incidents.</p></li><li><p>Map control decisions to established security, AI governance and assurance frameworks.</p></li></ol><p></p><p><span>The AI and Agentic Risk Management and Control Framework (ARMCF) was designed to help organizations govern, secure, monitor, and recover AI and agentic systems using a lifecycle model that aligns with familiar cybersecurity and risk disciplines. It synthesizes established concepts from NIST AI RMF, NIST SP 800-53, ISO/IEC 42001, MITRE ATLAS, OWASP LLM Top 10, CIS Controls, CSA AICM 1.1, SOC 2, and related sources into a single operating model for teams that need both technical depth and auditability.</span></p><p><span>The framework exists because AI-enabled systems, especially those with tool access and autonomous action-taking capability, create governance and control gaps that are not fully resolved when organizations apply traditional cyber controls without AI-specific interpretation. ARMCF addresses that gap by defining six lifecycle-aligned domains, mapping them to recognized frameworks, and translating them into practical control objectives, risk scenarios, and implementation steps that security and risk leaders can operationalize.</span></p><h2><strong>Industry Resources For Practitioners</strong></h2><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://drive.google.com/drive/folders/1MhcL75RRKSR_Vh_gwJjWCjjkz1t6d2Fl&quot;,&quot;text&quot;:&quot;ARMCF Downloadable Framework&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://drive.google.com/drive/folders/1MhcL75RRKSR_Vh_gwJjWCjjkz1t6d2Fl"><span>ARMCF Downloadable Framework</span></a></p><p></p><p>For technical leaders, ARMCF offers a common language for risk identification, policy design, control selection, security architecture, detection engineering, and incident response. For non-specialist readers, its core message is simpler: organizations should not adopt AI and agentic systems at speed unless they can identify what they use, define who is accountable, constrain what AI can access, observe how it behaves, and recover safely when things go wrong.</p><p></p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><strong>Thanks for reading Software Analyst Cyber Research! Subscribe for free to receive new cybersecurity research reports.</strong> </p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><p></p><h2><strong><span>Scope Definition</span></strong></h2><p><span>ARMCF applies to AI systems with autonomous decision-making or action-taking capability, including LLM-backed applications, orchestrated multi-agent pipelines, tool-using agent workflows, and AI-assisted human workflows where AI model output materially influences decisions. It covers systems that are built internally, integrated through APIs, procured as AI-enabled SaaS, or introduced indirectly through embedded features in third-party products.</span></p><p><span>The most material organizational risk often comes less from the model itself than from the operating environment around it: context access, tool invocation, external dependencies, delegated permissions, and weak governance. ARMCF therefore treats AI as both a technology risk and an operating model risk, which makes it useful for security architecture, third-party governance, internal audit, compliance, and resilience planning.</span></p><p><span>In practice, ARMCF applies to any AI capability that can influence meaningful business outcomes, access sensitive data, trigger downstream actions, or create accountability exposure for the organization. Read-only summarization tools may require lighter governance, while fully autonomous systems require a much broader set of controls and oversight.</span></p><p></p><h2><strong><span>Driving Factors</span></strong></h2><p><span>ARMCF is driven by the need to bring governance, security, threat modeling, resilience, and auditability into one operating model rather than treating them as separate workstreams.</span></p><p><span>This design reflects the reality that organizations are adopting AI faster than standards, procurement processes, and assurance models can fully adapt to.</span></p><p><span>One major driver is the fragmentation of existing guidance. Traditional cybersecurity frameworks provide strong foundations for control design and monitoring, but they do not always express risks such as prompt injection, insecure tool orchestration, agent identity misuse, data leakage, or autonomous overreach in language that operational teams can directly act on. AI governance frameworks, meanwhile, often describe principles well but may stop short of detailed security enforcement or SOC integration.</span></p><p><span>A second driver is the emergence of agentic systems as a different risk class. ARMCF explicitly addresses tool-calling agents, multi-step planning systems, unsupervised execution patterns, model supply chains, Model Context Protocol (MCP) style brokered tool access, and identity delegation concerns because those elements expand the potential blast radius of compromise beyond a single model. In practical terms, an AI system that can send email, modify files, call APIs, or execute workflow steps must be governed more like a privileged digital actor than like a static software component.</span></p><p><span>A third driver is the need for regulated organizations to preserve auditability. Security and risk leaders in financial services, healthcare, public sector, and critical infrastructure environments need traceable ownership, documented risk acceptance, evidence preservation, and cross-mapping to recognized standards before AI adoption can scale safely. ARMCF responds by embedding accountability, logging, classification, evidence handling, and framework mappings into its structure rather than leaving them as afterthoughts.</span></p><p style="text-align: center;"><em><span>&#8220;An AI system that can send email, modify files, call APIs, or execute workflow steps must be governed more like a privileged digital actor than like a static software component.&#8221;</span></em></p><p style="text-align: center;"></p><h2><strong><span>Aim and Purpose</span></strong></h2><p><span>ARMCF provides a governance and risk layer that sits above the technical control stack and helps organizations that are building, deploying, or procuring AI and agentic systems to operate them safely and consistently. Its purpose is to translate AI and agentic risks into implementable management expectations, technical safeguards, monitoring requirements, and recovery processes.</span></p><p><span>At a strategic level, the framework helps leadership define acceptable autonomy, prohibited use cases, risk ownership, and the minimum control posture expected before production deployment. At an operational level, it helps engineering, security, and risk teams discover AI assets, model threats, constrain permissions, monitor behavior, handle incidents, and improve controls over time.</span></p><p><span>The practical value of this dual aim is that ARMCF supports  both governance conversations in the boardroom and design conversations in architecture review forums. It gives senior managers a structure for accountability and readiness, while giving practitioners a method for assessing their environments and prioritizing remediation.</span></p><h2><strong>Core principles</strong></h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!aK4s!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9960626f-84cd-4f11-80bf-099449f8316b_1672x941.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!aK4s!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9960626f-84cd-4f11-80bf-099449f8316b_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!aK4s!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9960626f-84cd-4f11-80bf-099449f8316b_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!aK4s!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9960626f-84cd-4f11-80bf-099449f8316b_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!aK4s!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9960626f-84cd-4f11-80bf-099449f8316b_1672x941.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!aK4s!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9960626f-84cd-4f11-80bf-099449f8316b_1672x941.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9960626f-84cd-4f11-80bf-099449f8316b_1672x941.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!aK4s!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9960626f-84cd-4f11-80bf-099449f8316b_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!aK4s!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9960626f-84cd-4f11-80bf-099449f8316b_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!aK4s!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9960626f-84cd-4f11-80bf-099449f8316b_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!aK4s!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9960626f-84cd-4f11-80bf-099449f8316b_1672x941.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em><span>Figure 1: ARMCF Core Principles</span></em></p><p><span>ARMCF is built around five core principles: accountability, proportionality, lifecycle coverage, security-by-design, and auditability.</span></p><ol><li><p><strong><span>Accountability</span></strong><span>: every production AI system should have a named owner, a defined risk function, and a clear RACI for lifecycle decisions such as procurement, deployment, monitoring, and decommissioning. Without that discipline, organizations cannot reliably determine who is authorized to accept AI risk, approve change, or respond to incidents.</span></p></li><li><p><strong><span>Proportionality:</span></strong><span> ARMCF recognizes that not all AI systems present equal risk and explicitly supports classification by risk tier, autonomy level, data sensitivity, and use case criticality. This enables organizations to apply stronger controls to high-impact or agentic systems without burdening low-risk use cases with the same level of friction.</span></p></li><li><p><strong><span>Lifecycle Coverage: </span></strong><span>ARMCF is structured around six domains&#8212;GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, and RECOVER&#8212;which together reflect the full operational lifecycle of secure AI adoption. Meaningful readiness requires movement from policy to implementation, to monitoring, to response,  to recovery in a coherent and repeatable way that uses principles and pillars familiar to other security frameworks.</span></p></li><li><p><strong><span>Security-by-Design for Agentic Systems:</span></strong><span> Prompt inspection, tool allowlisting, agent identity, data minimization, software supply chain integrity, and behavioral monitoring appear in the framework as baseline control concepts because AI risk emerges from system interaction, not only from model content. In simple terms, ARMCF assumes that good intentions and acceptable use policies are not enough without technical enforcement and observable evidence.</span></p></li><li><p><strong><span>Auditability:</span></strong><span> The framework repeatedly emphasizes structured inventories, risk scoring, evidence preservation, SIEM export, sign-off, review dates, and roadmap milestones because mature AI governance must be inspectable and defensible under scrutiny. That orientation makes the framework especially relevant to organizations with internal audit, regulatory, or customer assurance obligations.</span></p></li></ol><p style="text-align: center;"><em><span>&#8220;ARMCF assumes that good intentions and acceptable use policies are not enough without technical enforcement and observable evidence.&#8221;</span></em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!JFVG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99e29f06-725c-4b5d-aea3-c721c966a005_1672x941.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!JFVG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99e29f06-725c-4b5d-aea3-c721c966a005_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!JFVG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99e29f06-725c-4b5d-aea3-c721c966a005_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!JFVG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99e29f06-725c-4b5d-aea3-c721c966a005_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!JFVG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99e29f06-725c-4b5d-aea3-c721c966a005_1672x941.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!JFVG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99e29f06-725c-4b5d-aea3-c721c966a005_1672x941.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/99e29f06-725c-4b5d-aea3-c721c966a005_1672x941.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!JFVG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99e29f06-725c-4b5d-aea3-c721c966a005_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!JFVG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99e29f06-725c-4b5d-aea3-c721c966a005_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!JFVG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99e29f06-725c-4b5d-aea3-c721c966a005_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!JFVG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99e29f06-725c-4b5d-aea3-c721c966a005_1672x941.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em><span>Figure 2: ARMCF Lifecycle</span></em></p><h2><strong><span>Pillars and Domains</span></strong></h2><p><span>ARMCF is organized into six domains that act as the framework&#8217;s operational pillars.</span></p><ol><li><p><strong><span>GOVERN:</span></strong><span> Establishes accountability, policy, risk appetite, inventory discipline, third-party governance, and fairness expectations.</span></p></li><li><p><strong><span>IDENTIFY:</span></strong><span> Covers asset discovery, data-flow understanding, AI-specific threat modeling, risk scoring, and blast-radius analysis.</span></p></li><li><p><strong><span>PROTECT:</span></strong><span> Defines preventive controls across prompts, outputs, tools, agent identity, least-privilege data handling, secure development, and workload isolation.</span></p></li><li><p><strong><span>DETECT:</span></strong><span> Focuses on telemetry, behavioral baselines, anomaly detection, data exfiltration monitoring, SIEM integration, and supply chain monitoring.</span></p></li><li><p><strong><span>RESPOND:</span></strong><span> Defines incident classification, containment, evidence handling, escalation, and root-cause analysis for AI-specific events.</span></p></li><li><p><strong><span>RECOVER:</span></strong><span> Addresses restoration, re-validation, control improvement, and lessons learned.</span></p></li></ol><p><span>These pillars are meaningful because they translate strategic intent into operational sequencing. For example, an organization that has drafted an AI policy but lacks inventory, monitoring, or containment capability cannot credibly claim readiness for high-risk agentic deployment. ARMCF therefore encourages leaders to think in terms of control completeness rather than isolated compliance artifacts.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!XNY5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc20b5641-ddb5-412a-9e83-ad0d399f27b2_1672x941.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!XNY5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc20b5641-ddb5-412a-9e83-ad0d399f27b2_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!XNY5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc20b5641-ddb5-412a-9e83-ad0d399f27b2_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!XNY5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc20b5641-ddb5-412a-9e83-ad0d399f27b2_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!XNY5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc20b5641-ddb5-412a-9e83-ad0d399f27b2_1672x941.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!XNY5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc20b5641-ddb5-412a-9e83-ad0d399f27b2_1672x941.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c20b5641-ddb5-412a-9e83-ad0d399f27b2_1672x941.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!XNY5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc20b5641-ddb5-412a-9e83-ad0d399f27b2_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!XNY5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc20b5641-ddb5-412a-9e83-ad0d399f27b2_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!XNY5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc20b5641-ddb5-412a-9e83-ad0d399f27b2_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!XNY5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc20b5641-ddb5-412a-9e83-ad0d399f27b2_1672x941.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em><span>Figure 3: ARMCF Journey Stages</span></em></p><h2><strong><span>Foundational Guidance</span></strong></h2><p><span>For security and risk management leaders, ARMCF offers several foundational guidance steps.</span></p><ol><li><p><strong><span>Establish policy and risk appetite before broad enablement.<br></span></strong><span> Organizations should define acceptable automation levels, prohibited use cases, approved providers, and decision rights before business units scale adoption through pilots or embedded vendor features.</span></p></li><li><p><strong><span>Maintain a live AI system registry.<br></span></strong><span> The registry should record system name, owner, use case, autonomy level, data sensitivity, deployment environment, and control-layer coverage.</span></p></li><li><p><strong><span>Model threats in AI-native terms.<br></span></strong><span>Traditional threat modeling remains useful, but ARMCF calls for coverage of prompt injection, insecure output handling, training data poisoning, denial of service, supply chain vulnerabilities, sensitive information disclosure, insecure tool design, excessive agency, automation bias, model theft, adversarial examples, and backdoored models.</span></p></li><li><p><strong><span>Enforce least privilege and observable control at each decision point.<br></span></strong><span> Agent tool access, agent identities, secrets injection, network reachability, and policy guardrails should be constrained and logged.</span></p></li><li><p><strong><span>Treat AI monitoring and incident response as first-class SecOps concerns.<br></span></strong><span> AI telemetry should flow to the SIEM, alert categories should be tuned for AI-specific attack chains, and response procedures should support kill-switch, quarantine, forensic preservation, and root-cause analysis.</span></p></li></ol><h2><strong><span>Security Leadership Use Cases</span></strong></h2><p><span>ARMCF is especially useful for leaders who must align innovation with control assurance in regulated or audit-heavy environments. A CISO or security architect can use the framework to define minimum production requirements for AI systems, enforce role ownership, and prioritize investments in identity, data protection, prompt security, and monitoring.</span></p><p><span>A security risk manager can use ARMCF to standardize risk statements, map threats to controls, document residual risk, and record review cycles using the framework&#8217;s risk-register model. An internal audit or compliance function can use the cross-mapping to NIST, ISO, CIS, SOC 2, and EU AI Act-style tiers to evaluate whether AI governance claims are supported by documented processes and evidence with measurable metrics.</span></p><p><span>ARMCF gives stakeholders a shared operating model: leaders define acceptable risk, practitioners implement controls, and assurance functions verify whether those controls exist and work.</span></p><h2><strong><span>Readiness Model</span></strong></h2><p><span>ARMCF can also be read as a readiness model for AI and agentic adoption. At the most basic level, organizations need visibility: a current inventory, classification, data-flow mapping, and identification of tools and dependencies. Without that baseline, later controls become difficult to scope or test.</span></p><p><span>The next level is governance and prevention, where policy, ownership, tool allowlists, agent identities, data minimization, network isolation, and secure build controls are introduced.</span></p><p><span>After that comes operational maturity, where behavioral monitoring, prompt anomaly detection, SIEM integration, incident playbooks, and evidence preservation are embedded into daily operations.</span></p><p><span>The highest level is continuous improvement. Recovery planning, quarterly risk review, post-incident control enhancements, supply chain monitoring, and board-level reporting create the feedback loops required for sustainable governance. This staged interpretation aligns well with the implementation roadmap described in the core framework, which moves from foundation to enforcement to maturity over a defined period.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!haFN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee502c39-ae01-4c3d-ad39-ab67096a4335_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!haFN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee502c39-ae01-4c3d-ad39-ab67096a4335_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!haFN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee502c39-ae01-4c3d-ad39-ab67096a4335_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!haFN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee502c39-ae01-4c3d-ad39-ab67096a4335_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!haFN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee502c39-ae01-4c3d-ad39-ab67096a4335_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!haFN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee502c39-ae01-4c3d-ad39-ab67096a4335_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ee502c39-ae01-4c3d-ad39-ab67096a4335_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!haFN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee502c39-ae01-4c3d-ad39-ab67096a4335_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!haFN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee502c39-ae01-4c3d-ad39-ab67096a4335_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!haFN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee502c39-ae01-4c3d-ad39-ab67096a4335_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!haFN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee502c39-ae01-4c3d-ad39-ab67096a4335_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>Figure 4: ARMCF Framework Mappings</span></p><h2><strong><span>Mapping and Assurance</span></strong></h2><p><span>One of ARMCF&#8217;s strengths is that it does not ask organizations to abandon familiar frameworks. Instead, it acts as a translation layer that maps AI-specific needs to known governance and security structures such as NIST AI RMF, NIST SP 800-53, ISO 42001, CIS Controls, SOC 2, MITRE ATLAS, OWASP LLM Top 10, and CSA AICM 1.1. In regulated settings, assurance depends on demonstrating continuity with recognized models rather than introducing entirely  isolated methodologies.</span></p><p><span>The control mapping in the core framework spreadsheet that accompanies this paper shows how ARMCF controls connect to source obligations. Examples include linking GV-1 to NIST AI RMF GOVERN and NIST 800-53 risk management controls, PT-1 to NIST 800-53 input validation and transmission confidentiality, PT-3 to identity and access enforcement, DT-4 to SecOps monitoring, and RC-4 to continuous improvement requirements. These mappings help practitioners explain why a given control matters not only for AI safety but also for governance, audit, and assurance alignment.  For each control, the mapping spreadsheet also provides a suggested measurable metric along with scoring guidance as examples of how a control can be defined, applied and then consistently measured.</span></p><p><span>ARMCF also incorporates EU AI Act-style risk tiering concepts, distinguishing unacceptable, high, limited, and minimal risk use cases and tying them to varying expectations for domain coverage and oversight. A tiered model supports a defensible management narrative: stronger autonomy and stronger consequence require stronger governance. While full EU AI Act compliance has recently been postponed until 2027/28, it is still important to move ahead with preparations for compliance and to design new AI and agentic systems with the relevant controls in place.</span></p><p style="text-align: center;"><em><span>&#8220;Stronger autonomy and stronger consequence require stronger governance&#8221;</span></em></p><h2><strong><span>Implementation Guidance</span></strong></h2><p><span>The framework&#8217;s implementation roadmap provides a practical starting point for leaders who need to move from concept to delivery. In the foundation phase, the emphasis is on inventory, risk appetite, ownership assignment, threat modeling for the highest-risk systems, prompt inspection, and tool allowlisting. These are sensible first steps because they establish visibility and the earliest preventive boundaries.</span></p><p><span>In the enforcement phase, the framework introduces stronger identity, monitoring, SIEM correlation, incident playbooks, and AI SBOM integration. This reflects a transition from governance intention to control durability, where organizations begin to instrument AI systems in the same manner they instrument privileged workloads and critical applications.</span></p><p><span>In the maturity phase, the roadmap calls for broader MITRE ATLAS detection coverage, formal risk assessment of in-scope systems, tabletop response exercises, quarterly governance review, board reporting, and evaluation against ISO 42001 or other certification readiness. That final stage is especially relevant for organizations that must demonstrate not just intent, but measurable operational competence over time.</span></p><h2><strong><span>Putting ARMCF into Practice</span></strong></h2><p><span>For executive and non-specialist readers, the simplest interpretation of ARMCF is that AI adoption requires the same seriousness organizations already apply to identity, cloud, and third-party risk. Before granting AI systems broad access or autonomy, leadership should know what systems exist, what they can do, what data they can reach, who owns them, and how they are stopped when they misbehave.</span></p><p><span>This message does not imply that AI should be slowed indefinitely. It implies that adoption should be staged, classified, and evidenced in proportion to risk. The stronger the autonomy and the higher the consequence, the stronger the governance, technical controls, and monitoring that should be expected.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6RoV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9752282b-7126-4f5b-b40e-28e6c76c5e7f_1148x646.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6RoV!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9752282b-7126-4f5b-b40e-28e6c76c5e7f_1148x646.png 424w, https://substackcdn.com/image/fetch/$s_!6RoV!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9752282b-7126-4f5b-b40e-28e6c76c5e7f_1148x646.png 848w, https://substackcdn.com/image/fetch/$s_!6RoV!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9752282b-7126-4f5b-b40e-28e6c76c5e7f_1148x646.png 1272w, https://substackcdn.com/image/fetch/$s_!6RoV!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9752282b-7126-4f5b-b40e-28e6c76c5e7f_1148x646.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6RoV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9752282b-7126-4f5b-b40e-28e6c76c5e7f_1148x646.png" width="1148" height="646" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9752282b-7126-4f5b-b40e-28e6c76c5e7f_1148x646.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:646,&quot;width&quot;:1148,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6RoV!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9752282b-7126-4f5b-b40e-28e6c76c5e7f_1148x646.png 424w, https://substackcdn.com/image/fetch/$s_!6RoV!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9752282b-7126-4f5b-b40e-28e6c76c5e7f_1148x646.png 848w, https://substackcdn.com/image/fetch/$s_!6RoV!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9752282b-7126-4f5b-b40e-28e6c76c5e7f_1148x646.png 1272w, https://substackcdn.com/image/fetch/$s_!6RoV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9752282b-7126-4f5b-b40e-28e6c76c5e7f_1148x646.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em><span>Figure 5: Control Maturity Versus Risk Exposure</span></em></p><h2><strong><span>Closing Analysis</span></strong></h2><p><span>ARMCF is valuable because it translates the abstract challenge of AI governance into a concrete operating framework for security and risk leaders. Its main contribution is not unique or novel, but the integration of established cyber, risk, and AI guidance into a structure that reflects how agentic systems actually create business exposure.</span></p><p><span>For practitioners, the framework&#8217;s enduring strength is its balance: it is technical enough to guide architecture, controls, and incident handling, yet structured enough to support policy, auditability, and management communication. It helps  organizations assess readiness, prioritize capability development, and introduce AI and agentic systems with clearer ownership, stronger controls, and more defensible assurance outcomes.</span></p><p style="text-align: center;"><em><span>&#8220;Organizations should not adopt AI and agentic systems at speed unless they can identify what they use, define who is accountable, constrain what AI can access, observe how it behaves, and recover safely when things go wrong.&#8221;</span></em></p><h2><strong><span>Accompanying Resources:</span></strong></h2><p><span>SACR  has provided some sample tools and adjuncts to this document that provide additional detail of the recommended controls to implement. These are laid out in the same domains and principles as the guidance sections above, and also contain mapping to popular AI, Cloud and Security frameworks as well as some suggested metrics that can be used to measure compliance with a given control.</span></p><p><span>These resources are provided for informational purposes only. They do not constitute legal, compliance, or implementation advice, and SACR does not guarantee their accuracy, completeness, or suitability for regulated environments. Organizations should validate any control mapping, metric, or implementation decision against their own risk, legal, and compliance requirements.</span></p><p><span>Please also read the FAQ  for further explanation when considering risk and compliance implications.</span></p><h2><strong><span>Industry Resources For Practitioners</span></strong></h2><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://drive.google.com/drive/folders/1MhcL75RRKSR_Vh_gwJjWCjjkz1t6d2Fl&quot;,&quot;text&quot;:&quot;Full ARMCF Guide &amp; Resources&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://drive.google.com/drive/folders/1MhcL75RRKSR_Vh_gwJjWCjjkz1t6d2Fl"><span>Full ARMCF Guide &amp; Resources</span></a></p><p></p><h2><strong><span>ARMCF  Control Assessment Tables</span></strong></h2><p><span>The following summary tables adapt the attached ARMCF domains and control objectives into a practitioner-friendly methodology reference set for self-assessment and readiness analysis. Teams can use them to review existing controls, identify gaps, and prioritize remediation in advance of broader AI and agentic rollout.</span></p><p><span>In the accompanying Control and Mapping Spreadsheet for ARMCF, the same domains are represented in more detail,  with accompanying cross-references to existing Security frameworks, and with suggested measurement metrics and sample scoring rubrics also provided.</span></p><p></p><h3><strong><span>Domain Overview Table</span></strong></h3><p><span>The six ARMCF domains should be treated as an interconnected operating lifecycle, not as separate compliance categories. GOVERN and IDENTIFY establish the foundation; PROTECT and DETECT create enforceable control and visibility; RESPOND and RECOVER determine whether the organization can contain failure and restore operations safely. An organization&#8217;s readiness is ultimately limited by its weakest material control, not its average maturity score.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3z2C!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14ce040a-e97b-4824-b0b1-d6a0f25bcca1_2696x2056.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3z2C!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14ce040a-e97b-4824-b0b1-d6a0f25bcca1_2696x2056.png 424w, https://substackcdn.com/image/fetch/$s_!3z2C!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14ce040a-e97b-4824-b0b1-d6a0f25bcca1_2696x2056.png 848w, https://substackcdn.com/image/fetch/$s_!3z2C!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14ce040a-e97b-4824-b0b1-d6a0f25bcca1_2696x2056.png 1272w, https://substackcdn.com/image/fetch/$s_!3z2C!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14ce040a-e97b-4824-b0b1-d6a0f25bcca1_2696x2056.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3z2C!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14ce040a-e97b-4824-b0b1-d6a0f25bcca1_2696x2056.png" width="1456" height="1110" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/14ce040a-e97b-4824-b0b1-d6a0f25bcca1_2696x2056.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1110,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2540135,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://softwareanalyst.substack.com/i/206437801?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14ce040a-e97b-4824-b0b1-d6a0f25bcca1_2696x2056.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3z2C!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14ce040a-e97b-4824-b0b1-d6a0f25bcca1_2696x2056.png 424w, https://substackcdn.com/image/fetch/$s_!3z2C!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14ce040a-e97b-4824-b0b1-d6a0f25bcca1_2696x2056.png 848w, https://substackcdn.com/image/fetch/$s_!3z2C!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14ce040a-e97b-4824-b0b1-d6a0f25bcca1_2696x2056.png 1272w, https://substackcdn.com/image/fetch/$s_!3z2C!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14ce040a-e97b-4824-b0b1-d6a0f25bcca1_2696x2056.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><h3><span>GOVERN Methodology</span></h3><p>The GOVERN domain establishes the authority under which AI risk is accepted and managed. Before evaluating technical safeguards, the organization should be able to identify each production AI system, its accountable owner, its permitted use, its autonomy level and the individual authorized to accept residual risk. A policy without ownership, inventory and decision rights provides limited assurance.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xOwu!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefb4e900-a3e2-4002-b431-ba6629707605_2042x1304.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xOwu!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefb4e900-a3e2-4002-b431-ba6629707605_2042x1304.png 424w, https://substackcdn.com/image/fetch/$s_!xOwu!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefb4e900-a3e2-4002-b431-ba6629707605_2042x1304.png 848w, https://substackcdn.com/image/fetch/$s_!xOwu!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefb4e900-a3e2-4002-b431-ba6629707605_2042x1304.png 1272w, https://substackcdn.com/image/fetch/$s_!xOwu!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefb4e900-a3e2-4002-b431-ba6629707605_2042x1304.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xOwu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefb4e900-a3e2-4002-b431-ba6629707605_2042x1304.png" width="1456" height="930" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/efb4e900-a3e2-4002-b431-ba6629707605_2042x1304.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:930,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1347447,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://softwareanalyst.substack.com/i/206437801?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefb4e900-a3e2-4002-b431-ba6629707605_2042x1304.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!xOwu!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefb4e900-a3e2-4002-b431-ba6629707605_2042x1304.png 424w, https://substackcdn.com/image/fetch/$s_!xOwu!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefb4e900-a3e2-4002-b431-ba6629707605_2042x1304.png 848w, https://substackcdn.com/image/fetch/$s_!xOwu!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefb4e900-a3e2-4002-b431-ba6629707605_2042x1304.png 1272w, https://substackcdn.com/image/fetch/$s_!xOwu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefb4e900-a3e2-4002-b431-ba6629707605_2042x1304.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p></p><h3><span>IDENTIFY Methodology</span></h3><p>The IDENTIFY domain determines whether the organization understands its actual AI exposure. This includes sanctioned and shadow AI, data and context flows, reachable tools, external dependencies and the maximum potential blast radius. An assessment should consider the complete operating environment around the model, not only the model itself.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!i1Wn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5648f9f0-3c86-45cf-9ba1-560416220388_2036x1236.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!i1Wn!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5648f9f0-3c86-45cf-9ba1-560416220388_2036x1236.png 424w, https://substackcdn.com/image/fetch/$s_!i1Wn!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5648f9f0-3c86-45cf-9ba1-560416220388_2036x1236.png 848w, https://substackcdn.com/image/fetch/$s_!i1Wn!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5648f9f0-3c86-45cf-9ba1-560416220388_2036x1236.png 1272w, https://substackcdn.com/image/fetch/$s_!i1Wn!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5648f9f0-3c86-45cf-9ba1-560416220388_2036x1236.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!i1Wn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5648f9f0-3c86-45cf-9ba1-560416220388_2036x1236.png" width="1456" height="884" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5648f9f0-3c86-45cf-9ba1-560416220388_2036x1236.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:884,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1267300,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://softwareanalyst.substack.com/i/206437801?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5648f9f0-3c86-45cf-9ba1-560416220388_2036x1236.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!i1Wn!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5648f9f0-3c86-45cf-9ba1-560416220388_2036x1236.png 424w, https://substackcdn.com/image/fetch/$s_!i1Wn!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5648f9f0-3c86-45cf-9ba1-560416220388_2036x1236.png 848w, https://substackcdn.com/image/fetch/$s_!i1Wn!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5648f9f0-3c86-45cf-9ba1-560416220388_2036x1236.png 1272w, https://substackcdn.com/image/fetch/$s_!i1Wn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5648f9f0-3c86-45cf-9ba1-560416220388_2036x1236.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p></p><h3><strong>PROTECT Methodology</strong></h3><p>The PROTECT domain translates governance decisions into enforceable technical boundaries. Agent identities, tool invocation, data access, secrets, network reachability and software supply-chain integrity should be restricted by default and expanded only through deliberate approval. For agentic systems, least privilege must apply to both information access and action-taking capability.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZJGQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0ad4567-e37f-46de-bcef-18a73cc6227b_2028x1448.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZJGQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0ad4567-e37f-46de-bcef-18a73cc6227b_2028x1448.png 424w, https://substackcdn.com/image/fetch/$s_!ZJGQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0ad4567-e37f-46de-bcef-18a73cc6227b_2028x1448.png 848w, https://substackcdn.com/image/fetch/$s_!ZJGQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0ad4567-e37f-46de-bcef-18a73cc6227b_2028x1448.png 1272w, https://substackcdn.com/image/fetch/$s_!ZJGQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0ad4567-e37f-46de-bcef-18a73cc6227b_2028x1448.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZJGQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0ad4567-e37f-46de-bcef-18a73cc6227b_2028x1448.png" width="1456" height="1040" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c0ad4567-e37f-46de-bcef-18a73cc6227b_2028x1448.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1040,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1543411,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://softwareanalyst.substack.com/i/206437801?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0ad4567-e37f-46de-bcef-18a73cc6227b_2028x1448.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ZJGQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0ad4567-e37f-46de-bcef-18a73cc6227b_2028x1448.png 424w, https://substackcdn.com/image/fetch/$s_!ZJGQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0ad4567-e37f-46de-bcef-18a73cc6227b_2028x1448.png 848w, https://substackcdn.com/image/fetch/$s_!ZJGQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0ad4567-e37f-46de-bcef-18a73cc6227b_2028x1448.png 1272w, https://substackcdn.com/image/fetch/$s_!ZJGQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0ad4567-e37f-46de-bcef-18a73cc6227b_2028x1448.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p></p><h3><strong>RESPOND Methodology</strong></h3><p>The RESPOND domain tests whether the organization can contain an AI-related incident without depending on the affected system to cooperate. Response procedures should support rapid credential revocation, tool-access suspension, agent quarantine, kill-switch activation, evidence preservation and escalation to the appropriate security, legal, privacy and business stakeholders.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6zj7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36a9bc7a-9d01-4f00-835b-43f675eb636a_2088x1358.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6zj7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36a9bc7a-9d01-4f00-835b-43f675eb636a_2088x1358.png 424w, https://substackcdn.com/image/fetch/$s_!6zj7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36a9bc7a-9d01-4f00-835b-43f675eb636a_2088x1358.png 848w, https://substackcdn.com/image/fetch/$s_!6zj7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36a9bc7a-9d01-4f00-835b-43f675eb636a_2088x1358.png 1272w, https://substackcdn.com/image/fetch/$s_!6zj7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36a9bc7a-9d01-4f00-835b-43f675eb636a_2088x1358.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6zj7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36a9bc7a-9d01-4f00-835b-43f675eb636a_2088x1358.png" width="1456" height="947" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/36a9bc7a-9d01-4f00-835b-43f675eb636a_2088x1358.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:947,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1473079,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://softwareanalyst.substack.com/i/206437801?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36a9bc7a-9d01-4f00-835b-43f675eb636a_2088x1358.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6zj7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36a9bc7a-9d01-4f00-835b-43f675eb636a_2088x1358.png 424w, https://substackcdn.com/image/fetch/$s_!6zj7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36a9bc7a-9d01-4f00-835b-43f675eb636a_2088x1358.png 848w, https://substackcdn.com/image/fetch/$s_!6zj7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36a9bc7a-9d01-4f00-835b-43f675eb636a_2088x1358.png 1272w, https://substackcdn.com/image/fetch/$s_!6zj7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36a9bc7a-9d01-4f00-835b-43f675eb636a_2088x1358.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><h3><strong><span>RECOVER Methodology</span></strong></h3><p><span>The RECOVER domain addresses the conditions required for safe restoration. Restarting an AI system is not sufficient. Before redeployment, teams should verify the model and supporting artifacts, identities, permissions, allowlists, dependencies, data integrity and behavioral baselines. Material findings should feed back into the risk register and control roadmap.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7mrz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3af75822-9d29-48f0-acfd-2d52fe26476d_1992x1174.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7mrz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3af75822-9d29-48f0-acfd-2d52fe26476d_1992x1174.png 424w, https://substackcdn.com/image/fetch/$s_!7mrz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3af75822-9d29-48f0-acfd-2d52fe26476d_1992x1174.png 848w, https://substackcdn.com/image/fetch/$s_!7mrz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3af75822-9d29-48f0-acfd-2d52fe26476d_1992x1174.png 1272w, https://substackcdn.com/image/fetch/$s_!7mrz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3af75822-9d29-48f0-acfd-2d52fe26476d_1992x1174.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7mrz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3af75822-9d29-48f0-acfd-2d52fe26476d_1992x1174.png" width="1456" height="858" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3af75822-9d29-48f0-acfd-2d52fe26476d_1992x1174.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:858,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1058492,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://softwareanalyst.substack.com/i/206437801?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3af75822-9d29-48f0-acfd-2d52fe26476d_1992x1174.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!7mrz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3af75822-9d29-48f0-acfd-2d52fe26476d_1992x1174.png 424w, https://substackcdn.com/image/fetch/$s_!7mrz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3af75822-9d29-48f0-acfd-2d52fe26476d_1992x1174.png 848w, https://substackcdn.com/image/fetch/$s_!7mrz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3af75822-9d29-48f0-acfd-2d52fe26476d_1992x1174.png 1272w, https://substackcdn.com/image/fetch/$s_!7mrz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3af75822-9d29-48f0-acfd-2d52fe26476d_1992x1174.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p></p><h3><strong><span>Risk Register Reference</span></strong></h3><p><span>The risk register connects credible AI risk scenarios to the controls intended to prevent, detect or contain them. The examples below are illustrative rather than exhaustive. Organizations should adapt them to their own systems and record affected assets, likelihood, impact, control effectiveness, residual risk, accountable owner, remediation actions and review dates.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hFeX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75fb5a5d-f51c-45f4-8e31-dd8745bbb9e4_2196x1420.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hFeX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75fb5a5d-f51c-45f4-8e31-dd8745bbb9e4_2196x1420.png 424w, https://substackcdn.com/image/fetch/$s_!hFeX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75fb5a5d-f51c-45f4-8e31-dd8745bbb9e4_2196x1420.png 848w, https://substackcdn.com/image/fetch/$s_!hFeX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75fb5a5d-f51c-45f4-8e31-dd8745bbb9e4_2196x1420.png 1272w, https://substackcdn.com/image/fetch/$s_!hFeX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75fb5a5d-f51c-45f4-8e31-dd8745bbb9e4_2196x1420.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hFeX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75fb5a5d-f51c-45f4-8e31-dd8745bbb9e4_2196x1420.png" width="1456" height="941" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/75fb5a5d-f51c-45f4-8e31-dd8745bbb9e4_2196x1420.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:941,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1504077,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://softwareanalyst.substack.com/i/206437801?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75fb5a5d-f51c-45f4-8e31-dd8745bbb9e4_2196x1420.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!hFeX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75fb5a5d-f51c-45f4-8e31-dd8745bbb9e4_2196x1420.png 424w, https://substackcdn.com/image/fetch/$s_!hFeX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75fb5a5d-f51c-45f4-8e31-dd8745bbb9e4_2196x1420.png 848w, https://substackcdn.com/image/fetch/$s_!hFeX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75fb5a5d-f51c-45f4-8e31-dd8745bbb9e4_2196x1420.png 1272w, https://substackcdn.com/image/fetch/$s_!hFeX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75fb5a5d-f51c-45f4-8e31-dd8745bbb9e4_2196x1420.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p></p><h2>Conclusion &amp; Recommended Next Steps</h2><p>ARMCF gives security and risk leaders a practical structure for doing that. It connects governance decisions to technical safeguards, observable evidence, incident response and recovery. It also gives CISOs, engineering teams, risk functions and auditors a shared language for determining whether an AI system is ready for production and what must improve before it receives broader access or authority.</p><p>Security leaders can begin applying ARMCF through five practical actions:</p><ol><li><p><strong>Inventory</strong> sanctioned, embedded and shadow AI systems across the organization.</p></li><li><p><strong>Classify</strong> each system by autonomy, data sensitivity, business criticality and potential consequence.</p></li><li><p><strong>Assess</strong> the highest-risk systems against the six ARMCF domains.</p></li><li><p><strong>Prioritize</strong> material gaps in identity, tool access, data protection, monitoring, containment and recovery.</p></li><li><p><strong>Report</strong> readiness, residual risk and remediation ownership to the appropriate executive and governance stakeholders.</p></li></ol><p>Begin with the systems that can access sensitive data, invoke tools, call APIs, modify records or initiate consequential business actions. These systems represent the most immediate need for defensible governance and control.</p><h2>Put ARMCF into Practice</h2><p>Access the accompanying ARMCF resources to begin assessing your environment:</p><ul><li><p>Download the <strong>ARMCF Control and Mapping Spreadsheet</strong></p></li><li><p>Review the <strong>full ARMCF presentation and implementation guide</strong></p></li><li><p>Use the <strong>domain assessment tables</strong> to identify control gaps</p></li><li><p>Consult the <strong>ARMCF FAQ</strong> for additional risk and compliance context</p></li></ul><p>We welcome feedback from CISOs, security architects, AI security practitioners, risk leaders and auditors applying ARMCF in real environments. Your practical experience will help us strengthen future versions of the framework as agentic architectures and security requirements continue to evolve.</p><p><strong>Review the framework. Assess one high-risk AI system. Identify the control gaps that must be addressed before its autonomy expands.</strong></p><p>To receive future SACR research, framework updates and practitioner guidance, subscribe to Software Analyst Cyber Research and share ARMCF with the leaders responsible for AI governance and security in your organization.</p><p><strong>Questions or practitioner feedback? Contact the SACR research team using the <a href="https://softwareanalyst.io/contact/">contact form.</a></strong></p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Software Analyst Cyber Research! Subscribe for free to receive new cybersecurity research reports on Data, AI, SecOps and Identity</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/p/armcf-introducing-a-practitioner?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/p/armcf-introducing-a-practitioner?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/p/armcf-introducing-a-practitioner/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/p/armcf-introducing-a-practitioner/comments"><span>Leave a comment</span></a></p><div class="directMessage button" data-attrs="{&quot;userId&quot;:6770950,&quot;userName&quot;:&quot;SACR&quot;,&quot;canDm&quot;:null,&quot;dmUpgradeOptions&quot;:null,&quot;isEditorNode&quot;:true}" data-component-name="DirectMessageToDOM"></div><p></p><p></p>]]></content:encoded></item><item><title><![CDATA[The Case for Ephemeral Ransomware Resilience (ERR) And How Recovery Is the New Attack Surface ]]></title><description><![CDATA[The architectural standard for disaster recovery under full credential compromise and adversarial threat model]]></description><link>https://softwareanalyst.substack.com/p/the-case-for-ephemeral-ransomware</link><guid isPermaLink="false">https://softwareanalyst.substack.com/p/the-case-for-ephemeral-ransomware</guid><dc:creator><![CDATA[Lawrence Pingree]]></dc:creator><pubDate>Thu, 09 Jul 2026 18:01:26 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!0UaX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed09423f-c7c9-4243-a5fd-7951821fff2d_2352x1390.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p></p><p><strong>Executive Summary: The Evolution of Ransomware</strong></p><p>For a decade, defeating ransomware meant one thing: have backups you can restore. Attackers have since moved the fight. Instead of your data, they now target your recovery, disabling the consoles and credentials behind your backups before the ransom note ever lands. This report introduces <strong>Ephemeral Ransomware Resilience (ERR),</strong> a recovery standard that holds even when the attacker already has the keys.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0UaX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed09423f-c7c9-4243-a5fd-7951821fff2d_2352x1390.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0UaX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed09423f-c7c9-4243-a5fd-7951821fff2d_2352x1390.png 424w, https://substackcdn.com/image/fetch/$s_!0UaX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed09423f-c7c9-4243-a5fd-7951821fff2d_2352x1390.png 848w, https://substackcdn.com/image/fetch/$s_!0UaX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed09423f-c7c9-4243-a5fd-7951821fff2d_2352x1390.png 1272w, https://substackcdn.com/image/fetch/$s_!0UaX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed09423f-c7c9-4243-a5fd-7951821fff2d_2352x1390.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0UaX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed09423f-c7c9-4243-a5fd-7951821fff2d_2352x1390.png" width="1456" height="860" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ed09423f-c7c9-4243-a5fd-7951821fff2d_2352x1390.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:860,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3711070,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://softwareanalyst.substack.com/i/203710101?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed09423f-c7c9-4243-a5fd-7951821fff2d_2352x1390.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!0UaX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed09423f-c7c9-4243-a5fd-7951821fff2d_2352x1390.png 424w, https://substackcdn.com/image/fetch/$s_!0UaX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed09423f-c7c9-4243-a5fd-7951821fff2d_2352x1390.png 848w, https://substackcdn.com/image/fetch/$s_!0UaX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed09423f-c7c9-4243-a5fd-7951821fff2d_2352x1390.png 1272w, https://substackcdn.com/image/fetch/$s_!0UaX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed09423f-c7c9-4243-a5fd-7951821fff2d_2352x1390.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/subscribe?"><span>Subscribe now</span></a></p><p></p><p>Ransomware taught the security industry a hard lesson, and the industry learned it well. After years of watching organizations pay to unlock their own files, defenders invested in backups, then in immutable backups, and built recovery plans designed to make the ransom irrelevant. The logic was sound: if you can restore, you do not have to pay.</p><p>Attackers adapted to that logic. If reliable backups are what defeat ransomware, then the backups themselves become the target. Today&#8217;s operators rarely start with your data. They start with your recovery. During the weeks they spend inside a network before anyone notices, they hunt for the systems that would let you bounce back: the backup console, the credentials that control it, the replication settings, the restore workflows. They weaken or destroy that infrastructure first. By the time the ransom note appears, the recovery you were counting on may already be gone.</p><p>This is the part that catches even prepared teams off guard. Storage immutability was supposed to close this door. But write protection only stops deletion from inside the console. The console itself, along with the API and command line behind it, stays reachable. An attacker holding valid administrative credentials does not need to break anything. They use the access your own organization granted them, and copies that cannot be edited can still be expired, unprotected, or cut off from the systems meant to restore them.</p><p>SACR defines the response to this problem as Ephemeral Ransomware Resilience, or ERR: an architectural standard for recovery that stays intact even when an attacker already holds administrative control. ERR rests on three ideas, each aimed at removing a single point of failure. First, isolate the management plane, so protected copies cannot be reached through any console, API, or command line, no matter whose credentials are compromised. Second, create clean copies automatically and continuously, so a recent, trustworthy recovery point always exists without depending on a person acting correctly at the worst possible moment. Third, keep a temporary, independent compute environment on standby, so the business can keep running while primary systems are rebuilt.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NRQh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48701e96-a185-4942-ad6d-6bc8dabfcede_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NRQh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48701e96-a185-4942-ad6d-6bc8dabfcede_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!NRQh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48701e96-a185-4942-ad6d-6bc8dabfcede_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!NRQh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48701e96-a185-4942-ad6d-6bc8dabfcede_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!NRQh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48701e96-a185-4942-ad6d-6bc8dabfcede_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NRQh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48701e96-a185-4942-ad6d-6bc8dabfcede_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/48701e96-a185-4942-ad6d-6bc8dabfcede_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!NRQh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48701e96-a185-4942-ad6d-6bc8dabfcede_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!NRQh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48701e96-a185-4942-ad6d-6bc8dabfcede_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!NRQh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48701e96-a185-4942-ad6d-6bc8dabfcede_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!NRQh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48701e96-a185-4942-ad6d-6bc8dabfcede_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>For security leaders, the shift is simple to state and significant in practice. Ransomware resilience should be measured by provable recoverability, not by the existence of backups. The right question is no longer whether you have copies, but whether you could prove you would still recover if an attacker already held the keys. The pages that follow trace how the threat evolved, why tape, cloud immutability, and offsite replication all fall short against a credentialed attacker, and the specific questions every team should be able to answer about its own recovery architecture.</p><p>Recovery has become part of security architecture. ERR offers a practical way to know whether yours can withstand the attack it was built to survive.</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Software Analyst Cyber Research!  Subscribe for free to receive new cybersecurity research reports on Data &amp; AI Security.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><p><strong>Key Insights: The New Adversarial Reality</strong></p><ul><li><p><strong>Management-Plane Vulnerability: </strong>The $4.44M average breach cost is driven by 24-day attacker dwell times, allowing total compromise of reachable backup infrastructure before detection.</p></li><li><p><strong>Industrialized Handoff: </strong>The window from initial access to ransomware deployment has collapsed from 8 hours to 22 seconds, making human-led response obsolete.</p></li><li><p><strong>Structural Gaps: </strong>Current backup vendors protect storage while leaving control paths exposed</p></li></ul><p><strong>Implication:</strong> CISOs should treat management-plane isolation, ephemeral compute continuity, and on-demand rebuildability as architectural requirements rather than product features. Modern attacker timelines and AI agent-based attacks can routinely outrun human response. ERR assumes compromise is inevitable. Its objective is to make environments rebuildable on demand from trusted, automated sources while continuously proving restore readiness. This is the true promise and underpinning of becoming a resilient enterprise.</p><p><strong>Strategic Mandates for CISOs</strong></p><ol><li><p><strong>Enforce Isolation: </strong>Mandate management-plane isolation, not just storage immutability, as a non-negotiable procurement baseline.</p></li><li><p><strong>Verify Continuity: </strong>Validate sub-hourly recovery points and ensure ephemeral compute exists to sustain a 30-day restoration window.</p></li><li><p><strong>Scrub Restore Points: </strong>Implement pre-restore threat scanning to eliminate attacker persistence and prevent reinfection loops.</p></li></ol><p></p><h2><strong>The Ransomware Threat Landscape: From Encryption to Management-Plane Sovereignty</strong></h2><p>Recovery infrastructure is now a primary target. Attackers have pivoted from encrypting production data to dismantling the recovery control planes intended to safeguard it. Adversarial innovation has moved from volume-based encryption to industrialized, high-speed management-plane compromise, targeting the very consoles and APIs used for restoration. Effective defense requires architectural isolation that assumes administrative compromise, shifting the goal from preventing encryption to ensuring environment rebuildability.</p><ol><li><p><strong>Phase 1: Encrypt-and-Ransom (2013&#8211;2018). </strong>Primary focus on availability via production data encryption. Organizations neutralized this model through basic offline backups, forcing an adversarial pivot.</p></li><li><p><strong>Phase 2: Backup-Targeting (2019&#8211;2023). </strong>Pre-detonation dwell time utilized to locate and delete repositories. Backup destruction became routine, steadily declining the efficacy of traditional recovery methods.</p></li><li><p><strong>Phase 3: Management-Plane Sovereignty (2024&#8211;Present). </strong>Attackers leverage compromised admin consoles to delete backups on demand. The handoff from initial access to detonation has collapsed to <strong>22 seconds</strong>, making human-led response impossible.</p></li></ol><h2><strong>Strategic Evolution: The Industrialization of Extortion</strong></h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!gJYS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc22d667a-e8d0-4f84-9fec-b8f7deb64fe5_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gJYS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc22d667a-e8d0-4f84-9fec-b8f7deb64fe5_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!gJYS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc22d667a-e8d0-4f84-9fec-b8f7deb64fe5_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!gJYS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc22d667a-e8d0-4f84-9fec-b8f7deb64fe5_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!gJYS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc22d667a-e8d0-4f84-9fec-b8f7deb64fe5_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gJYS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc22d667a-e8d0-4f84-9fec-b8f7deb64fe5_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c22d667a-e8d0-4f84-9fec-b8f7deb64fe5_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!gJYS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc22d667a-e8d0-4f84-9fec-b8f7deb64fe5_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!gJYS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc22d667a-e8d0-4f84-9fec-b8f7deb64fe5_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!gJYS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc22d667a-e8d0-4f84-9fec-b8f7deb64fe5_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!gJYS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc22d667a-e8d0-4f84-9fec-b8f7deb64fe5_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>The Escalation of Extortion Models</strong></h3><p>Encryption is no longer the sole lever. Attackers now layer extortion models to bypass recovery defenses and maximize financial pressure through data suppression. The rise of data-theft-only variants (increasing from 2% in 2020 to &gt;15% in 2025<a href="https://cloud.google.com/blog/topics/threat-intelligence/m-trends-2026"><sup>1</sup></a>) and RaaS-driven industrialization has outpaced traditional perimeter and backup security. CISOs must adopt the Ephemeral Ransomware Resilience (ERR) standard to sustain operations via management-plane isolation and continuous, automated validation.</p><ul><li><p><strong>Triple extortion (third-party pressure):</strong> Attackers contact the victim&#8217;s customers, partners, or regulators directly, threatening to release their data or notify authorities, amplifying pressure beyond the primary victim.</p></li><li><p><strong>Data-theft-only extortion (no encryption):</strong> A rapidly growing variant, rising from roughly 2% of financially motivated incidents in 2020 to more than 15% in 2025 (Google M-Trends 2026). Attackers skip encryption entirely, relying purely on data exposure threats. This model is faster, lower-risk for the attacker, and bypasses backup-based defenses completely.</p></li><li><p><strong>Ransomware-as-a-Service (RaaS):</strong> The criminal supply chain that made all of the above scalable. Developers lease ransomware toolkits to affiliates who execute attacks and split proceeds. LockBit, BlackCat/ALPHV, Clop, and Akira all operated this model. Even after law enforcement disrupted LockBit and BlackCat in 2024, new affiliate groups emerged rapidly, with Flashpoint tracking a 179% year-over-year surge in attacks from successor groups.</p></li></ul><h3>Typical Ransomware Attack on Backups</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!necJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed4e4da2-a76b-42c9-9573-eb8e1fbd9087_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!necJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed4e4da2-a76b-42c9-9573-eb8e1fbd9087_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!necJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed4e4da2-a76b-42c9-9573-eb8e1fbd9087_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!necJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed4e4da2-a76b-42c9-9573-eb8e1fbd9087_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!necJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed4e4da2-a76b-42c9-9573-eb8e1fbd9087_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!necJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed4e4da2-a76b-42c9-9573-eb8e1fbd9087_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ed4e4da2-a76b-42c9-9573-eb8e1fbd9087_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!necJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed4e4da2-a76b-42c9-9573-eb8e1fbd9087_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!necJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed4e4da2-a76b-42c9-9573-eb8e1fbd9087_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!necJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed4e4da2-a76b-42c9-9573-eb8e1fbd9087_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!necJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed4e4da2-a76b-42c9-9573-eb8e1fbd9087_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>Full Ransomware Attack Phases in Detail</h3><ol><li><p><strong>Initial Access:</strong> This is the entry point into the target environment. Threat actors typically rely on the paths of least resistance to gain their initial foothold.</p><ul><li><p><strong>Phishing:</strong> Sending malicious attachments or links to harvest credentials or deploy initial loaders.</p></li><li><p><strong>Exploitation of Public-Facing Applications:</strong> Targeting unpatched vulnerabilities in firewalls, VPNs, or web servers.</p></li><li><p><strong>Compromised Credentials:</strong> Utilizing credentials purchased from Initial Access Brokers (IABs) or obtained through brute-force attacks on exposed Remote Desktop Protocol (RDP) instances.</p></li></ul></li><li><p><strong>Execution and Persistence:</strong> Once inside, the attacker needs to ensure they maintain access even if the initial entry point is discovered, patched, or rebooted.</p><ul><li><p><strong>Command and Control (C2):</strong> Establishing communication channels between the compromised network and attacker-controlled servers (often using tools like Cobalt Strike or Sliver).</p></li><li><p><strong>Persistence Mechanisms:</strong> Creating scheduled tasks, modifying registry run keys, or creating new system accounts to ensure continuous access.</p></li><li><p><strong>Defense Evasion:</strong> Disabling endpoint detection and response (EDR) tools, clearing logs, or using Living off the Land (LotL) techniques, abusing legitimate administrative tools like PowerShell or WMI to blend in with normal traffic.</p></li></ul></li><li><p><strong>Privilege Escalation:</strong> Initial access rarely grants the administrative rights needed to deploy ransomware network-wide. The attacker must elevate their privileges.</p><ul><li><p><strong>Credential Dumping:</strong> Extracting passwords or hashes from system memory (e.g., using Mimikatz to dump LSASS).</p></li><li><p><strong>Active Directory Exploitation:</strong> Utilizing attacks like Kerberoasting or exploiting domain misconfigurations to gain Domain Admin privileges.</p></li></ul></li><li><p><strong>Discovery and Lateral Movement:</strong> With elevated privileges, the attacker maps the network to identify high-value targets, critical data repositories, and the organization&#8217;s backup infrastructure.</p><ul><li><p><strong>Network Reconnaissance:</strong> Scanning for open ports, shared drives, and active directory structures.</p></li><li><p><strong>Lateral Movement:</strong> Moving from the initial compromised endpoint to other systems within the network using protocols like SMB or RDP, utilizing the credentials harvested in the previous stage.</p></li></ul></li><li><p><strong>Collection and Exfiltration:</strong> In modern double extortion campaigns, attackers steal sensitive data before locking the systems. This gives them leverage to demand payment even if the victim can restore from backups.</p><ul><li><p><strong>Data Staging:</strong> Archiving and compressing sensitive files into hidden directories.</p></li><li><p><strong>Exfiltration:</strong> Transferring the staged data to external cloud storage providers (like MEGA or cloud sync tools) using protocols that mimic normal outbound web traffic.</p></li></ul></li><li><p><strong>Impact (Encryption and Extortion):</strong> The final, visible stage of the attack.</p><ul><li><p><strong>Backup Destruction:</strong> Locating and deleting shadow copies, neutralizing local backups, or poisoning cloud backup routines to prevent easy recovery.</p></li><li><p><strong>Mass Deployment:</strong> Pushing the ransomware payload simultaneously across the network using tools like Group Policy Objects (GPO) or deployment software (e.g., SCCM).</p></li><li><p><strong>Encryption:</strong> Executing the encryption routine, locking the files, and dropping the ransom notes detailing how the victim can contact the attackers to negotiate payment for the decryption key and the promise to delete the exfiltrated data.</p></li></ul></li></ol><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4wVW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa378ee14-18a2-4e6d-ab83-6cf2b9b334d9_1672x941.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4wVW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa378ee14-18a2-4e6d-ab83-6cf2b9b334d9_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!4wVW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa378ee14-18a2-4e6d-ab83-6cf2b9b334d9_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!4wVW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa378ee14-18a2-4e6d-ab83-6cf2b9b334d9_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!4wVW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa378ee14-18a2-4e6d-ab83-6cf2b9b334d9_1672x941.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4wVW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa378ee14-18a2-4e6d-ab83-6cf2b9b334d9_1672x941.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a378ee14-18a2-4e6d-ab83-6cf2b9b334d9_1672x941.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!4wVW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa378ee14-18a2-4e6d-ab83-6cf2b9b334d9_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!4wVW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa378ee14-18a2-4e6d-ab83-6cf2b9b334d9_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!4wVW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa378ee14-18a2-4e6d-ab83-6cf2b9b334d9_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!4wVW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa378ee14-18a2-4e6d-ab83-6cf2b9b334d9_1672x941.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>With All These Critical Attacks, We Can See a Pattern Emerge</strong></h3><p>The pattern across all landmark incidents is that attackers did not simply encrypt files and wait. They spent dwell time understanding the victim&#8217;s backup and recovery posture, locating credentials for management consoles, and staging data exfiltration before triggering the final payload. Recovery architecture, not just perimeter defense, was a decisive factor in outcome severity and the strength of their breaches.</p><h1><strong>Modernizing Disaster Recovery: Architecture vs. Reactive Monitoring</strong></h1><p>Effective disaster recovery in the modern threat landscape requires moving beyond static, signature-based defenses. As ransomware operators weaponize shifting infrastructures, moving from encrypting data to dismantling recovery control planes, security teams must adopt proactive telemetry. By integrating anomaly detection with continuous configuration monitoring, defenders can surface architectural tampering before it manifests as a total recovery failure.</p><h3><strong>Anomaly Detection vs. Malware Scanning</strong></h3><p>These tools serve distinct, non-overlapping functions:</p><ul><li><p><strong>Anomaly Detection:</strong> Uses machine learning to establish behavioral baselines. It flags symptomatic evidence of active compromise, such as brute-force attempts on backup consoles, changes to backup policies, or unexpected changes in backup volume, enabling response before data loss occurs.</p></li><li><p><strong>Malware Scanning:</strong> A foundational validation layer focused on identifying known threats and validating software integrity within production environments.</p></li></ul><p><strong>Operational Directive:</strong> Malware scanning validates the cleanliness of a binary; anomaly detection validates the integrity of the infrastructure.</p><h3><strong>Change Detection as a Fidelity Signal</strong></h3><p>In compromised environments, unauthorized infrastructure modifications are often the sole indicator of administrative takeover. Threat actors frequently compromise infrastructure to isolate administrators, modify backup permissions, or establish persistence. Because adjacent sensors are often blinded or bypassed, continuous change monitoring of the backup control plane is essential. This telemetry acts as a high-fidelity trigger for investigation, identifying when the ground truth of the environment deviates from policy.</p><h3><strong>The Adversarial Focus: Targeting the Backup Control Plane</strong></h3><p>Backup infrastructure is the primary target for modern extortion. Threat actors monetize breaches by neutralizing the recovery path before triggering ransomware, either by severing administrator access, poisoning recovery routines, or modifying permissions to facilitate silent data exfiltration. Defender priorities must shift from purely securing the storage layer to hardening the access architecture surrounding it. Any management-plane configuration, permission, API key, or administrative account that enables recovery must be treated as a potential attack vector for lateral movement or sabotage.</p><h3><strong>Comparison of Anomaly Detection vs Malware Scanning</strong></h3><p>While both tools are necessary for a layered security strategy, they serve distinct operational purposes:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!kz5N!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42ea71b6-f8fd-40c1-8d4c-14218887803e_1672x941.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!kz5N!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42ea71b6-f8fd-40c1-8d4c-14218887803e_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!kz5N!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42ea71b6-f8fd-40c1-8d4c-14218887803e_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!kz5N!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42ea71b6-f8fd-40c1-8d4c-14218887803e_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!kz5N!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42ea71b6-f8fd-40c1-8d4c-14218887803e_1672x941.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!kz5N!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42ea71b6-f8fd-40c1-8d4c-14218887803e_1672x941.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/42ea71b6-f8fd-40c1-8d4c-14218887803e_1672x941.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!kz5N!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42ea71b6-f8fd-40c1-8d4c-14218887803e_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!kz5N!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42ea71b6-f8fd-40c1-8d4c-14218887803e_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!kz5N!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42ea71b6-f8fd-40c1-8d4c-14218887803e_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!kz5N!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42ea71b6-f8fd-40c1-8d4c-14218887803e_1672x941.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>Why Tape, Cloud Immutability, and Offsite Replication All Fail the Adversarial Recovery Test</strong></h3><p>Before the management-plane threat emerged, these approaches were considered adequate. Air-gapped tape offered physical separation. Cloud object lock offered write protection at the storage layer. Offsite replication offered geographic redundancy. Each was designed to protect against the operational failure modes that dominated the threat model through the 2010s: hardware failure, accidental deletion, and site-level outages. None were designed to survive a credential-holding attacker with console access and time to operate. When that threat model is applied, a structural gap appears in each approach, not in the storage medium, but in the access architecture surrounding it.</p><ul><li><p><strong>Air-gapped tape and drive:</strong> Operationally infeasible for modern recovery SLAs; often unmaintained.</p></li><li><p><strong>Cloud immutability with console access:</strong> Storage write protection exists, but admin credentials can issue delete commands via the management API. If those credentials are compromised, the backup is reachable.</p></li><li><p><strong>Offsite replication:</strong> Duplicates the problem: if the primary management plane is compromised, the replication credential is too.</p></li><li><p><strong>Manual backup schedules:</strong> Introduces human failure points at exactly the moment, during incident response, when humans are most error-prone and distracted.</p></li></ul><p>The gap is not in storage technology; it is in access architecture. Most backup platforms were designed for operational recovery (hardware failure, accidental deletion), not adversarial recovery (attacker with admin credentials attempting to eliminate recovery options before triggering ransomware).</p><p>The financial stakes are clear. IBM&#8217;s 2025 Cost of a Data Breach Report puts the global average breach cost at $4.44 million<a href="https://www.ibm.com/reports/data-breach"><sup>2</sup></a>. Verizon&#8217;s 2025 DBIR places median attacker dwell time at 24 days for non-actor-disclosed breaches<a href="https://www.verizon.com/business/resources/T16f/reports/2025-dbir-data-breach-investigations-report.pdf"><sup>3</sup></a>, leaving a window wide enough for attackers to map, stage, and execute against backup infrastructure long before detonation. Chainalysis notes that while total ransomware payments stagnated in 2025, median payment sizes rose to $59,565 as gangs shifted focus to higher-value targets.<a href="https://www.chainalysis.com/blog/crypto-ransomware-2026/"><sup>4</sup></a></p><p>Designing for adversarial recovery requires a fundamentally different assumption: <strong>treat the management plane as compromised by default.</strong></p><p>This distinction matters because:</p><ol><li><p><strong>Software-layer immutability</strong> protects data from deletion within the management console, but the console itself remains reachable. A compromised admin account can still interact with the backup environment and infrastructure.</p></li><li><p><strong>Architectural isolation</strong> removes the management plane entirely; there is no console, API, or CLI path to the protected copies, regardless of what credentials the attacker holds. The former is a policy control. The latter is a design guarantee. Only the latter holds under full credential compromise.</p></li></ol><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!l1Ms!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ff1a874-2592-4179-9bac-dc607109e683_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!l1Ms!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ff1a874-2592-4179-9bac-dc607109e683_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!l1Ms!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ff1a874-2592-4179-9bac-dc607109e683_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!l1Ms!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ff1a874-2592-4179-9bac-dc607109e683_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!l1Ms!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ff1a874-2592-4179-9bac-dc607109e683_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!l1Ms!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ff1a874-2592-4179-9bac-dc607109e683_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0ff1a874-2592-4179-9bac-dc607109e683_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!l1Ms!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ff1a874-2592-4179-9bac-dc607109e683_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!l1Ms!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ff1a874-2592-4179-9bac-dc607109e683_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!l1Ms!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ff1a874-2592-4179-9bac-dc607109e683_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!l1Ms!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ff1a874-2592-4179-9bac-dc607109e683_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Five Questions Every CISO Should Ask Before Trusting Their DR Architecture</strong></h2><p>Most DR architectures have never been stress-tested against the adversarial threat model, the scenario where the attacker already holds valid administrative credentials and is actively attempting to eliminate recovery options before triggering ransomware. Vendor documentation and sales briefings rarely address this scenario with architectural specificity. These five questions are designed to move that conversation from marketing claims to verifiable architecture. They apply equally in initial procurement, annual DR reviews, and post-incident retrospectives. A vendor that cannot answer them with specificity not policy language, but demonstrable design, fails the ERR standard.</p><p>When auditing a DR architecture against ERR principles, five questions expose the structural gaps:</p><ol><li><p><strong>Can an attacker with full admin credentials delete or modify your backup copies?<br></strong><em>Note: If yes or if the vendor cannot demonstrate otherwise, the architecture fails the ERR management-plane test.<br></em></p></li><li><p><strong>How often are isolated copies created, and is the process fully automated?<br></strong><em>Manual processes introduce failure at exactly the wrong moment. Hourly automated copies are the baseline.<br></em></p></li><li><p><strong>What is your recovery compute strategy if primary infrastructure is completely unavailable?<br></strong><em>Restoring to already destroyed infrastructure is not a recovery plan. Ephemeral VM continuity is required.<br></em></p></li><li><p><strong>Can you prove restore points are free of attacker persistence before restoration begins?<br></strong><em>Restoring a reinfected image extends the incident. Pre-restore threat scanning is an emerging best practice. Alternatively, organizations can restore data into a separate standby environment and scan it before returning it to production.<br></em></p></li><li><p><strong>What SLA governs ephemeral continuity duration?<br></strong><em>30 days is a baseline. Regulated industries may require longer windows and granular RTO guarantees.<br><br></em></p></li></ol><p><strong>Defining Ephemeral Ransomware Resilience (ERR): The Architectural Standard Immutability Forgot</strong></p><h3>Defining Ephemeral Ransomware Resilience (ERR)</h3><p>SACR Definition: Ephemeral Ransomware Resilience (ERR) and the Three Pillars That Distinguish It from Storage Immutability</p><p>Ephemeral Ransomware Resilience (ERR) is the architectural standard for disaster recovery systems that remain operationally intact when an attacker holds valid administrative credentials. It addresses the gap between storage-layer and disaster recovery immutability, which protects data at rest, and management-plane isolation, which removes the attacker&#8217;s ability to locate, delete, or corrupt backup copies and recovery infrastructure through any available control path.</p><p><strong>Best fit:</strong> Organizations with cloud and IaC momentum and leadership support for recovery engineering and control-plane hardening.</p><p>At a practical level, ERR requires three capabilities:</p><ul><li><p>Management-plane isolation that ensures backup copies cannot be accessed through a console, API, or CLI, even under full credential compromise.</p></li><li><p>Automated continuous protection that creates copies every hour or less without human intervention.</p></li><li><p>Ephemeral compute continuity that provisions temporary compute environments capable of sustaining business operations for 30 days or longer.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0gFp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2955093-aa98-46ef-a9db-98191b007733_1672x941.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0gFp!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2955093-aa98-46ef-a9db-98191b007733_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!0gFp!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2955093-aa98-46ef-a9db-98191b007733_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!0gFp!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2955093-aa98-46ef-a9db-98191b007733_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!0gFp!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2955093-aa98-46ef-a9db-98191b007733_1672x941.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0gFp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2955093-aa98-46ef-a9db-98191b007733_1672x941.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c2955093-aa98-46ef-a9db-98191b007733_1672x941.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!0gFp!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2955093-aa98-46ef-a9db-98191b007733_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!0gFp!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2955093-aa98-46ef-a9db-98191b007733_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!0gFp!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2955093-aa98-46ef-a9db-98191b007733_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!0gFp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2955093-aa98-46ef-a9db-98191b007733_1672x941.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Note: </strong>Vendor-neutral ERR Framework (can apply to any platform). This section is vendor-agnostic. Any provider that can prove management-plane isolation, automated continuous protection, and ephemeral compute continuity can theoretically satisfy ERR. ERR complements detection and incident response; it is not a replacement. ERR is also not a synonym for storage-layer immutability: basic write-once/object-lock capabilities that still leave console/API/CLI control paths reachable do not meet the ERR standard. ERR assumes an attacker may already hold valid administrative credentials and focuses on ensuring recovery remains viable under that condition. Organizations that treat air-gapped backups as equivalent to ERR should verify whether their air-gap extends to the management plane, not only the storage medium.</p><h3><strong>ERR Key Outcome: Ephemeral Compute Continuity</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!59yl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2b233dd-9eb7-406d-bd33-d80ee77d9a90_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!59yl!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2b233dd-9eb7-406d-bd33-d80ee77d9a90_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!59yl!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2b233dd-9eb7-406d-bd33-d80ee77d9a90_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!59yl!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2b233dd-9eb7-406d-bd33-d80ee77d9a90_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!59yl!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2b233dd-9eb7-406d-bd33-d80ee77d9a90_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!59yl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2b233dd-9eb7-406d-bd33-d80ee77d9a90_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b2b233dd-9eb7-406d-bd33-d80ee77d9a90_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!59yl!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2b233dd-9eb7-406d-bd33-d80ee77d9a90_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!59yl!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2b233dd-9eb7-406d-bd33-d80ee77d9a90_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!59yl!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2b233dd-9eb7-406d-bd33-d80ee77d9a90_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!59yl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2b233dd-9eb7-406d-bd33-d80ee77d9a90_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>What Is Ephemeral Compute Continuity?</strong></h3><p>Ephemeral Compute Continuity is a core requirement of the Ephemeral Ransomware Resilience (ERR) framework. It ensures that if your primary infrastructure is destroyed or compromised, you have a resilient, temporary, independent cloud environment ready to provision and sustain your business operations for a defined recovery window (30 days or more). Unlike traditional restoration, which often depends on the same infrastructure that may have been compromised, ephemeral compute provides a dedicated, standby environment to ensure your operations can continue without relying on the health of your primary systems.</p><h3><strong>Market Timing: ERR Is Early-Stage but Validated Before Becoming a Compliance Requirement</strong></h3><p>The window for establishing ERR as a recognized architectural standard is open, but it will not remain open indefinitely. Regulatory bodies are tightening DR requirements, cyber insurance underwriters are beginning to ask questions about management-plane access controls, and security leadership is increasingly aware that console-based backup deletion is a documented attacker tactic. The vendors and frameworks that define the category now will shape how buyers evaluate DR architecture for the next several years. ERR is still in its early adoption phase, giving early advocates disproportionate influence over the market narrative. As the concept matures, it will likely become a procurement checklist item, and enterprise pricing will play a larger role in buying decisions. N-able, the subject of this research report, offers flexibility and often dominates the conversation.</p><ul><li><p><strong>Stage:</strong> Signal and Early Traction (language is forming faster than standardized requirements)</p></li><li><p><strong>Vendor signals:</strong> N-able Cove Data Protection represents an early MSP-accessible path toward full ERR alignment; in parallel, enterprise-tier platforms are increasingly emphasizing management-plane isolation and verified recovery (including pre-restore validation) as roadmap priorities</p></li><li><p><strong>Customer signals:</strong> Growing CISO interest in whether an attacker with compromised credentials could delete backups. This is a question that most incumbent platforms cannot answer with architectural certainty.</p></li><li><p><strong>Regulatory signals:</strong> DORA (EU financial sector DR requirements), NIST CSF 2.0 recovery function emphasis, and tightening cyber insurance requirements are creating compliance demand for demonstrable recovery architecture</p></li><li><p><strong>SACR verdict:</strong> Real problem, early but credible solutions, market language still forming but ideal timing for concept evangelism, and for MSP-delivered ERR to establish the category before enterprise pricing dominates</p></li></ul><h3><strong>Common Misconceptions: Why Storage Immutability, Air-Gaps, and EDR Are Not Substitutes for ERR</strong></h3><p>Because ERR is a newly coined framework, buyers and vendors alike are still working out what it does mean, and what it does not. Several common misreadings create dangerous gaps in disaster recovery, or DR, posture. Organizations should not confuse ERR with storage immutability, traditional vault architectures, or detection technologies. They should verify that any claimed air gap extends to the management plane rather than only the storage layer. Each misconception leads organizations to believe they have adversarial recovery coverage that they do not, in fact, have.</p><ul><li><p>ERR is <strong>not</strong> storage immutability alone; write protection without management-plane isolation fails the adversarial test.</p></li><li><p>ERR is <strong>not</strong> a product category; it is an architectural standard that multiple vendors may satisfy through different implementations.</p></li><li><p>ERR is <strong>not</strong> a replacement for EDR/XDR/UEM/MDR; it is the recovery-layer complement to detection and response.</p></li></ul><h2><strong>Solution Landscape: Mapping Recovery Architectures to ERR</strong></h2><p>This taxonomy categorizes recovery stacks by their resilience to administrative compromise, differentiating between marketing claims of immutability and the architectural reality of control-plane isolation.</p><ul><li><p><strong>Immutable Storage Primitives (Hyperscalers):</strong> Write Once, Read Many (WORM) and object-lock policies harden the data layer but fail to mitigate console or API risk. Without management-plane severance, these remain reachable targets for credentialed attackers.</p></li><li><p><strong>Traditional Backup Platforms:</strong> Structurally vulnerable to credential-holding attackers. These are optimized for accidental deletion, not adversarial takeover, and fail if the management plane remains accessible via standard administrative paths.</p></li><li><p><strong>Enterprise Vault / Isolated Recovery Environments:</strong> Architecturally robust, providing hardened silos for data. However, they often impose prohibitive costs and operational overhead, limiting adoption to high-end enterprise deployments.</p></li><li><p><strong>DRaaS &amp; Orchestration Platforms:</strong> Superior in recovery speed and automation, yet frequently lack default management-plane isolation. Resilience here is a matter of configuration rather than fundamental design.</p></li><li><p><strong>Verified Recovery / Clean-Room Testing:</strong> Represents the market pivot from simple immutability to provable recoverability. Pre-restore validation is now a baseline expectation for mature recovery stacks.</p></li></ul><p><strong>SACR Directive:</strong> ERR is an architectural standard, not a brand. Any platform satisfying the three pillars, management-plane isolation, continuous automated copies, and ephemeral compute continuity, meets the standard. The adversarial threat model renders legacy designs relying on reachable consoles obsolete.</p><h3><strong>Benchmarking Recovery Strategies</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!W49h!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd14b1c78-3e07-4453-8687-628ec62b87a9_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!W49h!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd14b1c78-3e07-4453-8687-628ec62b87a9_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!W49h!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd14b1c78-3e07-4453-8687-628ec62b87a9_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!W49h!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd14b1c78-3e07-4453-8687-628ec62b87a9_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!W49h!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd14b1c78-3e07-4453-8687-628ec62b87a9_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!W49h!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd14b1c78-3e07-4453-8687-628ec62b87a9_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d14b1c78-3e07-4453-8687-628ec62b87a9_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!W49h!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd14b1c78-3e07-4453-8687-628ec62b87a9_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!W49h!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd14b1c78-3e07-4453-8687-628ec62b87a9_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!W49h!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd14b1c78-3e07-4453-8687-628ec62b87a9_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!W49h!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd14b1c78-3e07-4453-8687-628ec62b87a9_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Modernizing DR Validation: Continuous Resilience vs. Manual Testing</strong></h2><p>Traditional disaster recovery testing relies on manual, point-in-time exercises that are often infrequent and prone to human error. Modern resilient architectures mandate a shift to continuous, automated validation, ensuring that recovery capabilities are not merely planned, but provably operational.</p><h3><strong>Automated Recovery Testing (ART): Proving Viability</strong></h3><p>ART replaces manual, infrequent testing cycles with software-driven validation, continuously verifying that backup data is not just present, but functional and ready for deployment.</p><ul><li><p><strong>Orchestrated Sandboxing:</strong> Automated instantiation of isolated environments (sandboxes) enabling testing without disrupting production.</p></li><li><p><strong>Application-Level Validation:</strong> Testing extends beyond simple data existence; the system boots virtual machines or databases and executes validation scripts to confirm application-layer health.</p></li><li><p><strong>Compliance and Reporting:</strong> Automated teardown generates verifiable telemetry, which includes Recovery Time Objective (RTO) metrics, which are key to providing objective evidence of readiness for auditors and stakeholders.</p></li></ul><h3><strong>Clean Room Recovery (CRR): Ensuring Integrity</strong></h3><p>Standard restores risk a catastrophic re-infection loop, where dormant malware, backdoors, or compromised credentials within backups trigger immediate re-compromise. Clean Room Recovery provides the sanitization layer necessary to decouple recovery from potential persistence.</p><ul><li><p><strong>Isolated Sanitization:</strong> Systems are restored into a sterile, walled-off environment, completely segmented from the infected production network and external internet.</p></li><li><p><strong>Forensic Scrubbing:</strong> Within this environment, security teams leverage Endpoint Detection and Response (EDR) and forensic tools to identify and purge persistence mechanisms before reintroduction.</p></li><li><p><strong>Staged Reintroduction:</strong> Only after a system is cryptographically certified as clean and patched is it moved back into the production environment.</p></li></ul><h3><strong>Strategic Synthesis: Validation vs. Sanitization</strong></h3><p>These disciplines form a sequential, interdependent workflow:</p><blockquote><p><strong>1. ART (Validation) verifies that the infrastructure is capable of restoration.</strong></p><p><strong>2. CRR (Sanitization) ensures the data being restored is safe to operate.</strong></p></blockquote><p>A modern recovery strategy fails without both: ART guarantees your engine starts, while CRR ensures the vehicle is not sabotaged before you begin the journey.</p><h2><strong>N-able Cove Data Protection: Architectural Assessment</strong></h2><p>N-able Cove Data Protection operates as an ERR-aligned platform. Unlike legacy backup tools retrofitted for security, Cove&#8217;s design prioritizes management-plane isolation as a foundational requirement.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ttsu!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9332013c-db5d-405c-a574-af0b3f26706b_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ttsu!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9332013c-db5d-405c-a574-af0b3f26706b_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!ttsu!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9332013c-db5d-405c-a574-af0b3f26706b_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!ttsu!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9332013c-db5d-405c-a574-af0b3f26706b_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!ttsu!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9332013c-db5d-405c-a574-af0b3f26706b_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ttsu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9332013c-db5d-405c-a574-af0b3f26706b_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9332013c-db5d-405c-a574-af0b3f26706b_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!ttsu!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9332013c-db5d-405c-a574-af0b3f26706b_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!ttsu!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9332013c-db5d-405c-a574-af0b3f26706b_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!ttsu!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9332013c-db5d-405c-a574-af0b3f26706b_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!ttsu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9332013c-db5d-405c-a574-af0b3f26706b_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>ERR Pillar Mapping: A Technical Audit of Cove Data Protection</strong></h3><ul><li><p><strong>Management-Plane Isolation (Fortified Copies): </strong>These backups are stored in a physically and logically isolated environment. Access is strictly severed from the standard management console, API, and CLI. There is no automated path for an attacker, even one with full domain admin credentials, to locate, alter, or prematurely expire these copies. Restoration requires a verified, out-of-band support process, effectively functioning as an air-gap by design.</p></li><li><p><strong>Automated Continuous Protection: </strong>TrueDelta technology enables granular, byte-level tracking, supporting recovery point objectives (RPOs) of one hour or less. This automation removes the human dependency that typically causes backup failure during the high-stress, fog of war phase of a ransomware incident.</p></li><li><p><strong>Ephemeral Compute Continuity (DRaaS): </strong>Cove&#8217;s Disaster Recovery as a Service (DRaaS) provides the ephemeral compute tier necessary to sustain operations. By pre-staging standby images in the cloud, the platform allows for rapid failover, decoupling business continuity from the availability of primary infrastructure.</p></li></ul><p><strong>Analyst Directive: </strong>The MSP delivery model acts as a distribution moat. While enterprise-tier platforms achieve ERR through complex, high-overhead vaulting, N-able delivers comparable isolation via a multi-tenant channel. This simplifies the procurement and deployment of architectural resilience for mid-market organizations that lack the capacity to architect it internally.</p><h2><strong>Market Outlook: ERR as a Procurement Standard</strong></h2><p>Ephemeral Ransomware Resilience (ERR) is rapidly transitioning from a visionary architectural concept to a non-negotiable market requirement. As cyber insurance underwriters and regulatory bodies, such as DORA in the EU financial sector and NIST CSF 2.0, tighten recovery standards, simple immutability is no longer recognized as a sufficient defense against modern adversarial tactics.</p><h3><strong>Market Map: Ransomware Resilience Solutions &amp; ERR</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2SQs!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6c95f38-4227-404a-a7a6-673befcc447b_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2SQs!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6c95f38-4227-404a-a7a6-673befcc447b_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!2SQs!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6c95f38-4227-404a-a7a6-673befcc447b_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!2SQs!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6c95f38-4227-404a-a7a6-673befcc447b_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!2SQs!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6c95f38-4227-404a-a7a6-673befcc447b_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2SQs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6c95f38-4227-404a-a7a6-673befcc447b_1920x1080.png" width="727" height="408.9375" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a6c95f38-4227-404a-a7a6-673befcc447b_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:727,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!2SQs!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6c95f38-4227-404a-a7a6-673befcc447b_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!2SQs!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6c95f38-4227-404a-a7a6-673befcc447b_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!2SQs!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6c95f38-4227-404a-a7a6-673befcc447b_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!2SQs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6c95f38-4227-404a-a7a6-673befcc447b_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>The Roadmap to Mainstream Adoption</strong></h3><ul><li><p><strong>Procurement Shift (12&#8211;18 Months): </strong>Expect CISOs to move beyond generic &#8216;backup&#8217; requirements, demanding specific documentation on management-plane isolation during RFP processes. Legacy platforms that rely on reachable administrative consoles will face immediate scrutiny as organizations prioritize designs where even full credential compromise cannot result in backup deletion.</p></li><li><p><strong>Validation as a Service: </strong>Automated Recovery Testing (ART) will become a default baseline. Proving that backups are functional and capable of booting virtual machines or databases, not just present on disk, will shift from a nice-to-have feature to an auditable necessity for business continuity.</p></li><li><p><strong>The Sanitization Layer: </strong>Clean Room Recovery (CRR) will define the next maturity curve. The industry is moving toward a standard where restored data must be cryptographically certified as clean within isolated environments before reintroduction into the production network to prevent reinfection loops from dormant malware.</p></li><li><p><strong>Channel-Led Scaling: </strong>Mid-market organizations, lacking the internal capacity for complex recovery engineering, will rely on Managed Service Providers (MSPs) to operationalize ERR. The providers that successfully abstract the complexity of management-plane isolation and ephemeral compute will capture the bulk of this emerging market by providing enterprise-grade resilience at a mid-market price point.</p></li></ul><h3><strong>Strategic Cybersecurity and Disaster Recovery Industry Implications</strong></h3><p>The industrialization of extortion, where the median attacker dwell time remains around 24 days, allows threat actors significant time to dismantle recovery control planes. The shift toward ERR represents a fundamental change in the security contract: organizations are no longer just buying storage; they are procuring a guaranteed, isolated path to environment rebuildability that remains intact even when the primary infrastructure is totally compromised.</p><h3><strong>SACR Key Takeaway</strong></h3><p>Ephemeral Ransomware Resilience (ERR) corrects from potentially catastrophic outcomes by pivoting from reactive storage-level protection to proactive, architectural isolation. ERR is an essential implementation framework for modern adversarial resilience and recovery. ERR shifts the focus from simply preventing encryption to ensuring guaranteed environment rebuildability and data integrity, even in scenarios of full credential compromise.</p><p><strong>Sources:</strong></p><ol><li><p><strong>Google / Mandiant M-Trends 2026<br></strong>Median time between initial access and handoff to ransomware operators collapsed from more than 8 hours in 2022 to just 22 seconds in 2025, driven by pre-staged tooling and industrialized initial access broker collaboration. Attacks combining encryption and data theft rose to 77% of ransomware intrusions (up from 57% in 2024). Data-theft-only extortion grew from ~2% of financially motivated incidents in 2020 to more than 15% in 2025.<br><a href="https://cloud.google.com/blog/topics/threat-intelligence/m-trends-2026">https://cloud.google.com/blog/topics/threat-intelligence/m-trends-2026</a></p><p></p></li><li><p><strong>IBM Cost of a Data Breach Report 2025<br></strong>Global average cost of a data breach: $4.44 million. Organizations using AI-driven security cut breach lifecycle by 80 days and saved ~$1.9M on average.<br><a href="https://www.ibm.com/reports/data-breach">https://www.ibm.com/reports/data-breach<br></a></p></li><li><p><strong>Verizon 2025 Data Breach Investigations Report (DBIR)<br></strong>Median attacker dwell time for non-actor-disclosed breaches: 24 days. 54% of ransomware victims had their domains present in infostealer logs. 64% of victims refused to pay ransom in 2024.<br><a href="https://www.verizon.com/business/resources/T16f/reports/2025-dbir-data-breach-investigations-report.pdf">https://www.verizon.com/business/resources/T16f/reports/2025-dbir-data-breach-investigations-report.pdf<br></a></p></li><li><p><strong>Chainalysis 2026 Crypto Crime Report: Ransomware<br></strong>Total ransomware payments stagnated in 2025 even as attacks increased. Median ransom payment rose to $59,565 (up from $12,738 in 2024), reflecting a shift toward higher-value targets.<br><a href="https://www.chainalysis.com/blog/crypto-ransomware-2026/">https://www.chainalysis.com/blog/crypto-ransomware-2026/</a><a href="https://cloud.google.com/blog/topics/threat-intelligence/m-trends-2026"><br></a></p></li></ol><p><strong>Disclosure:</strong> This report is commissioned and sponsored by N-able. SACR retains full editorial control, independence and objectivity. N-able&#8217;s role is limited to providing briefing access, customer contacts, and factual review. Sponsorship does not influence SACR&#8217;s findings, competitive analysis, or recommendations.</p><div><hr></div><p></p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Software Analyst Cyber Research! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/p/the-case-for-ephemeral-ransomware/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/p/the-case-for-ephemeral-ransomware/comments"><span>Leave a comment</span></a></p><div class="directMessage button" data-attrs="{&quot;userId&quot;:6770950,&quot;userName&quot;:&quot;SACR&quot;,&quot;canDm&quot;:null,&quot;dmUpgradeOptions&quot;:null,&quot;isEditorNode&quot;:true}" data-component-name="DirectMessageToDOM"></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/p/the-case-for-ephemeral-ransomware?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/p/the-case-for-ephemeral-ransomware?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[From Perimeter to Proof: The New Architecture of Email Security]]></title><description><![CDATA[How identity, investigation, browser security, and AI are reshaping the future of email defense.]]></description><link>https://softwareanalyst.substack.com/p/from-perimeter-to-proof-the-new-architecture</link><guid isPermaLink="false">https://softwareanalyst.substack.com/p/from-perimeter-to-proof-the-new-architecture</guid><dc:creator><![CDATA[Anna Perrone]]></dc:creator><pubDate>Mon, 29 Jun 2026 12:03:28 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!AxDA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2922183e-4afc-4d23-b628-7bda7cf3d481_1980x1116.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Anna Perrone is a Research Associate/Business Process Analyst at SACR focused on email security, AI-driven threats, and research governance. Her work spans industry-wide reports and vendor analysis across the cybersecurity stack.</em><br></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Software Analyst Cyber Research! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h1><strong><span>Executive Summary</span></strong></h1><p><span>Email is still the cheapest, highest-leverage path into the enterprise. Three decades of layered defenses have not narrowed the vector. They have moved it up the stack. The fight today is not really about malicious attachments at the perimeter. It is about trust, identity, and human judgment inside the inbox, and across the workflows that wrap around the inbox. The argument of this report is that in 2026, email security should be understood and purchased as an identity-graph problem with auditable evidence behind it, rather than as a content-filter problem with a headline detection rate on the marketing page.</span></p><p><span>Four claims sit underneath that thesis.</span></p><p><strong><span>Email security is becoming more contextual.</span></strong><span> Many of today&#8217;s most damaging attacks, including business email compromise (BEC), vendor email compromise (VEC), account takeover (ATO), and OAuth abuse, often contain few traditional indicators of compromise. The relevant signal increasingly lies in communication patterns, identity relationships, behavioral context, and whether a request makes sense within the normal operation of the business.</span></p><p><strong><span>Email security is converging with identity, data, and security operations.</span></strong><span> Modern attacks rarely stop at the inbox. A phishing email may lead to credential theft, SaaS compromise, unauthorized access, or data exposure. As a result, organizations must evaluate email-security platforms based on how effectively they connect to identity systems, data-security programs, and incident-response workflows.</span></p><p><strong><span>The market is becoming more layered.</span></strong><span> No single architecture fully addresses prevention, contextual analysis, investigation, remediation, and governance. Secure email gateways (SEGs), integrated cloud email security platforms (ICES), investigation-centric tools, and automation-driven systems coexist because they solve different parts of the problem.</span></p><p><strong><span>The attacks are more layered. </span></strong><span>While email remains the dominant vector for social engineering, attacks are now proliferating across multiple channels and platforms such as Slack, WhatsApp, Teams, voicemail, etc. The invasion of trusted sources presents a major challenge that traditional solutions must work to solve. Until then, all messages, links, attachments, and senders must be assumed malicious.</span></p><p><strong><span>Explainability is becoming a procurement requirement.</span></strong><span> As email security becomes more interconnected and operationally significant, organizations need to understand why a platform reached a conclusion, what evidence supports it, and how response decisions can be defended to executives, auditors, regulators, and cyber insurers.</span></p><h2><strong><span>Why This Matters</span></strong></h2><p><span>For CISOs, security architects, and senior practitioners, the practical question is not whether the secure email gateway is dead or whether ICES replaces it. The better question is what each layer uniquely contributes. Does it prevent delivery? Does it understand the communication context? Does it produce evidence? Does it reduce blast radius? Does it remediate across mailboxes, shared folders, OAuth grants, mailbox rules, and collaboration surfaces? Does it integrate into the systems where security operations teams already work?</span></p><p><span>The future of email security is unlikely to be defined by a single architecture. It will be defined by how effectively different architectures help organizations understand attacks, respond to them efficiently, and reduce risk across an ever-more-complex communication environment.</span></p><h1><strong><span>Defining Email Security</span></strong></h1><p><span>For the purposes of this report, email security refers to the technologies and processes used to protect business communications from phishing, fraud, account compromise, unauthorized access, and data exposure.</span></p><p><span>Today, email security encompasses far more than the inspection of messages, links, and attachments. Organizations increasingly evaluate communications in the context of identities, relationships, business processes, user behavior, and the infrastructure that supports modern digital workflows. As a result, email-security platforms now incorporate varying degrees of behavioral analysis, identity context, investigation, remediation, automation, and response.</span></p><p><span>The category also extends beyond the inbox itself. Many attacks involve collaboration platforms, cloud applications, messaging systems, supplier portals, and browser-based workflows as part of a broader social-engineering chain. While email remains the primary focus of this report, many vendors increasingly position their offerings as broader communication-security platforms.</span></p><p><span>For this report, email security should therefore be understood as the set of technologies and workflows used to secure business communications, the identities and relationships that support those communications, and the business processes that attackers increasingly seek to exploit.</span></p><h1><strong><span>Why Email Security Is Changing</span></strong></h1><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!f4G4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10dd80ec-6c83-41df-9d02-acc73cda6d38_1590x894.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!f4G4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10dd80ec-6c83-41df-9d02-acc73cda6d38_1590x894.png 424w, https://substackcdn.com/image/fetch/$s_!f4G4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10dd80ec-6c83-41df-9d02-acc73cda6d38_1590x894.png 848w, https://substackcdn.com/image/fetch/$s_!f4G4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10dd80ec-6c83-41df-9d02-acc73cda6d38_1590x894.png 1272w, https://substackcdn.com/image/fetch/$s_!f4G4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10dd80ec-6c83-41df-9d02-acc73cda6d38_1590x894.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!f4G4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10dd80ec-6c83-41df-9d02-acc73cda6d38_1590x894.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/10dd80ec-6c83-41df-9d02-acc73cda6d38_1590x894.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!f4G4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10dd80ec-6c83-41df-9d02-acc73cda6d38_1590x894.png 424w, https://substackcdn.com/image/fetch/$s_!f4G4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10dd80ec-6c83-41df-9d02-acc73cda6d38_1590x894.png 848w, https://substackcdn.com/image/fetch/$s_!f4G4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10dd80ec-6c83-41df-9d02-acc73cda6d38_1590x894.png 1272w, https://substackcdn.com/image/fetch/$s_!f4G4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10dd80ec-6c83-41df-9d02-acc73cda6d38_1590x894.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>The evolution of email security is often described through product categories, but the deeper driver is attacker behavior. Attackers have adapted around the controls organizations deployed, and each adaptation has forced defenders to expand what email security is expected to understand.</span></p><p><span>The first generation of email security focused on malicious content and suspicious infrastructure. That made sense when attackers relied heavily on spam, malware attachments, commodity phishing kits, and newly registered domains. The defensive model was built around inspection, reputation, signatures, sandboxing, and policy enforcement.</span></p><p><span>Many of the most damaging attacks today look different. They exploit established relationships, legitimate infrastructure, identity workflows, and human decision-making under pressure. As a result, the current attack surface is not simply bad email; it is business workflow abused through email.</span></p><h2><strong><span>Business Email Compromise</span></strong></h2><p><span>Business email compromise remains one of the most damaging attack categories precisely because it often lacks the artifacts that email security tools were originally built to find. A BEC attack may impersonate an executive, finance employee, legal contact, or trusted business partner. The objective is usually to trigger a payment, redirect funds, disclose sensitive information, or approve an action that appears legitimate.</span></p><p><span>The technical content of the message may be unremarkable. There may be no malware attachment, no suspicious link, and no obviously malicious domain. The signal exists in the relationship, the timing, the request, and the deviation from normal business processes.</span></p><p><span>This is why relationship intelligence, behavioral baselining, and identity context became important. A content filter may see a normal message. A system with access to communication history and tenant behavior may see an unusual request from an unusual sender to an unusual recipient at an unusual time.</span></p><h2><strong><span>Vendor Email Compromise</span></strong></h2><p><span>Vendor email compromise extends this problem further because the attacker may operate from a legitimate supplier account. The sender is real, the domain is real, the email history is real, and the business relationship is real. The anomaly may be limited to a change in payment details, an unusual invoice, or a subtle deviation in workflow.</span></p><p><span>VEC is difficult because Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM), and Domain-based Message Authentication, Reporting, and Conformance (DMARC) may all pass. Domain reputation may be clean. The communication may be part of an existing thread. In this scenario, the security question becomes less about whether the sender can be authenticated and more about whether the request aligns with expected business behavior.</span></p><p><span>This is where ICES platforms and behaviorally informed systems gained traction. They were able to observe internal mail flow, mailbox relationships, communication cadence, and post-delivery behavior in ways that legacy gateway models often could not.</span></p><h2><strong><span>Trusted-Cloud Phishing</span></strong></h2><p><span>Trusted-cloud phishing has become one of the clearest examples of why reputation-based approaches are insufficient on their own. Attackers are expanding use of Microsoft 365, Google Workspace, Adobe, Dropbox, DocuSign, Atlassian, Confluence, Power BI, Notion, Figma, Vercel, Replit, and other legitimate services to host content or facilitate phishing workflows.</span></p><p><span>The infrastructure is often legitimate. The abuse occurs inside the workflow.</span></p><p><span>This creates a structural challenge for URL-rewrite controls and reputation feeds. A trusted domain may host a malicious workflow without the domain itself being malicious. The destination may not reveal risk until the user interacts with the page, follows a redirect chain, scans a QR code, grants OAuth consent, or submits credentials.</span></p><p><span>This is why dynamic analysis, URL detonation, browser interaction, screenshot capture, and redirect-chain reconstruction are becoming more important. For trusted-cloud phishing, defenders need to understand what happens after engagement rather than only evaluating the initial destination.</span></p><h2><strong><span>AI-Generated Social Engineering</span></strong></h2><p><span>Generative AI has changed the cost structure of phishing. Highly personalized spear phishing once required manual research and careful crafting. Today, attackers can generate targeted messages at scale using public data, breached information, social media, company context, and industry-specific language.</span></p><p><span>This does not mean every phishing email is sophisticated. It does mean the ceiling has moved. Messages can be more personalized, more grammatical, more context-aware, and more difficult to distinguish from routine business communication.</span></p><p><span>Static templates and legacy lexical detection struggle in this environment. If every message can be slightly different, template matching becomes less useful. Defenders must evaluate intent, sender behavior, communication context, and the action being requested.</span></p><h2><strong><span>OAuth, ATO, and Identity Abuse</span></strong></h2><p><span>Some email-related attacks do not depend on malicious email content at all. OAuth consent phishing, session hijacking, MFA fatigue, adversary-in-the-middle phishing, and help-desk social engineering often begin with communication but quickly move into identity systems.</span></p><p><span>An attacker may convince a user to grant a malicious OAuth application read or send permissions. They may steal a session cookie after MFA completion. They may impersonate an employee to a help desk and trigger an MFA reset. They may gain access to a mailbox and use that account for lateral phishing or supplier fraud.</span></p><p><span>These attacks show why email security and identity security are increasingly difficult to separate. The email may initiate the event, but the risk quickly moves into Entra ID, Google identity, OAuth grants, session tokens, mailbox rules, software-as-a-service (SaaS) applications, and data repositories.</span></p><p><span>For buyers, this changes the evaluation criteria. A modern email security platform will be judged not only on whether it blocks messages, but also on whether it helps contain ATO, clean up malicious mailbox rules, revoke OAuth grants, support SOAR and SIEM workflows, and connect suspicious communications to identity activity.</span></p><h2><strong><span>What These Attacks Have in Common</span></strong></h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!oN12!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92c3d82f-88b2-4988-87c0-c7e529cc3a31_1812x1016.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!oN12!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92c3d82f-88b2-4988-87c0-c7e529cc3a31_1812x1016.png 424w, https://substackcdn.com/image/fetch/$s_!oN12!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92c3d82f-88b2-4988-87c0-c7e529cc3a31_1812x1016.png 848w, https://substackcdn.com/image/fetch/$s_!oN12!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92c3d82f-88b2-4988-87c0-c7e529cc3a31_1812x1016.png 1272w, https://substackcdn.com/image/fetch/$s_!oN12!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92c3d82f-88b2-4988-87c0-c7e529cc3a31_1812x1016.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!oN12!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92c3d82f-88b2-4988-87c0-c7e529cc3a31_1812x1016.png" width="1456" height="816" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/92c3d82f-88b2-4988-87c0-c7e529cc3a31_1812x1016.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:816,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!oN12!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92c3d82f-88b2-4988-87c0-c7e529cc3a31_1812x1016.png 424w, https://substackcdn.com/image/fetch/$s_!oN12!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92c3d82f-88b2-4988-87c0-c7e529cc3a31_1812x1016.png 848w, https://substackcdn.com/image/fetch/$s_!oN12!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92c3d82f-88b2-4988-87c0-c7e529cc3a31_1812x1016.png 1272w, https://substackcdn.com/image/fetch/$s_!oN12!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92c3d82f-88b2-4988-87c0-c7e529cc3a31_1812x1016.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>Although these attack patterns differ, they share a common theme. They exploit trust that already exists in the organization.</span></p><p><span>BEC exploits trust between colleagues. VEC exploits trust between businesses. Trusted-cloud phishing exploits trust in legitimate platforms. OAuth abuse exploits trust in authentication workflows. AI-generated social engineering exploits trust in communication itself.</span></p><p><span>This does not make content inspection irrelevant. It means content inspection is no longer enough. The modern email security stack needs to combine content analysis, relationship intelligence, identity context, dynamic investigation, response automation, and evidence generation.</span></p><h1><strong><span>How Email Security Evolved</span></strong></h1><p><span>The history of email security is often presented as a sequence of product categories. Secure email gateways gave way to integrated cloud email security platforms, which are now competing with investigation-centric and agentic approaches. Viewed too simply, the market appears to be a series of replacements.</span></p><p><span>In practice, each generation emerged because attackers changed their behavior and because organizations changed how they communicated. New architectures were not created because previous approaches stopped working entirely. They emerged because existing methods became insufficient on their own.</span></p><p><span>Understanding this progression helps explain why the market now contains multiple competing models rather than one dominant architecture.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!o7Mh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2bbd1e36-38af-4cd4-a256-de345bf83780_1592x894.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!o7Mh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2bbd1e36-38af-4cd4-a256-de345bf83780_1592x894.png 424w, https://substackcdn.com/image/fetch/$s_!o7Mh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2bbd1e36-38af-4cd4-a256-de345bf83780_1592x894.png 848w, https://substackcdn.com/image/fetch/$s_!o7Mh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2bbd1e36-38af-4cd4-a256-de345bf83780_1592x894.png 1272w, https://substackcdn.com/image/fetch/$s_!o7Mh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2bbd1e36-38af-4cd4-a256-de345bf83780_1592x894.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!o7Mh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2bbd1e36-38af-4cd4-a256-de345bf83780_1592x894.png" width="1456" height="818" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2bbd1e36-38af-4cd4-a256-de345bf83780_1592x894.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:818,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!o7Mh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2bbd1e36-38af-4cd4-a256-de345bf83780_1592x894.png 424w, https://substackcdn.com/image/fetch/$s_!o7Mh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2bbd1e36-38af-4cd4-a256-de345bf83780_1592x894.png 848w, https://substackcdn.com/image/fetch/$s_!o7Mh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2bbd1e36-38af-4cd4-a256-de345bf83780_1592x894.png 1272w, https://substackcdn.com/image/fetch/$s_!o7Mh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2bbd1e36-38af-4cd4-a256-de345bf83780_1592x894.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong><span>The Perimeter Era</span></strong></h2><p><span>For much of email security&#8217;s history, the primary challenge was preventing malicious content from reaching users. Spam campaigns, malware attachments, malicious links, and known-bad infrastructure dominated the threat landscape. Attackers relied on domains and hosting environments that were often disposable and relatively easy to identify.</span></p><p><span>The resulting architecture was the secure email gateway. Secure email gateways (SEGs) sat in-path through MX redirection, inspected inbound and outbound messages before delivery, and enforced policy at the perimeter. Their capabilities included anti-spam scoring, signature-based malware detection, URL inspection, attachment sandboxing, encryption, outbound DLP, archiving, and continuity.</span></p><p><span>This model worked because the attack surface matched the control point. If most threats entered through the mail stream and carried identifiable content or infrastructure signals, then inspecting mail before delivery was both practical and effective.</span></p><p><span>The gateway era also created many capabilities that organizations still depend on. Regulated industries continue to require archive, eDiscovery, retention, encryption at send, continuity, and outbound policy controls. These are not legacy concerns. They remain central to how large enterprises manage communication risk.</span></p><p><span>The limitation was that the model assumed malicious activity could often be identified through the content or infrastructure associated with the message. As attackers shifted toward impersonation, account compromise, and social engineering, that assumption became less reliable.</span></p><h2><strong><span>The Cloud and Identity Era</span></strong></h2><p><span>The transition to Microsoft 365 and Google Workspace changed email security architecture. Email became one part of a broader cloud productivity environment connected to identity systems, document repositories, collaboration platforms, and SaaS workflows.</span></p><p><span>This transition created the conditions for integrated cloud email security. ICES platforms are deployed through API integrations rather than MX redirection, allowing them to observe mailbox telemetry, internal communications, identity context, and post-delivery behavior. They could identify, quarantine, claw back, or banner messages after delivery, and they could build tenant-level behavioral baselines based on how people actually communicated.</span></p><p><span>This was particularly useful for BEC, VEC, reply-chain hijack, ATO, and lateral phishing. These attacks often bypassed traditional inspection because there was little malicious content to inspect. The relevant signal existed in communication history, sender-recipient relationships, identity behavior, and deviations from baseline.</span></p><p><span>ICES introduced important advantages, but also structural tradeoffs. API-based systems can be faster to deploy and better positioned to observe internal mail, but messages may land before verdicts are rendered. API throttling can constrain scale in large tenants. Outbound DLP and pre-delivery policy enforcement are often thinner than in gateway architectures. Remediation depth varies widely, particularly across shared mailboxes, delegated folders, distribution lists, and lateral campaigns.</span></p><p><span>The cloud and identity era did not eliminate the gateway. It created a second layer with a different evidence shape.</span></p><h2><strong><span>The Investigation Era</span></strong></h2><p><span>The current phase is being shaped by trusted infrastructure, AI-generated social engineering, multimodal phishing, and operational pressure on security teams. Attackers now use legitimate SaaS platforms, QR codes, image-based content, dynamic redirects, HTML smuggling, and adversary-in-the-middle phishing kits to evade controls that depend on static indicators.</span></p><p><span>This has shifted the buyer question. Historically, organizations primarily wanted to know whether a message was malicious. Today, they need to know why it was flagged, how the attack works, whether similar messages exist elsewhere, what users interacted with it, and what response action occurred.</span></p><p><span>That creates demand for evidence packets and investigation workflows. Useful evidence may include reason strings, signal contributions, screenshots, redirect chains, certificate details, domain registration data, URL detonation results, model or rule references, analyst override history, and blast-radius analysis.</span></p><p><span>This is also where SOAR, SIEM, IT service management (ITSM), extended detection and response (XDR), and managed detection and response integrations become important. Detection that does not produce action is telemetry. The practical value of an email security platform depends on its ability to remediate across mailboxes, revoke malicious OAuth grants, remove mailbox rules, cluster campaigns, contain ATO, and reduce security operations center (SOC) workload.</span></p><h2><strong><span>Why Multiple Architectures Continue to Exist</span></strong></h2><p><span>Email security rarely evolves through clean replacement. Organizations operate under different constraints, and those constraints shape procurement.</span></p><p><span>A financial institution may require SEG-grade archive, encryption, continuity, and outbound DLP. A cloud-native technology company may prioritize ICES because its primary problem is BEC and supplier fraud. A data-sensitive enterprise may care about connecting phishing to DSPM, DLP, and managed detection, defense, and response (MDDR) workflows. A resource-constrained security team may prioritize agentic investigation and autonomous remediation.</span></p><p><span>These priorities are not mutually exclusive. Many mature programs will continue to run layered architectures that combine MX-in-path controls, API-based ICES, platform-native controls, identity integrations, browser protections, and response automation.</span></p><p><span>The next phase of the market is therefore unlikely to produce a single winner. It will be shaped by how effectively each architecture contributes useful context, evidence, and action.</span></p><h1><strong><span>Modern Email Security Architectures</span></strong></h1><p><span>The evolution of email security has produced a market that is more diverse than at any point in its history. Organizations face a wider range of threats than they did a decade ago, while security teams operate under different regulatory obligations, staffing constraints, risk tolerances, and operational priorities.</span></p><p><span>As a result, the market no longer revolves around a single architectural model. Instead, several approaches have emerged, each built around different assumptions about how attacks occur and what security teams need most.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-WWs!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F839ca188-f8fe-4e86-ba05-57c5d8ba0faf_1906x1076.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-WWs!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F839ca188-f8fe-4e86-ba05-57c5d8ba0faf_1906x1076.png 424w, https://substackcdn.com/image/fetch/$s_!-WWs!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F839ca188-f8fe-4e86-ba05-57c5d8ba0faf_1906x1076.png 848w, https://substackcdn.com/image/fetch/$s_!-WWs!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F839ca188-f8fe-4e86-ba05-57c5d8ba0faf_1906x1076.png 1272w, https://substackcdn.com/image/fetch/$s_!-WWs!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F839ca188-f8fe-4e86-ba05-57c5d8ba0faf_1906x1076.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-WWs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F839ca188-f8fe-4e86-ba05-57c5d8ba0faf_1906x1076.png" width="1456" height="822" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/839ca188-f8fe-4e86-ba05-57c5d8ba0faf_1906x1076.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:822,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:975681,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://softwareanalyst.substack.com/i/204048151?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F839ca188-f8fe-4e86-ba05-57c5d8ba0faf_1906x1076.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-WWs!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F839ca188-f8fe-4e86-ba05-57c5d8ba0faf_1906x1076.png 424w, https://substackcdn.com/image/fetch/$s_!-WWs!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F839ca188-f8fe-4e86-ba05-57c5d8ba0faf_1906x1076.png 848w, https://substackcdn.com/image/fetch/$s_!-WWs!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F839ca188-f8fe-4e86-ba05-57c5d8ba0faf_1906x1076.png 1272w, https://substackcdn.com/image/fetch/$s_!-WWs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F839ca188-f8fe-4e86-ba05-57c5d8ba0faf_1906x1076.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><h2><strong><span>Policy and Perimeter-Centric Architectures</span></strong></h2><p><span>Policy and perimeter-centric architectures are typically associated with secure email gateways. They inspect messages before delivery, enforce inbound and outbound policy, and provide capabilities such as malware analysis, URL inspection, attachment sandboxing, encryption, archive, eDiscovery, continuity, and outbound DLP.</span></p><p><span>Their strength is breadth. Many organizations require email security to support governance and compliance alongside threat detection. For these buyers, SEG capabilities remain essential.</span></p><p><span>The gap is context. Perimeter-centric architectures can struggle when attacks contain few traditional indicators of compromise, especially BEC, VEC, internal-to-internal lateral phishing, and account takeover. In those cases, identity context and communication history may matter more than attachment or URL inspection.</span></p><h2><strong><span>Relationship and Identity-Centric Architectures</span></strong></h2><p><span>Relationship and identity-centric architectures emerged because many modern attacks exploit existing relationships rather than suspicious infrastructure. These platforms use API deployment, mailbox telemetry, communication history, tenant baselines, sender-recipient patterns, authentication activity, and user context to identify suspicious behavior.</span></p><p><span>This model is particularly strong against BEC, VEC, executive impersonation, account takeover, and reply-chain hijack. The relevant signal often exists outside the message itself.</span></p><p><span>The tradeoff is that attackers combine behavioral deception with infrastructure abuse, trusted-cloud hosting, image-based phishing, quishing, and HTML smuggling. Relationship intelligence remains important, but it may not provide a complete view of attacks where the primary signal exists in the destination workflow rather than the communication relationship.</span></p><h2><strong><span>Investigation and Evidence-Centric Architectures</span></strong></h2><p><span>Investigation and evidence-centric architectures focus on understanding how attacks operate. They dynamically inspect URLs, follow redirect chains, capture screenshots, detonate content, analyze infrastructure, evaluate domains, and produce artifacts that analysts can review.</span></p><p><span>This approach is especially relevant for trusted-cloud phishing, QR-code attacks, adversary-in-the-middle kits, dynamic redirects, and attacks that hide malicious behavior behind legitimate services.</span></p><p><span>Its strength is explainability. Security teams, auditors, insurers, and executives need to understand why a verdict was reached. The challenge is operational balance. Deep investigation must be fast enough, scalable enough, and easy enough to integrate into SOC workflows.</span></p><h2><strong><span>Agentic and Automation-Centric Architectures</span></strong></h2><p><span>Agentic and automation-centric architectures focus on operational scale. They use LLMs, small language models, specialized agents, and automated workflows to investigate messages, evaluate intent, assemble evidence, cluster campaigns, trigger remediation, and reduce analyst workload.</span></p><p><span>This model reflects a practical problem. As AI lowers the cost of creating attacks, defenders need to lower the cost of investigation and response. Agentic systems attempt to function as force multipliers for SOC teams.</span></p><p><span>The open question is governance. Organizations need to understand how much authority they are willing to delegate to automated systems, especially when those systems can quarantine messages, trigger password resets, escalate incidents, or initiate XDR and SOAR workflows.</span></p><h2><strong><span>Why No Single Architecture Will Win</span></strong></h2><p><span>The existence of multiple architectures does not mean the market has failed to converge. It reflects the fact that organizations are solving different problems.</span></p><p><span>A regulated enterprise may prioritize SEG controls. A cloud-native organization may prioritize ICES. A security team facing trusted-cloud abuse may prioritize investigation and evidence. A lean SOC may prioritize agentic automation.</span></p><p><span>Most mature organizations will combine elements of several models. The procurement question is not which architecture is best in the abstract; it is which combination produces the most useful prevention, context, evidence, and response for the buyer&#8217;s specific environment.</span></p><h1><strong><span>Market Outlook: Email Security Beyond the Inbox</span></strong></h1><p><span>The email security market has spent three decades expanding the scope of what organizations expect from the category. The first generation focused on preventing malicious content from reaching the inbox. The second focused on understanding the relationships and behaviors surrounding communications. The current generation emphasizes investigation, response, and operational efficiency alongside detection.</span></p><p><span>The next phase is unlikely to be defined by one breakthrough technology. It will be shaped by several trends already visible in buyer priorities, attack patterns, and vendor roadmaps.</span></p><h2><strong><span>Identity and Email Continue to Converge</span></strong></h2><p><span>Email security and identity security are becoming more interconnected. BEC often relies on account compromise. OAuth abuse often begins with social engineering. Session theft, credential harvesting, MFA fatigue, and help-desk manipulation frequently involve communication channels alongside identity systems.</span></p><p><span>This does not mean email security vendors become identity vendors. It means email products need identity context, and identity products benefit from communication context.</span></p><p><span>Buyers should expect tighter integration with Entra ID, Google Identity, OAuth telemetry, session activity, ATO detection, mailbox-rule cleanup, and identity threat detection and response workflows.</span></p><p><span>Detection efficacy remains important, but detection claims are becoming harder to differentiate. Nearly every major vendor claims strong performance. Buyers want to know whether a platform can explain its decisions.</span></p><p><span>Evidence packets, detection-as-code, model cards, signal contributions, reason strings, analyst override paths, and exportable case records will become more important during procurement. Opaque classifiers may still perform well, but buyers under pressure from boards, insurers, auditors, and regulators prefer systems that can produce defensible evidence.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tBx3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2cc569fe-7b99-4733-9a87-6f1cf1faf19d_1982x1112.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tBx3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2cc569fe-7b99-4733-9a87-6f1cf1faf19d_1982x1112.png 424w, https://substackcdn.com/image/fetch/$s_!tBx3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2cc569fe-7b99-4733-9a87-6f1cf1faf19d_1982x1112.png 848w, https://substackcdn.com/image/fetch/$s_!tBx3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2cc569fe-7b99-4733-9a87-6f1cf1faf19d_1982x1112.png 1272w, https://substackcdn.com/image/fetch/$s_!tBx3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2cc569fe-7b99-4733-9a87-6f1cf1faf19d_1982x1112.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tBx3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2cc569fe-7b99-4733-9a87-6f1cf1faf19d_1982x1112.png" width="1456" height="817" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2cc569fe-7b99-4733-9a87-6f1cf1faf19d_1982x1112.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:817,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tBx3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2cc569fe-7b99-4733-9a87-6f1cf1faf19d_1982x1112.png 424w, https://substackcdn.com/image/fetch/$s_!tBx3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2cc569fe-7b99-4733-9a87-6f1cf1faf19d_1982x1112.png 848w, https://substackcdn.com/image/fetch/$s_!tBx3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2cc569fe-7b99-4733-9a87-6f1cf1faf19d_1982x1112.png 1272w, https://substackcdn.com/image/fetch/$s_!tBx3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2cc569fe-7b99-4733-9a87-6f1cf1faf19d_1982x1112.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong><span>Response Becomes More Important Than Detection</span></strong></h2><p><span>Security teams evaluate email security based on operational outcomes. The relevant questions are no longer limited to whether a vendor detects threats. Buyers want to know how quickly messages are removed, whether the system can claw back across shared mailboxes and delegated folders, how it handles OAuth grants and mailbox rules, whether it clusters related campaigns, and how well it integrates with SOAR, SIEM, ITSM, XDR, and MDDR workflows.</span></p><p><span>Mean time to remediation, blast radius reduced, SOC hours saved, ATO containment time, and false-positive reduction are becoming more useful metrics than raw detection rates.</span></p><h2><strong><span>Communication Security Expands Beyond Email</span></strong></h2><p><span>Email remains critical, but attacks now move across Teams, Slack, SharePoint, Google Drive, WhatsApp, LinkedIn, Discord, SMS, supplier portals, and browser-based workflows. Buyers should distinguish between integrations that merely forward alerts and integrations that provide message-level enforcement such as quarantine, removal, revoke, or user protection.</span></p><p><span>The future of communication security is less about protecting a single channel and more about following social engineering across the channels where work actually happens.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4_Qe!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F304b0810-9b68-47e8-9539-0e4db8fe2296_1592x896.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4_Qe!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F304b0810-9b68-47e8-9539-0e4db8fe2296_1592x896.png 424w, https://substackcdn.com/image/fetch/$s_!4_Qe!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F304b0810-9b68-47e8-9539-0e4db8fe2296_1592x896.png 848w, https://substackcdn.com/image/fetch/$s_!4_Qe!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F304b0810-9b68-47e8-9539-0e4db8fe2296_1592x896.png 1272w, https://substackcdn.com/image/fetch/$s_!4_Qe!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F304b0810-9b68-47e8-9539-0e4db8fe2296_1592x896.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4_Qe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F304b0810-9b68-47e8-9539-0e4db8fe2296_1592x896.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/304b0810-9b68-47e8-9539-0e4db8fe2296_1592x896.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!4_Qe!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F304b0810-9b68-47e8-9539-0e4db8fe2296_1592x896.png 424w, https://substackcdn.com/image/fetch/$s_!4_Qe!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F304b0810-9b68-47e8-9539-0e4db8fe2296_1592x896.png 848w, https://substackcdn.com/image/fetch/$s_!4_Qe!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F304b0810-9b68-47e8-9539-0e4db8fe2296_1592x896.png 1272w, https://substackcdn.com/image/fetch/$s_!4_Qe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F304b0810-9b68-47e8-9539-0e4db8fe2296_1592x896.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>Email and data security are also moving closer together. A phishing email may lead to credential theft, credential theft may lead to unauthorized access, and unauthorized access may lead to data exposure. The incident spans email, identity, SaaS, and sensitive data, even if it begins with one message.</span></p><p><span>This creates a closer relationship between email security, DSPM, DLP, insider risk, and MDDR. Buyers should expect more vendors to position phishing as the beginning of a broader attack lifecycle rather than a standalone category.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!RrYO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb741553-9a50-470d-9f10-36b5a7fc3db5_1590x892.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!RrYO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb741553-9a50-470d-9f10-36b5a7fc3db5_1590x892.png 424w, https://substackcdn.com/image/fetch/$s_!RrYO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb741553-9a50-470d-9f10-36b5a7fc3db5_1590x892.png 848w, https://substackcdn.com/image/fetch/$s_!RrYO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb741553-9a50-470d-9f10-36b5a7fc3db5_1590x892.png 1272w, https://substackcdn.com/image/fetch/$s_!RrYO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb741553-9a50-470d-9f10-36b5a7fc3db5_1590x892.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!RrYO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb741553-9a50-470d-9f10-36b5a7fc3db5_1590x892.png" width="1456" height="817" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bb741553-9a50-470d-9f10-36b5a7fc3db5_1590x892.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:817,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!RrYO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb741553-9a50-470d-9f10-36b5a7fc3db5_1590x892.png 424w, https://substackcdn.com/image/fetch/$s_!RrYO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb741553-9a50-470d-9f10-36b5a7fc3db5_1590x892.png 848w, https://substackcdn.com/image/fetch/$s_!RrYO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb741553-9a50-470d-9f10-36b5a7fc3db5_1590x892.png 1272w, https://substackcdn.com/image/fetch/$s_!RrYO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb741553-9a50-470d-9f10-36b5a7fc3db5_1590x892.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1><strong><span>CISO Implications</span></strong></h1><p><span>The email security market is becoming more complex, not less.</span></p><p><span>For most organizations, the future of email security will not involve replacing one architecture with another. Instead, it will involve assembling a layered security program that combines prevention, contextual analysis, investigation, and response capabilities.</span></p><p><span>As a result, the primary challenge for CISOs is no longer selecting a single email-security platform. It is determining which capabilities most directly reduce risk within their organization&#8217;s operating model, staffing constraints, regulatory requirements, and threat environment.</span></p><p><span>The most effective email-security programs over the next several years will not necessarily be those with the highest detection rates. They will be the programs that most effectively align technology investments with business risk, operational realities, and incident-response requirements.</span></p><h2><strong><span>Align Architecture to Risk</span></strong></h2><p><span>Different email-security architectures solve different problems.</span></p><p><span>Organizations operating in highly regulated industries continue to require secure email gateway capabilities such as encryption, archiving, continuity, eDiscovery, and outbound data loss prevention. These requirements do not disappear simply because phishing techniques evolve.</span></p><p><span>Organizations most concerned with business email compromise, supplier fraud, account takeover, executive impersonation, and lateral phishing may place greater emphasis on relationship- and identity-centric platforms capable of understanding communication context and behavioral anomalies.</span></p><p><span>Organizations facing sophisticated phishing campaigns that leverage trusted infrastructure, QR codes, image-based deception, adversary-in-the-middle workflows, or complex redirect chains may benefit from investigation-centric approaches that provide greater visibility into how attacks operate and why they were detected.</span></p><p><span>Organizations struggling with analyst workload, staffing shortages, or increasing alert volumes may place greater value on automation, orchestration, and agentic investigation capabilities designed to accelerate response and reduce manual effort.</span></p><p><span>The objective should not be identifying the &#8220;best&#8221; architecture. The objective should be identifying which combination of capabilities best supports the organization&#8217;s security operating model.</span></p><h3><strong><span>Indicators That Additional Investigation Capabilities May Be Needed</span></strong></h3><p><span>CISOs should consider strengthening investigation-centric capabilities when they observe one or more of the following conditions:</span></p><ul><li><p><span>Trusted-cloud phishing consistently bypasses existing controls.</span></p></li><li><p><span>Analysts spend significant time manually validating phishing verdicts.</span></p></li><li><p><span>Security teams struggle to explain detection decisions to executives, auditors, or insurers.</span></p></li><li><p><span>QR-code phishing, browser-based attacks, or credential-harvesting campaigns are increasing.</span></p></li><li><p><span>Security operations teams lack sufficient visibility into post-click attack behavior.</span></p></li><li><p><span>Incident investigations frequently require evidence gathering from multiple tools.</span></p></li></ul><p><span>These conditions often indicate that detection alone is not providing sufficient operational context.</span></p><h2><strong><span>Evaluate Operational Outcomes, Not Feature Lists</span></strong></h2><p><span>Many procurement processes still focus heavily on feature comparisons and detection claims. Those factors remain important, but they rarely determine long-term success. The more useful question is whether a platform improves operational outcomes.</span></p><p><span>Examples include:</span></p><ul><li><p><span>Reduction in business email compromise exposure.</span></p></li><li><p><span>Faster remediation of malicious messages.</span></p></li><li><p><span>Lower analyst investigation time.</span></p></li><li><p><span>Improved visibility into account compromise activity.</span></p></li><li><p><span>Reduced incident-response effort.</span></p></li><li><p><span>Better integration with existing security workflows.</span></p></li><li><p><span>More defensible evidence for audits, insurance reviews, and executive reporting.</span></p></li></ul><p><span>As the gaps in detection capabilities close across vendors, operational effectiveness becomes a more important differentiator than incremental improvements in efficacy.</span></p><h2><strong><span>Consider the Economics of Security Operations</span></strong></h2><p><span>Email security should be evaluated as both a technology decision and an operational decision. Many organizations already possess significant visibility into threats. The limiting factor is often the ability to investigate, validate, and respond at scale.</span></p><p><span>CISOs should therefore assess:</span></p><ul><li><p><span>Analyst effort required to investigate alerts.</span></p></li><li><p><span>Time required to remediate identified threats.</span></p></li><li><p><span>Administrative overhead associated with deployment and maintenance.</span></p></li><li><p><span>Training requirements for analysts and administrators.</span></p></li><li><p><span>Opportunities to consolidate tools or workflows.</span></p></li><li><p><span>Ability to automate repetitive investigative tasks.</span></p></li></ul><p><span>The most effective platform is not the platform that generates the most alerts. It is the platform that helps the organization reduce risk with the least operational friction.</span></p><p><span>As staffing pressures continue across the industry, operational efficiency becomes the important procurement consideration.</span></p><h2><strong><span>Implementation Considerations</span></strong></h2><p><span>Before adopting a new platform, security leaders should evaluate how well it integrates with the broader security ecosystem.</span></p><p><span>Key considerations include:</span></p><ul><li><p><span>Integration with Microsoft 365, Google Workspace, Entra ID, and identity-security platforms.</span></p></li><li><p><span>Support for SIEM, SOAR, XDR, ITSM, and incident-response workflows.</span></p></li><li><p><span>Remediation capabilities across shared mailboxes, delegated mailboxes, mailbox rules, OAuth grants, and collaboration environments.</span></p></li><li><p><span>Visibility into Teams, Slack, SharePoint, Google Drive, browser-based workflows, and other communication channels.</span></p></li><li><p><span>Reporting capabilities for security operations, audit, compliance, and executive stakeholders.</span></p></li><li><p><span>Administrative complexity and ongoing operational requirements.</span></p></li></ul><p><span>Organizations should also recognize that deployment architecture creates tradeoffs.</span></p><p><span>MX-based gateways often provide stronger pre-delivery controls, governance capabilities, and outbound protections. API-based platforms often provide richer contextual visibility, identity awareness, and post-delivery response capabilities.</span></p><p><span>Neither model is universally superior.</span></p><h2><strong><span>Emerging Risks CISOs Should Monitor</span></strong></h2><p><span>Several trends deserve increased attention over the next 24 months.</span></p><h3><strong><span>Trusted Infrastructure Abuse</span></strong></h3><p><span>Attackers leverage legitimate platforms rather than obviously malicious infrastructure. Microsoft 365, Google Workspace, Dropbox, Adobe, Atlassian, and similar services are frequently incorporated into phishing workflows.</span></p><p><span>This trend reduces the effectiveness of approaches that rely primarily on reputation and static indicators.</span></p><p><strong><span>Expanding Attack Surface</span></strong></p><p><span>As organizations deploy AI agents across inboxes and business workflows, they create new targets for social engineering. Agents increasingly interact with emails, links, attachments, and external requests on behalf of users, expanding the number of identities, workflows, and trust relationships that security teams must protect.</span></p><p><span>While AI agents may have purported &gt;99% detection rates, the &lt;1% outlier cases where the AI proves susceptible mandate that email-security programs evolve from protecting human users alone to securing both human and machine participants in business workflows.</span></p><h3><strong><span>Identity-Centric Attacks</span></strong></h3><p><span>Business email compromise, OAuth abuse, adversary-in-the-middle phishing, session theft, and account takeover blur the distinction between email security and identity security.</span></p><p><span>Organizations should expect tighter integration between email security, identity security, and incident-response programs.</span></p><h3><strong><span>Explainability Requirements</span></strong></h3><p><span>Security decisions face increasing scrutiny from boards, auditors, regulators, and cyber insurers.</span></p><p><span>Organizations should evaluate not only whether a platform can detect threats, but whether it can explain detection decisions in a way that supports operational and governance requirements.</span></p><h3><strong><span>Automation Governance</span></strong></h3><p><span>Agentic investigation and autonomous remediation offer significant operational benefits.</span></p><p><span>However, organizations should establish clear policies regarding what actions may be automated, what approvals are required, and how automated decisions are reviewed and validated.</span></p><h2><strong><span>Questions CISOs Should Answer Before Evaluating Vendors</span></strong></h2><p><span>Before engaging vendors, security leaders should align internally on several strategic questions:</span></p><ul><li><p><span>Is our primary concern governance, fraud prevention, phishing detection, investigation, or operational efficiency?</span></p></li><li><p><span>Where do our current controls consistently fail?</span></p></li><li><p><span>How much analyst time is spent investigating email-related incidents?</span></p></li><li><p><span>Do we require evidence suitable for audits, cyber-insurance reviews, or executive reporting?</span></p></li><li><p><span>How important is integration with identity-security workflows?</span></p></li><li><p><span>Do we need visibility beyond email into collaboration and communication platforms?</span></p></li><li><p><span>Which operational metrics are most important to improve over the next 24 months?</span></p></li></ul><p><span>Organizations that answer these questions first will generally conduct more effective evaluations than organizations that begin with product comparisons.</span></p><h2><strong><span>Priorities for the Next 12&#8211;24 Months</span></strong></h2><h3><strong><span>High Priority</span></strong></h3><ul><li><p><span>Reduce business email compromise and supplier fraud exposure.</span></p></li><li><p><span>Strengthen integration between email security and identity security.</span></p></li><li><p><span>Improve remediation speed and operational efficiency.</span></p></li><li><p><span>Increase visibility into trusted-cloud phishing and post-click attack behavior.</span></p></li></ul><h3><strong><span>Medium Priority</span></strong></h3><ul><li><p><span>Expand protection beyond email into collaboration and communication platforms.</span></p></li><li><p><span>Improve explainability and evidence generation for investigations.</span></p></li><li><p><span>Strengthen integration between phishing detection and incident-response workflows.</span></p></li></ul><h3><strong><span>Emerging Priority</span></strong></h3><ul><li><p><span>Evaluate agentic investigation and autonomous response capabilities.</span></p></li><li><p><span>Assess opportunities to consolidate investigation workflows.</span></p></li><li><p><span>Monitor convergence between email security, identity security, and data security.</span></p></li></ul><h2><strong><span>Bottom Line</span></strong></h2><p><span>The future of email security is unlikely to be defined by a single product category or architectural model. The organizations that succeed will be those that align prevention, contextual analysis, investigation, automation, and response capabilities around business risk rather than vendor categories.</span></p><p><span>The most important procurement question is, &#8220;Which combination of capabilities most effectively reduces risk and operational burden for our organization?&#8221;</span></p><h1><strong><span>Vendor Profiles</span></strong></h1><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!lBfn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcca6b36-f4b7-4756-b80a-7f44bacf9874_1704x956.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!lBfn!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcca6b36-f4b7-4756-b80a-7f44bacf9874_1704x956.png 424w, https://substackcdn.com/image/fetch/$s_!lBfn!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcca6b36-f4b7-4756-b80a-7f44bacf9874_1704x956.png 848w, https://substackcdn.com/image/fetch/$s_!lBfn!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcca6b36-f4b7-4756-b80a-7f44bacf9874_1704x956.png 1272w, https://substackcdn.com/image/fetch/$s_!lBfn!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcca6b36-f4b7-4756-b80a-7f44bacf9874_1704x956.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!lBfn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcca6b36-f4b7-4756-b80a-7f44bacf9874_1704x956.png" width="1456" height="817" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bcca6b36-f4b7-4756-b80a-7f44bacf9874_1704x956.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:817,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1648252,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://softwareanalyst.substack.com/i/204048151?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcca6b36-f4b7-4756-b80a-7f44bacf9874_1704x956.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!lBfn!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcca6b36-f4b7-4756-b80a-7f44bacf9874_1704x956.png 424w, https://substackcdn.com/image/fetch/$s_!lBfn!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcca6b36-f4b7-4756-b80a-7f44bacf9874_1704x956.png 848w, https://substackcdn.com/image/fetch/$s_!lBfn!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcca6b36-f4b7-4756-b80a-7f44bacf9874_1704x956.png 1272w, https://substackcdn.com/image/fetch/$s_!lBfn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcca6b36-f4b7-4756-b80a-7f44bacf9874_1704x956.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p><span>Unlike the earlier market map, which categorized vendors by their primary email-security architecture, the ecosystem map below illustrates how leading vendors are extending beyond traditional email security into adjacent domains. It highlights the broader security ecosystem, including identity, browser protection, data security, security operations, and human risk, to show where vendors are expanding their capabilities and where buyers should expect increasing market convergence.</span></p><p><span>The vendor profiles that follow are not product reviews, rankings, or procurement recommendations.</span></p><p><span>They are intended to illustrate how different vendors are responding to many of the same forces reshaping the email security market. Each profile reflects a distinct architectural perspective on the challenges discussed throughout this report, including business email compromise, trusted-cloud phishing, account takeover, explainability, operational scale, and the growing convergence between email, identity, and data security.</span></p><p><span>As a result, the profiles should not be evaluated primarily through a feature-by-feature comparison. Organizations purchase email security platforms for different reasons. A highly regulated enterprise may prioritize governance, continuity, encryption, and outbound DLP. A cloud-native organization may prioritize behavioral analysis and post-delivery remediation. A security team facing sophisticated phishing campaigns may place greater emphasis on investigation and evidence generation. Another may prioritize automation and analyst efficiency.</span></p><p><span>The goal of these profiles is therefore not to identify a single winner. It is to understand the assumptions each vendor is making about the future of email security, the problems each vendor is best positioned to solve, and the tradeoffs buyers should consider when evaluating different approaches.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!pfZh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08bdc2a5-b35d-4621-bc28-b9d27c11b32e_1990x1116.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!pfZh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08bdc2a5-b35d-4621-bc28-b9d27c11b32e_1990x1116.png 424w, https://substackcdn.com/image/fetch/$s_!pfZh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08bdc2a5-b35d-4621-bc28-b9d27c11b32e_1990x1116.png 848w, https://substackcdn.com/image/fetch/$s_!pfZh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08bdc2a5-b35d-4621-bc28-b9d27c11b32e_1990x1116.png 1272w, https://substackcdn.com/image/fetch/$s_!pfZh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08bdc2a5-b35d-4621-bc28-b9d27c11b32e_1990x1116.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!pfZh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08bdc2a5-b35d-4621-bc28-b9d27c11b32e_1990x1116.png" width="1456" height="817" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/08bdc2a5-b35d-4621-bc28-b9d27c11b32e_1990x1116.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:817,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1958766,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://softwareanalyst.substack.com/i/204048151?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08bdc2a5-b35d-4621-bc28-b9d27c11b32e_1990x1116.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!pfZh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08bdc2a5-b35d-4621-bc28-b9d27c11b32e_1990x1116.png 424w, https://substackcdn.com/image/fetch/$s_!pfZh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08bdc2a5-b35d-4621-bc28-b9d27c11b32e_1990x1116.png 848w, https://substackcdn.com/image/fetch/$s_!pfZh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08bdc2a5-b35d-4621-bc28-b9d27c11b32e_1990x1116.png 1272w, https://substackcdn.com/image/fetch/$s_!pfZh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08bdc2a5-b35d-4621-bc28-b9d27c11b32e_1990x1116.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><h2><strong><span>Mimecast</span></strong></h2><h3><strong><span>Overview</span></strong></h3><p><span>As email security has evolved, much of the industry&#8217;s attention has shifted toward behavioral analysis, identity context, and post-delivery detection. Yet for many large enterprises, email remains more than a phishing problem. It is a business-critical communications platform governed by regulatory requirements, legal discovery obligations, business continuity planning, and data-protection policies. These operational requirements continue to shape procurement decisions alongside evolving threat models.</span></p><p><span>Mimecast occupies a distinctive position because it approaches email security as both a security platform and a communications risk platform. While the company has expanded into AI-assisted detection, account takeover protection, automated investigation, data security, and human risk management, its architectural philosophy remains rooted in unifying prevention, governance, continuity, compliance, and operational resilience within a single platform. Recent product expansion also reflects a broader trend in which email security is converging with human risk, data protection, AI-enabled workflows, and broader communications security.</span></p><h3><strong><span>Why This Vendor Matters</span></strong></h3><p><span>Mimecast represents an important perspective within the email-security market: governance, resilience, and operational simplicity remain strategic requirements even as attackers increasingly exploit identity, trust, and human behavior.</span></p><p><span>Rather than abandoning its secure email gateway heritage, Mimecast has modernized it by incorporating behavioral detection, AI-assisted investigation, account takeover protection, data-security visibility, and human risk analytics. The result is a platform designed to balance traditional communications governance with the demands of today&#8217;s phishing, impersonation, identity-based attacks, and data-exposure risks. As organizations increasingly seek to consolidate security capabilities, Mimecast&#8217;s strategy reflects a broader market trend toward integrating communications security, governance, human risk, data protection, and operational resilience within a unified platform.</span></p><h3><strong><span>Product &amp; Architecture</span></strong></h3><p><span>Mimecast remains one of the few vendors capable of operating as a traditional MX-in-path secure email gateway, an API-integrated cloud email security platform, or a hybrid combination of both. This flexibility allows organizations to preserve pre-delivery inspection and policy enforcement while incorporating cloud-native visibility, post-delivery remediation, and behavioral analysis.</span></p><p><span>The platform&#8217;s API deployment model is also significant. Through direct integration with Microsoft 365 and Google Workspace, Mimecast can deliver its full detection stack through API deployment without requiring MX record changes. This allows customers to inspect and remediate messages after delivery without sitting directly in the mail flow, while documented APIs and prebuilt connectors enable email telemetry to integrate with broader security operations and automation workflows.</span></p><p><span>The platform combines malware detection, URL analysis, attachment inspection, impersonation protection, account takeover monitoring, collaboration security, archive, continuity, encryption, and outbound DLP within a unified architecture. Rather than positioning governance and threat protection as separate products, Mimecast increasingly presents them as complementary layers of the same communications-security platform.</span></p><p><span>Mimecast also provides DMARC management capabilities that help organizations enforce DMARC, SPF, and DKIM policies, improve visibility into legitimate email senders, and reduce domain spoofing alongside its broader governance and outbound protection capabilities.</span></p><p><span>Mimecast has also simplified ongoing administration by replacing large numbers of granular policies with protection categories built around phishing, malware, spam, and impersonation while still allowing advanced controls where needed. This reflects a broader trend toward reducing operational complexity without sacrificing enterprise flexibility.</span></p><p><span>At the center of Mimecast&#8217;s behavioral detection is CyberGraph, an identity graph that maps relationships between senders and recipients and learns normal communication patterns within an organization. Those relationship signals help identify potential impersonation, business email compromise, and other anomalies that may not be apparent through content inspection alone. CyberGraph also contributes to a cross-customer intelligence loop, allowing signals observed across the broader customer base to inform detection and protection beyond a single tenant&#8217;s relationship map.</span></p><h3><strong><span>Market Context</span></strong></h3><p><span>Mimecast reflects the continued relevance of policy- and governance-centric architectures. While much of the market has shifted toward relationship intelligence, identity-driven detection, and investigation-first workflows, many organizations continue to require retention, eDiscovery, encryption, continuity, outbound DLP, and policy enforcement. These requirements have not disappeared as attacks evolved. Instead, they increasingly coexist alongside behavioral detection, human-risk management, data-security visibility, and AI-assisted response.</span></p><p><span>The company&#8217;s recent investments suggest an acknowledgement that governance alone is no longer sufficient. By expanding into identity-aware detection, human risk analytics, automated investigation, data-security monitoring, and broader security integrations, Mimecast is attempting to bridge traditional communications governance with the operational demands of modern email security.</span></p><h3><strong><span>Product and Technical Notes</span></strong></h3><p><span>Several aspects of Mimecast&#8217;s recent product evolution stand out.</span></p><p><span>The platform&#8217;s Automated Remediation Service enables malicious messages to be removed across an organization when verdicts change after delivery, reducing analyst effort while limiting campaign spread. Mimecast has also strengthened its account takeover capabilities by integrating identity telemetry with Mimecast Insider to identify anomalous behavior, monitor potential data exfiltration, and automatically restrict compromised accounts from continuing to send email.</span></p><p><span>Mimecast also offers Email Incident Response services that provide expert-led investigation and remediation support for organizations that require additional operational assistance during active phishing campaigns. User and entity behavioral analytics further establish communication baselines so that suspicious deviations, rather than only known indicators of compromise, can trigger investigation or containment.</span></p><p><span>Another area of investment is analyst efficiency. Mimecast Mihra AI, or Mimecast Intelligent Human Risk Agent, comprises a growing suite of AI agents that support investigation workflows, summarize findings, recommend response actions, and integrate with external AI environments through the Mihra MCP Gateway. This allows security teams to run Mimecast investigation workflows inside external AI environments, including Claude and Gemini, rather than forcing those workflows into a separate interface. The platform also emphasizes explainability by surfacing the indicators that contributed to a verdict, allowing analysts to understand why a message was flagged rather than relying solely on opaque risk scores.</span></p><p><span>Mimecast has also expanded beyond traditional email security through capabilities such as Incydr, extending runtime visibility into data movement across endpoints, browsers, SaaS applications, MCP connections, and AI workflows. The company has similarly begun addressing risks associated with AI agents and machine identities, reflecting a broader shift as automated systems increasingly participate in business communications.</span></p><p><span>Mimecast also integrates with SIEM, SOAR, and broader security platforms, allowing email telemetry to contribute to enterprise-wide investigations. Human Risk Insights extends visibility into user risk, attack trends, and configuration improvements, while the Human Risk Command Center ingests third-party telemetry from tools such as CrowdStrike and Microsoft Defender to help security teams prioritize organizational risk. Managed security and incident-response services provide additional operational support for organizations with limited in-house security resources.</span></p><h3><strong><span>Operational Considerations for Buyers</span></strong></h3><p><span>Mimecast is often strongest in organizations where compliance, continuity, retention, encryption, operational governance, human risk reduction, and administrative simplicity remain important purchasing criteria alongside phishing protection.</span></p><p><span>Large enterprises and regulated industries may particularly value consolidating communications security, continuity, archiving, governance, data protection, and incident response within a single platform. Organizations whose primary objective is maximizing behavioral detection against sophisticated BEC or identity-centric attacks may also evaluate more specialized architectures, but buyers seeking to consolidate governance, resilience, human risk, data security, and threat protection are likely to view Mimecast differently than vendors focused primarily on detection.</span></p><h3><strong><span>Competition and Positioning</span></strong></h3><p><span>Mimecast competes through platform breadth rather than specialization. Its approach combines governance, continuity, compliance, threat protection, data protection, human risk capabilities, and broader communications-security coverage within a unified architecture instead of optimizing around a single detection methodology.</span></p><p><span>Recent efforts to simplify product packaging reinforce this strategy by making a broad platform easier to deploy and manage. As buyers continue to reduce product sprawl, operational simplicity, architectural breadth, and cross-domain telemetry may become increasingly important differentiators alongside detection efficacy.</span></p><h3><strong><span>Challenges and Open Questions</span></strong></h3><p><span>Mimecast&#8217;s primary challenge remains maintaining differentiation as behavioral analysis, explainability, AI-assisted investigation, and identity-aware detection become increasingly common across the market.</span></p><p><span>The company has significantly expanded its platform in recent years, extending into human risk, data security, AI-assisted operations, and broader communications security. The remaining question is less whether these capabilities exist and more how seamlessly they operate as a unified experience. Buyers will increasingly evaluate not only the depth of individual capabilities, but also whether the platform delivers measurable operational improvements across governance, security, data protection, and response.</span></p><h3><strong><span>Implications for Email Security Moving Forward</span></strong></h3><p><span>Mimecast&#8217;s recent direction suggests that the next phase of email security may involve operational consolidation as much as technical innovation. The company is simplifying deployment, integrating AI into analyst workflows, strengthening identity-aware response, expanding into data security and AI-related risks, and broadening its security ecosystem while preserving the governance capabilities that have long differentiated the platform.</span></p><p><span>If this direction continues, Mimecast may be well-positioned for organizations seeking to reduce operational complexity without sacrificing enterprise governance. Its continued investment in integrated security capabilities reflects a broader market trend toward platform consolidation, where governance, communications security, data protection, human risk, and operational resilience increasingly converge within unified security platforms.</span></p><h1><strong><span>Abnormal AI</span></strong></h1><h2><strong><span>Overview</span></strong></h2><p><span>Abnormal AI has established itself as one of the most prominent vendors in the ICES market by focusing on a problem that many organizations continue to struggle with: attacks that appear legitimate.</span></p><p><span>While phishing remains the most common email-borne threat, some of the most damaging incidents today involve BEC, VEC, ATO, executive impersonation, and other forms of social engineering that often contain few traditional indicators of compromise. In these scenarios, the challenge is not simply determining whether a message is malicious. It is determining whether a communication is consistent with the relationships, workflows, and business processes that normally exist within an organization.</span></p><p><span>Abnormal&#8217;s platform is designed around that premise. Its architecture emphasizes behavioral analysis, communication context, and organizational understanding rather than relying exclusively on content inspection and reputation systems. Over time, the company has expanded beyond its original focus on behavioral email detection into adjacent areas such as identity protection, ATO defense, explainability, and automated detection engineering.</span></p><p><span>Today, Abnormal&#8217;s position in the market is shaped less by the fact that it helped popularize relationship intelligence and more by how it continues to evolve those capabilities. Recent investments in a behavioral foundation model, threat research, explainability, and AI-assisted operations suggest a vendor focused on scaling and operationalizing behavioral security rather than treating it as a standalone detection technique.</span></p><h2><strong><span>Why This Vendor Matters</span></strong></h2><p><span>Abnormal represents one of the clearest examples of the industry&#8217;s shift toward communication-aware security.</span></p><p><span>The company&#8217;s platform is built around the belief that understanding how people normally communicate provides valuable security context that traditional inspection methods often miss. This remains particularly relevant as organizations continue facing attacks that exploit trusted relationships, supplier ecosystems, and established business processes.</span></p><p><span>Equally important, Abnormal has increasingly positioned itself not only as an email-security vendor but as a source of threat intelligence, attack research, and operational insight into how modern social-engineering campaigns are evolving.</span></p><h2><strong><span>Product &amp; Architecture</span></strong></h2><p><span>Abnormal operates as an API-based security platform integrated directly with Microsoft 365 and Google Workspace environments. This deployment model provides access to mailbox telemetry, communication history, identity signals, and organizational context that can be used to evaluate activity across the tenant.</span></p><p><span>The platform&#8217;s architecture is designed to identify behavioral anomalies rather than focusing exclusively on malicious content. Communications are evaluated against established patterns involving senders, recipients, vendors, executives, and business processes. This allows the platform to identify attacks that may appear legitimate from a purely technical perspective but are inconsistent when viewed through the lens of organizational behavior.</span></p><p><span>This approach has proven particularly effective against BEC, vendor fraud, executive impersonation, ATO, and lateral phishing. These attacks often rely on legitimate infrastructure, compromised accounts, or trusted relationships, reducing the effectiveness of traditional detection techniques.</span></p><p><span>Over time, Abnormal has expanded beyond email-specific use cases. Identity protection capabilities reflect the reality that many modern email incidents evolve into broader identity-security events involving credential theft, unauthorized access, privilege abuse, or account compromise.</span></p><p><span>The company&#8217;s architectural direction increasingly reflects a broader view of communications security in which email, identity, user behavior, and organizational trust are treated as interconnected sources of security intelligence.</span></p><p><span>The platform&#8217;s evolution also reflects a recognition that email incidents increasingly extend beyond the inbox. While Abnormal remains best known for its email-security capabilities, recent investments suggest a broader focus on communication and identity risk. Identity Protection addresses account takeover scenarios that often begin with phishing or credential theft but quickly expand into cloud applications, SaaS environments, and identity systems.</span></p><p><span>The company has also invested in post-delivery remediation workflows designed to reduce the operational burden associated with modern phishing campaigns. This reflects a broader industry reality: identifying a malicious message is only one part of the response process. Organizations must also determine who received the message, who interacted with it, whether similar messages exist elsewhere in the tenant, and what actions are required to contain the threat. By expanding beyond detection into remediation and identity-aware response, Abnormal increasingly positions itself as part of a larger security workflow rather than a standalone email control.</span></p><h2><strong><span>Market Context</span></strong></h2><p><span>Abnormal&#8217;s growth reflects a larger market reality: attackers have become increasingly adept at blending into normal business operations.</span></p><p><span>The company&#8217;s 2026 threat research found that while phishing represented the majority of observed attacks, BEC continued to account for a disproportionate share of financial impact. Within that category, VEC represented 61% of observed BEC attacks, highlighting the extent to which attackers now target trusted supplier relationships rather than relying solely on executive impersonation schemes.</span></p><p><span>The research also identified meaningful differences between organizations of different sizes. Smaller organizations experienced significantly higher rates of executive-focused impersonation attacks, while large enterprises saw attackers increasingly target employees and leverage lateral movement within compromised environments. According to the company&#8217;s findings, large enterprises were roughly 50 times more likely to experience lateral attacks than smaller organizations.</span></p><p><span>These trends reinforce a broader shift occurring across email security. Attackers are increasingly calibrating campaigns to specific organizational structures, communication patterns, and business processes. The challenge is no longer simply detecting malicious infrastructure. It is understanding how attacks exploit trust, familiarity, and organizational context.</span></p><p><span>Abnormal&#8217;s strategy is closely aligned with this reality.</span></p><h2><strong><span>Product and Technical Notes</span></strong></h2><p><span>Several recent developments help illustrate where the company is investing.</span></p><p><span>Attune 1.0, Abnormal&#8217;s behavioral foundation model, represents a formalization of the company&#8217;s long-standing focus on communication behavior. Rather than functioning as a general-purpose LLM, Attune is designed specifically to understand organizational communication patterns, relationship structures, and behavioral signals across enterprise environments. The objective is not simply language analysis but understanding how people, teams, suppliers, and executives normally interact.</span></p><p><span>Detection360 is another significant area of investment.</span></p><p><span>As email-security vendors increasingly report similarly high efficacy rates, buyers have become more interested in understanding how verdicts are generated and how detections evolve over time. Detection360 is designed to provide greater transparency into the signals contributing to a particular verdict and the reasoning behind platform decisions.</span></p><p><span>This capability is evolving beyond explainability alone. Recent enhancements provide visibility into the individual signals contributing to a detection, and show how customer submissions influence future detections across the platform. This creates a feedback loop between customer-reported incidents and ongoing detection improvement.</span></p><p><span>Perhaps more interesting is the company&#8217;s investment in AI-assisted detection engineering.</span></p><p><span>Detection360 enhancements also incorporate agentic workflows capable of analyzing customer submissions, generating semantic and lookalike detections, identifying similar messages across the environment, and supporting automated remediation efforts. Safeguards remain in place to prevent customer submissions from automatically generating new detections without additional analysis and validation, but the direction is notable. It reflects an effort to reduce manual detection-engineering overhead while improving responsiveness to emerging threats.</span></p><p><span>The emphasis on Detection360 appears closely tied to a broader challenge facing the email-security market. Most major vendors now report strong detection efficacy, making it increasingly difficult for buyers to differentiate platforms based solely on vendor-provided performance metrics. As a result, explainability, transparency, and operational validation are becoming more important procurement criteria.</span></p><p><span>Abnormal&#8217;s approach has been to provide greater visibility into how detections are generated, how customer-reported incidents influence platform protections, and how analysts can validate platform decisions. According to the company, customer environments continue to demonstrate extremely high detection efficacy while maintaining false-positive rates below one percent. Whether buyers view those numbers as differentiating factors increasingly depends on their ability to independently understand and verify platform outcomes.</span></p><p><span>This focus on validation extends into the company&#8217;s broader product strategy. Customer submissions increasingly function not only as incident reports but also as inputs into future detection development. The long-term vision appears to be a system in which customer observations, analyst workflows, threat research, and automated detection engineering contribute to a continuously evolving protection model. While many vendors discuss AI-assisted operations, Abnormal&#8217;s roadmap places particular emphasis on applying those capabilities to detection creation, campaign clustering, lookalike identification, and remediation rather than limiting them to analyst assistance alone.</span></p><p><span>Threat intelligence has also become a growing area of emphasis.</span></p><p><span>The company&#8217;s recent research into the Venom phishing-as-a-service operation provides a useful example. The campaign targeted executives across multiple industries and employed QR codes constructed from Unicode characters rather than image files, allowing them to bypass many traditional scanning techniques. Victims were directed to Microsoft impersonation pages with pre-populated credentials and ultimately subjected to MFA-bypass techniques designed to establish persistent access. According to the company, behavioral analysis played a critical role in identifying the campaign because it contained few traditional indicators of compromise.</span></p><p><span>This type of research appears increasingly important to Abnormal&#8217;s broader market strategy. Rather than relying exclusively on efficacy claims, the company is investing in original threat analysis intended to demonstrate how modern attacks operate and why behavioral detection remains relevant.</span></p><h2><strong><span>Operational Considerations for Buyers</span></strong></h2><p><span>Organizations evaluating Abnormal should consider the platform&#8217;s strengths in relation to their primary threat concerns.</span></p><p><span>The architecture is particularly well aligned with environments where BEC, supplier fraud, ATO, executive impersonation, and social-engineering attacks represent significant risks. The platform&#8217;s emphasis on communication context and behavioral understanding provides advantages in situations where content inspection alone may be insufficient.</span></p><p><span>Buyers should also evaluate how detection visibility, remediation workflows, threat-intelligence reporting, and identity-security capabilities fit within broader operational processes. As explainability becomes a more important procurement requirement, the ability to understand and defend platform decisions may become increasingly valuable.</span></p><h2><strong><span>Competition and Positioning</span></strong></h2><p><span>Abnormal competes most directly against both legacy SEGs and newer cloud-native email-security platforms.</span></p><p><span>Against traditional vendors such as Proofpoint and Mimecast, the company generally positions behavioral analysis and organizational understanding as its primary differentiators. Against Microsoft, Abnormal is often deployed as a complementary layer rather than a replacement, extending native protections with additional behavioral analysis and threat-detection capabilities. According to the company, Microsoft environments represent a substantial portion of its installed base.</span></p><p><span>The company also increasingly intersects with adjacent identity-security and identity threat detection and response (ITDR) markets as account takeover and credential abuse become larger components of modern email-security programs. This convergence reflects a broader industry trend in which communication security and identity security are becoming increasingly difficult to separate.</span></p><p><span>Abnormal&#8217;s strongest position is often within organizations that have already concluded that business email compromise, supplier fraud, and account takeover represent their highest-priority email threats. In these environments, communication context and behavioral analysis frequently become more important evaluation criteria than traditional gateway capabilities.</span></p><p><span>Organizations operating in highly regulated industries may evaluate the platform differently. Archive, continuity, encryption, outbound DLP, and broader governance requirements remain important purchasing criteria for many enterprises, and buyers may therefore compare Abnormal alongside more operationally focused platforms depending on their priorities.</span></p><p><span>As a result, Abnormal&#8217;s success often depends less on replacing existing email infrastructure entirely and more on convincing buyers that behavioral intelligence deserves a dedicated layer within the security stack. The company&#8217;s continued growth suggests that many organizations increasingly agree with that premise, particularly as social engineering, supplier fraud, and identity compromise continue driving financial losses across the market.</span></p><h2><strong><span>Challenges and Open Questions</span></strong></h2><p><span>Abnormal&#8217;s primary challenge is maintaining differentiation as behavioral analysis becomes more common across the industry.</span></p><p><span>Many competing platforms now incorporate communication context, identity telemetry, and behavioral signals into their detection models. As a result, differentiation increasingly depends on the quality of those models, the effectiveness of operational workflows, and the ability to demonstrate measurable outcomes rather than simply claiming behavioral capabilities.</span></p><p><span>The company also faces the challenge of proving efficacy in a market where many vendors report similarly strong detection rates. This reality helps explain the growing emphasis on Detection360, explainability, customer feedback loops, and original threat research. These investments suggest a recognition that buyers increasingly want evidence, transparency, and operational proof rather than broad marketing claims alone.</span></p><h2><strong><span>Implications for Email Security Moving Forward</span></strong></h2><p><span>Abnormal&#8217;s vision of the market assumes that understanding behavior will remain a foundational component of email security.</span></p><p><span>That assumption appears increasingly reasonable as attackers continue leveraging trusted relationships, compromised accounts, supplier ecosystems, and highly personalized social-engineering techniques. The company&#8217;s own threat research suggests that attackers are becoming more targeted, more adaptive, and more willing to exploit organizational context rather than relying on generic phishing campaigns.</span></p><p><span>At the same time, the future of email security is unlikely to be defined by behavioral analysis alone. Identity telemetry, threat intelligence, investigation workflows, explainability, and automated response capabilities are all becoming increasingly important components of modern security programs.</span></p><p><span>Abnormal&#8217;s recent investments suggest the company understands this shift. The evolution of Detection360, the expansion of identity-security capabilities, the development of agentic detection-engineering workflows, and the growing focus on threat intelligence all point toward a broader vision that extends beyond email filtering and behavioral detection.</span></p><h2><strong><span>Conclusion</span></strong></h2><p><span>Abnormal remains one of the most influential vendors in the modern email-security market because its core focus continues to align with how attacks are evolving.</span></p><p><span>The company&#8217;s emphasis on communication context, behavioral analysis, and organizational understanding remains highly relevant in an environment where BEC, vendor fraud, ATO, and sophisticated social-engineering attacks continue to challenge traditional security controls.</span></p><p><span>Recent investments in explainability, AI-assisted detection engineering, threat intelligence, and identity protection suggest a vendor focused not only on identifying threats but on helping organizations understand, validate, and operationalize security decisions. As email security continues converging with identity, investigation, and automation, those capabilities may prove just as important as detection efficacy itself.</span></p><h1><strong><span>Varonis Interceptor (formerly SlashNext)</span></strong></h1><h2><strong><span>Overview</span></strong></h2><p><span>Email security has historically been evaluated through a relatively straightforward lens: can a platform identify and stop malicious messages before they reach users? While that objective remains important, many organizations are discovering that the challenge has become considerably more complex.</span></p><p><span>Modern phishing attacks increasingly rely on trusted infrastructure, legitimate cloud services, compromised accounts, and highly personalized social-engineering techniques. They often bypass traditional indicators of compromise and exploit the fact that employees are accustomed to interacting with Microsoft 365, Adobe, DocuSign, Dropbox, Salesforce, and countless other legitimate business platforms. In many cases, security teams are no longer struggling to identify obviously malicious content. They are struggling to determine whether a seemingly legitimate interaction is trustworthy.</span></p><p><span>Varonis entered this market from a different direction than most email-security vendors. The company built its reputation around data security, identity monitoring, and insider-risk visibility rather than email protection. Its introduction of Interceptor reflects a belief that phishing should be viewed not simply as an email problem, but as the first stage of a broader attack chain that often culminates in credential theft, data exposure, privilege escalation, or business process compromise.</span></p><p><span>This perspective has shaped both the architecture and positioning of the product. Rather than focusing exclusively on classifying messages, Interceptor places significant emphasis on investigation, evidence generation, attack reconstruction, and understanding attacker intent. The platform is designed not only to determine whether a message is malicious, but also to explain why that conclusion was reached and what actions defenders should take next.</span></p><p><span>That emphasis on evidence and investigation is particularly notable as AI continues to reshape both offensive and defensive security. As detection systems become increasingly automated, organizations are placing greater importance on understanding how decisions are made, validating security outcomes, and generating defensible evidence that can support response activities. In this environment, explainability becomes more than a product feature. It becomes part of the security workflow itself.</span></p><p><span>Today, Varonis occupies a distinctive position within the email-security market because it approaches phishing from the perspective of attack progression rather than message classification. The company is effectively arguing that security teams need to understand how attacks work, not simply whether they exist.</span></p><h2><strong><span>Why This Vendor Matters</span></strong></h2><p><span>Varonis represents one of the clearest examples of a broader shift occurring within email security: the movement from detection toward investigation.</span></p><p><span>Many platforms excel at identifying suspicious messages. Fewer platforms are designed around reconstructing attacks, analyzing infrastructure, generating evidence, and connecting phishing activity to broader identity and data-security workflows.</span></p><p><span>This distinction is important because modern phishing attacks increasingly span multiple systems, users, and channels. Security teams are often asked to answer questions that extend beyond whether a message was malicious. They need to understand how an attack was delivered, what infrastructure was involved, whether users interacted with it, what credentials may have been exposed, and whether additional systems were affected.</span></p><p><span>In account takeover scenarios, this data-security adjacency becomes particularly relevant. Once an account is compromised, the investigation often shifts from the original phishing message to questions about downstream access, including what sensitive data the account could reach, what actions were taken during the compromise window, and whether the incident created a broader data-exposure risk.</span></p><p><span>Interceptor&#8217;s connection to Varonis&#8217; data-centric security model gives it a natural path into those questions and helps distinguish its approach from email-security products that remain focused primarily on message-level detection and remediation.</span></p><h2><strong><span>Product &amp; Architecture</span></strong></h2><p><span>Interceptor combines foundational email-security functions with a broader investigative architecture intended to evaluate messages, URLs, infrastructure, and user interactions.</span></p><p><span>The platform analyzes inbound communications using multiple detection layers, including language models, visual analysis, infrastructure inspection, URL detonation, and behavioral indicators. Rather than relying on a single detection methodology, it attempts to build a more complete understanding of the attack and its associated infrastructure before reaching a verdict.</span></p><p><span>A notable component of the platform is the AI Phishing Sandbox. Unlike traditional sandboxing approaches that focus primarily on files or executable content, the AI Phishing Sandbox is designed to interact with phishing pages in a manner that resembles human behavior. The objective is to determine what a user would encounter if they followed the attack path, including redirects, credential collection forms, multi-step phishing workflows, and social-engineering mechanisms.</span></p><p><span>This capability is increasingly relevant because many modern phishing campaigns no longer depend on malware delivery. Instead, they rely on convincing users to authenticate, approve MFA requests, enter credentials, or disclose sensitive information. Understanding the user experience, therefore, becomes an important part of understanding the threat itself.</span></p><p><span>The platform also emphasizes infrastructure analysis. Redirect chains, domain registration details, certificate information, hosting environments, and related technical artifacts are incorporated into the investigative process. This allows analysts to move beyond simple classifications and develop a clearer understanding of how a campaign operates.</span></p><p><span>Another notable architectural decision is the company&#8217;s investment in browser-level visibility. As phishing increasingly shifts from email messages to browser interactions, the ability to observe and evaluate destinations becomes more valuable. Many attacks now involve multiple redirects, trusted cloud services, and staged credential-harvesting workflows that cannot be fully understood through message inspection alone.</span></p><p><span>A practical example helps illustrate why this visibility matters. A QR-code phishing attack may originate through email, direct a user toward a trusted cloud service, route them through multiple redirects, and ultimately present a credential-harvesting page designed to mimic a familiar business application. At each stage, the infrastructure involved may appear legitimate when evaluated in isolation. The challenge is understanding how those stages connect and whether the overall workflow serves a legitimate business purpose.</span></p><p><span>This is one reason browser-level visibility has become increasingly important. Modern phishing campaigns frequently distribute indicators across multiple systems and interactions rather than concentrating them within a single email or URL. Observing the complete user journey can therefore provide context that would be difficult to obtain through message inspection alone.</span></p><p><span>It also reflects a broader reality: users do not distinguish between corporate and personal communication channels when browsing. A credential-theft campaign launched through a personal Gmail account, SMS message, or social-media platform can ultimately create the same business risk as a phishing email delivered directly to a corporate inbox.</span><s><span> </span></s><span>Visibility at the browser layer can help close security gaps that traditional email-centric controls were never designed to address.</span></p><p><span>The broader platform combines several analytical approaches. Visual models inspect branding, screenshots, logos, embedded text, and QR codes. Language models evaluate requests, urgency, intent, and social-engineering techniques. Infrastructure analysis examines redirect chains, hosting environments, certificates, and domain characteristics, while behavioral signals contribute additional context around user interactions and attack progression.</span></p><p><span>This multimodal architecture reflects a broader reality of modern phishing campaigns. Attackers increasingly combine visual impersonation, trusted infrastructure, social engineering, and identity compromise within the same workflow. Evaluating those attacks often requires multiple analytical perspectives rather than relying on a single detection methodology.</span></p><p><span>The resulting architecture reflects a broader belief that phishing should be evaluated as a sequence of events rather than a single artifact. Messages, URLs, browser activity, infrastructure, and user interactions all contribute pieces of the overall picture.</span></p><h2><strong><span>Market Context</span></strong></h2><p><span>One of the most significant trends shaping the email-security market is the growing use of trusted infrastructure by attackers.</span></p><p><span>Historically, phishing campaigns often relied on newly registered domains, suspicious hosting providers, or clearly malicious infrastructure. While these tactics still exist, modern campaigns increasingly leverage services such as Microsoft 365, Adobe, Dropbox, DocuSign, Salesforce, Figma, Vercel, and Replit. The challenge is that these platforms are not inherently malicious. They are often core components of normal business operations.</span></p><p><span>The challenge for defenders is that these platforms are not inherently malicious. In many cases, they are essential components of normal business operations. Blocking them outright is rarely practical. As a result, phishing increasingly becomes a question of intent rather than infrastructure.</span></p><p><span>A credential-harvesting page hosted on a trusted service may appear legitimate from a reputation perspective. A redirect chain may traverse multiple trusted domains before arriving at a malicious destination. A phishing email may contain links that pass traditional reputation checks because the infrastructure itself is legitimate. This reality creates pressure on detection systems to evaluate more than domains and URLs.</span></p><p><span>Interceptor&#8217;s architecture is particularly aligned with this challenge. Rather than treating trusted infrastructure as inherently benign, the platform attempts to understand how that infrastructure is being used. Redirect behavior, destination analysis, page content, credential collection mechanisms, and browser interactions all become relevant signals.</span></p><p><span>The company&#8217;s briefing also highlighted the growing prevalence of QR-code phishing, image-based phishing, and attacks designed specifically to bypass traditional scanning technologies. These campaigns frequently rely on visual elements, embedded content, and cloud-hosted workflows that are difficult to evaluate through conventional content inspection alone.</span></p><p><span>This helps explain Varonis&#8217; investment in multimodal analysis. Modern phishing campaigns increasingly combine visual deception, trusted infrastructure, social engineering, and identity compromise within the same workflow. Evaluating any single component in isolation may not provide sufficient context.</span></p><p><span>The broader implication is that phishing detection increasingly requires understanding the entire attack path rather than merely inspecting the initial message.</span></p><h2><strong><span>Product and Technical Notes</span></strong></h2><p><span>Several aspects of Interceptor&#8217;s architecture reflect Varonis&#8217; broader security background.</span></p><p><span>The platform&#8217;s AI Phishing Sandbox is designed to interact with phishing destinations in a manner that more closely resembles human behavior than traditional URL inspection technologies. Rather than simply rendering a page or evaluating static content, the sandbox follows redirect chains, interacts with phishing workflows, analyzes credential-harvesting stages, and documents the techniques used by attackers. This approach is particularly relevant as phishing campaigns increasingly rely on trusted cloud services, staged redirects, and multi-step authentication workflows.</span></p><p><span>Evidence generation is another notable differentiator. Interceptor produces screenshots, redirect-chain analysis, certificate information, hosting details, domain-registration data, and supporting artifacts intended to help analysts understand how a verdict was reached. As AI-assisted detection becomes more common across the industry, the ability to independently validate security decisions may become increasingly important.</span></p><p><span>The platform also incorporates multimodal analysis techniques that evaluate visual content, language patterns, infrastructure signals, and behavioral indicators together. This reflects the reality that modern phishing campaigns often distribute indicators across multiple layers in order to evade traditional controls. QR-code phishing, image-based phishing, brand impersonation, and cloud-hosted phishing workflows frequently require multiple forms of analysis to accurately assess risk.</span></p><p><span>Interceptor&#8217;s browser-oriented capabilities further distinguish it from many email-security products. The platform places significant emphasis on understanding what users encounter after clicking a link rather than focusing exclusively on the message itself. This allows analysts to evaluate the complete attack path, including redirects, destination content, credential collection mechanisms, and other indicators that may not be visible through message inspection alone.</span></p><p><span>A useful way to understand Interceptor is as an attack-reconstruction platform as much as a detection platform. Traditional email-security products often answer a relatively narrow question: is this message malicious? Interceptor attempts to answer a broader set of questions. What did the user actually encounter? How many redirects occurred? What infrastructure was involved? What credential-harvesting mechanisms were present? What evidence supports the final verdict?</span></p><p><span>This distinction becomes increasingly important as phishing attacks move away from malware delivery and toward browser-based workflows. Understanding the sequence of events surrounding an attack can provide valuable context for analysts, incident responders, and security leaders attempting to assess risk and determine appropriate remediation actions. Screenshots, redirect-chain mapping, infrastructure analysis, and browser observations are ultimately most valuable when they help security teams reconstruct the attack narrative and make more informed response decisions.</span></p><p><span>The company&#8217;s background in data security also creates opportunities for tighter integration between phishing investigations and broader security workflows. While Interceptor remains an email-security product, organizations already using Varonis for DSPM, DLP, insider-risk monitoring, or identity investigations may find value in the ability to connect phishing activity with downstream security telemetry.</span></p><p><span>Another notable aspect of the platform is its emphasis on remediation and response. The market has historically focused heavily on detection efficacy, but security teams increasingly evaluate how quickly threats can be investigated, validated, and remediated. Varonis&#8217; approach reflects the view that evidence generation, investigation workflows, and remediation support are becoming more important procurement criteria as phishing campaigns grow more sophisticated and operational teams face increasing alert volume.</span></p><h2><strong><span>Operational Considerations for Buyers</span></strong></h2><p><span>Organizations evaluating Interceptor should understand that the platform&#8217;s primary value proposition extends beyond detection efficacy alone.</span></p><p><span>Its strongest differentiation emerges in environments where investigation quality, analyst validation, evidence generation, and response workflows are important evaluation criteria. Security teams that regularly investigate sophisticated phishing attacks may find particular value in the platform&#8217;s ability to generate screenshots, infrastructure analysis, redirect-chain visibility, and supporting evidence.</span></p><p><span>The browser-oriented elements of the architecture are also worth evaluating carefully. Many phishing attacks now unfold across multiple redirects and cloud-hosted environments that are difficult to assess through message inspection alone. Organizations concerned about trusted-cloud phishing, QR-code phishing, and browser-based credential theft may view this visibility as a meaningful advantage.</span></p><p><span>Buyers should also evaluate how Interceptor integrates into existing security operations. Detection quality remains important, but so do remediation workflows, reporting, analyst experience, and integration with broader security tooling. Organizations that already leverage Varonis for data security, insider-risk monitoring, or identity investigations may find additional operational value through shared workflows and investigative context.</span></p><p><span>Organizations should also evaluate where Interceptor fits within their broader email-security architecture. In many environments, the platform will function as an additional investigative layer rather than a direct replacement for existing controls. Organizations already using Microsoft Defender, secure email gateways, or ICES platforms may find value in the additional visibility provided through attack reconstruction, browser analysis, and evidence generation.</span></p><p><span>Questions around OAuth-grant response, identity-security integrations, SIEM and SOAR connectivity, and support for incident-response workflows may ultimately prove just as important as detection performance. As phishing increasingly intersects with identity compromise and SaaS abuse, operational integration becomes a larger part of the purchasing decision.</span></p><p><span>As explainability becomes a larger procurement consideration across cybersecurity, the ability to validate security decisions may become increasingly important. Interceptor&#8217;s emphasis on evidence generation aligns closely with this trend.</span></p><h2><strong><span>Competition and Positioning</span></strong></h2><p><span>Interceptor occupies an unusual position within the email-security market because it approaches phishing through the lens of investigation rather than communication analysis or governance.</span></p><p><span>Against traditional secure email gateways, the platform differentiates through attack reconstruction, infrastructure analysis, browser-level visibility, and evidence generation.</span></p><p><span>Against cloud-native ICES vendors, it emphasizes understanding the mechanics of attacks rather than focusing primarily on communication context and behavioral relationships.</span></p><p><span>Against newer AI-focused platforms, it competes through investigative depth and the ability to provide supporting evidence for security decisions.</span></p><p><span>This positioning does not necessarily place Interceptor in direct competition with every email-security vendor. In many procurement scenarios, buyers may evaluate multiple architectural approaches simultaneously.</span></p><p><span>Some organizations prioritize behavioral analysis and relationship intelligence. Others prioritize governance, compliance, archive, and continuity. Others increasingly prioritize investigation, explainability, and operational response.</span></p><p><span>Interceptor&#8217;s strongest fit is likely to be among organizations that view phishing as part of a broader security workflow rather than an isolated email problem.</span></p><p><span>The platform may be particularly attractive to organizations that have already invested heavily in incident response, security operations, identity security, or data protection programs and are looking for greater investigative depth within their phishing defenses. In these environments, attack reconstruction and evidence generation may provide meaningful operational value beyond traditional message classification.</span></p><p><span>Conversely, organizations whose primary requirements center on archive, continuity, encryption, compliance, or governance may prioritize different evaluation criteria. Interceptor is not attempting to compete primarily on those dimensions. Its differentiation is rooted in understanding how attacks operate, documenting the evidence behind security decisions, and supporting investigation and response workflows.</span></p><p><span>This positioning places the platform somewhat adjacent to many cloud-native email-security products rather than directly replacing them. For some organizations, the most relevant question may not be whether investigation-centric architectures replace relationship-centric or governance-centric approaches, but how those approaches complement one another within a broader security program. The platform may also appeal to security teams seeking stronger connections between phishing investigations, identity security, and data security operations.</span></p><p><span>Organizations that prioritize business email compromise detection, communication analysis, and relationship intelligence as their primary evaluation criteria may find stronger alignment with other architectural approaches. Interceptor is most differentiated when investigation quality, evidence generation, attack reconstruction, and operational response are central procurement requirements.</span></p><h2><strong><span>Challenges and Open Questions</span></strong></h2><p><span>Varonis&#8217; strategy raises several important questions about the future direction of email security.</span></p><p><span>The first concerns market education. Many organizations continue evaluating email-security platforms primarily through detection efficacy metrics. Investigation quality, evidence generation, and attack reconstruction may be valuable, but buyers must first view those capabilities as meaningful differentiators.</span></p><p><span>The second involves platform convergence. Many of the trends discussed throughout this report point toward increasing overlap between email security, identity protection, collaboration security, browser security, and data security. The market has not yet settled on how these capabilities should be packaged or delivered. Vendors are pursuing different visions of that future, and it remains unclear which models will ultimately prove most compelling to buyers.</span></p><p><span>A final question involves balancing automation with investigation. Rich investigative workflows can provide valuable context, but organizations must determine how much information analysts actually need and how that information should be incorporated into response processes. The balance between automated decision-making and human validation remains an active debate across the industry.</span></p><p><span>These questions are not unique to Varonis. They reflect broader uncertainties affecting the market as a whole.</span></p><h2><strong><span>Implications for Email Security Moving Forward</span></strong></h2><p><span>If Varonis&#8217; vision proves correct, the future of email security may place greater emphasis on investigation, validation, and response rather than detection alone.</span></p><p><span>Historically, the category focused on preventing malicious messages from reaching users. Modern environments increasingly require organizations to understand what happened after delivery, how users interacted with content, what infrastructure was involved, whether credentials were exposed, and what downstream actions are necessary.</span></p><p><span>The rise of trusted-cloud phishing reinforces this trend. When attackers operate through legitimate services and cloud platforms, reputation-based controls become less effective. Security teams increasingly need visibility into attacker behavior, infrastructure usage, redirect chains, and user interactions to make informed decisions.</span></p><p><span>At the same time, buyers are becoming more interested in explainability. As AI-assisted detection becomes commonplace, the ability to provide evidence, support analyst validation, and defend security decisions may become a meaningful competitive differentiator. Vendors that can combine automation with transparency are likely to be well-positioned as the market evolves.</span></p><p><span>Varonis&#8217; approach reflects one possible vision of that future: a security architecture in which phishing detection, investigation, evidence generation, and remediation operate as connected components of a broader workflow.</span></p><h2><strong><span>Conclusion</span></strong></h2><p><span>Varonis entered the email-security market from a different starting point than many of its competitors.</span></p><p><span>Rather than approaching phishing primarily as a messaging problem, the company views it as the beginning of a broader attack sequence that may ultimately involve identity compromise, data exposure, or business-process abuse. This perspective has shaped Interceptor&#8217;s emphasis on investigation, evidence generation, infrastructure analysis, and attack reconstruction.</span></p><p><span>The platform&#8217;s investments in AI Phishing Sandbox, multimodal detection, browser-level visibility, and explainable security workflows align closely with several of the most significant trends currently shaping the market. Trusted-cloud phishing, QR-code attacks, image-based phishing, and increasingly sophisticated social-engineering campaigns all place greater pressure on security teams to understand attacks rather than simply classify them.</span></p><p><span>Whether investigation-centric architectures become a dominant model remains an open question. Buyers will continue evaluating platforms through different lenses, including behavioral analysis, governance, automation, and operational efficiency. Interceptor represents a distinct perspective within that landscape: that understanding how an attack works may ultimately become just as important as detecting that it exists.</span></p><h1><strong><span>Ocean Security</span></strong></h1><h2><strong><span>Overview</span></strong></h2><p><span>As email attacks become more sophisticated, many security teams are discovering that detection alone is no longer the primary challenge. Most organizations can identify suspicious activity. The harder problem is understanding what happened, determining whether it matters, and responding quickly enough to reduce risk.</span></p><p><span>Ocean Security was founded around this operational reality. Rather than focusing exclusively on identifying known threats, the company emphasizes investigation, intent analysis, and automation. Its architecture reflects the belief that defenders increasingly need systems capable of evaluating unfamiliar attacks and reducing the manual effort required to investigate them.</span></p><p><span>This perspective aligns with a broader shift occurring across cybersecurity as AI lowers the cost of creating novel phishing campaigns and social-engineering attacks.</span></p><h2><strong><span>Why This Vendor Matters</span></strong></h2><p><span>Ocean represents one of the newer architectural directions emerging within email security: the use of AI-driven agents to investigate threats, evaluate intent, and automate portions of the response process.</span></p><p><span>The company reflects a growing belief that operational scale may become just as important as detection efficacy in the years ahead.</span></p><h2><strong><span>Product &amp; Architecture</span></strong></h2><p><span>Ocean&#8217;s architecture is built around pre-delivery investigation and agent-driven analysis.</span></p><p><span>The platform uses over a dozen purpose-built AI agents to investigate messages, sender identity, links, attachments, infrastructure, financial context, supporting context and more before delivery. Rather than relying exclusively on reputation systems or historical indicators, Ocean attempts to determine what an email is trying to accomplish and whether the requested action introduces meaningful risk.</span></p><p><span>This approach differs from traditional classification-focused architectures. Instead of simply categorizing a message as benign or malicious, the platform attempts to understand intent and gather supporting evidence before reaching a verdict.</span></p><p><span>The company also places significant emphasis on automated remediation and analyst-assistance workflows designed to reduce investigation time and operational burden. <br><br>Ocean deploys via API only, requiring no MX record changes, and integrates in less than 4 minutes. The platform sits on top of existing Microsoft 365 or Google Workspace environments.</span></p><h2><strong><span>Market Context</span></strong></h2><p><span>Ocean reflects two broader trends shaping the market: the rise of agentic security operations and the growing demand for systems that can evaluate communications in the context of business processes rather than message content alone.</span></p><p><span>As attackers increasingly use AI to generate new phishing content and adapt campaigns quickly, defenders are looking for technologies capable of evaluating unfamiliar scenarios rather than relying solely on historical patterns. This has created growing interest in systems that can investigate, reason, and automate portions of the response process.</span></p><p><strong><span>Product and Technical Notes</span></strong><span><br><br>Ocean&#8217;s platform stands out across three core capabilities: Agentic Protection, Agentic Automation, and Agentic Investigation.</span></p><p><span>The company&#8217;s focus on intent analysis differentiates it from many traditional detection approaches. Ocean&#8217;s autonomous investigation engine, Ray, serves as the platform&#8217;s central intelligence engine</span><strong><span> </span></strong><span>and is designed for the kinds of deep email-security investigations that often fall to Tier 3 analysts. For each reported or suspicious email, RAY runs a swarm of specialized sub-agents across areas such as invoice analysis, infrastructure assessment, sandboxing, and content review, compressing investigations that may otherwise take several hours into under two minutes.</span></p><p><span>Ocean&#8217;s value proposition is not only speed, but explainability: each verdict is presented as a step-by-step evidence chain showing the signals evaluated rather than as a black-box score. Ray also handles automated triage of reported phishing and quarantine release requests, allowing employees to receive rapid responses with a plain-language explanation of what was found, without requiring direct SOC involvement</span></p><p><span>Ocean emphasizes workflow automation, helping security teams move from detection to response with less manual effort. This reflects the company&#8217;s broader focus on analyst productivity and operational efficiency.</span></p><p><span>Ocean&#8217;s approach is also notable for its emphasis on evidence rather than scoring. Rather than relying primarily on anomaly detection, reputation systems, or risk scores, the platform attempts to identify concrete indicators that support or refute a malicious hypothesis. This philosophy aligns closely with the company&#8217;s broader focus on explainability and investigation.</span></p><h2><strong><span>Operational Considerations for Buyers</span></strong></h2><p><span>Ocean may be particularly attractive to organizations seeking to remediate threats with transparent and explainable AI decision making, reduce investigation workload without significantly expanding headcount, and to those concerned with missing novel AI-powered attacks that no longer trigger traditional detection signals.</span></p><p><span>Buyers should evaluate not only detection capabilities, but also how the platform integrates into existing SOC workflows, remediation processes, and governance requirements. As with many emerging platforms, operational trust and workflow fit may be just as important as technical efficacy.</span></p><h2><strong><span>Competition and Positioning</span></strong></h2><p><span>Ocean competes through automation and investigation depth rather than governance, behavioral analysis, or relationship intelligence.</span></p><p><span>Its strongest differentiation lies in combining agent-driven analysis with operational workflows designed to reduce analyst effort and accelerate response.</span></p><h2><strong><span>Challenges and Open Questions</span></strong></h2><p><span>The company&#8217;s central challenge is not proving that investigation can be automated. The more important question is how much investigation organizations will ultimately feel comfortable delegating to autonomous systems.</span></p><p><span>Like many emerging vendors, Ocean must also demonstrate scalability, consistency, and operational trust across larger enterprise environments.</span></p><p><span>Another question concerns channel coverage. Ocean&#8217;s long-term vision extends beyond email into platforms such as Slack, Teams, and other communication channels, but the platform&#8217;s current focus remains primarily on email security. As social-engineering attacks increasingly move across multiple communication surfaces, the company&#8217;s ability to extend its investigation and automation model beyond the inbox will be an important area to watch.</span></p><h2><strong><span>Implications for Email Security Moving Forward</span></strong></h2><p><span>If Ocean&#8217;s perspective proves correct, the future of email security may involve a greater shift from classification toward investigation and automation.</span></p><p><span>As attack volume continues increasing, organizations will likely place greater value on platforms capable of reducing analyst workload while maintaining confidence in security outcomes.</span></p><h2><strong><span>Conclusion</span></strong></h2><p><span>Ocean Security offers a forward-looking perspective on the email-security market.</span></p><p><span>Its emphasis on AI-driven investigation, intent analysis, and workflow automation reflects a belief that defenders increasingly need help understanding and responding to threats, not simply identifying them. Whether agentic investigation becomes a mainstream security model remains an open question, but Ocean highlights an important direction of travel for the industry.</span></p><h1><strong><span>Research Disclosure</span></strong></h1><p><span>This report reflects SACR&#8217;s independent research and analysis of the email security market as of June 2026.</span></p><p><span>Varonis and Abnormal AI participated in sponsored research programs associated with this report. Sponsorship provided access to briefings, product demonstrations, and supporting materials. It did not influence SACR&#8217;s conclusions, analysis, or editorial direction.</span></p><p><span>The vendor profiles in this report are not product reviews, rankings, or procurement recommendations. They are intended to illustrate how different vendors are responding to many of the same market forces discussed throughout the report. All opinions expressed are those of SACR.</span></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Software Analyst Cyber Research! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/p/from-perimeter-to-proof-the-new-architecture?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/p/from-perimeter-to-proof-the-new-architecture?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/p/from-perimeter-to-proof-the-new-architecture/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/p/from-perimeter-to-proof-the-new-architecture/comments"><span>Leave a comment</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Why CISOs Must Re-Think Identity Posture Management for AI Agents ]]></title><description><![CDATA[How identity security is shifting from static reviews and dashboards to governed, verifiable remediation for human, non-human, and AI-agent identities]]></description><link>https://softwareanalyst.substack.com/p/why-cisos-must-re-think-identity</link><guid isPermaLink="false">https://softwareanalyst.substack.com/p/why-cisos-must-re-think-identity</guid><dc:creator><![CDATA[SACR]]></dc:creator><pubDate>Fri, 12 Jun 2026 14:30:26 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!ny02!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88bf9977-9484-4760-9122-d3b3984788a1_2354x1338.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h3>Executive Summary</h3><p>Identity is the new perimeter. Every security leader has heard that phrase. Most have built programs around it. And yet identity-based attacks remain the most consistent, most documented, and most preventable category of enterprise breach. Not because the tools are inadequate. Because the governance model has not kept pace with the environment it is supposed to govern.</p><p>This report makes a direct argument: the identity security programs that most enterprises are running today are structurally mismatched with the identity environments they are trying to protect. The mismatch is not a product gap. It is an architectural one. And it is getting wider every quarter as AI agents enter enterprise workflows carrying identities, accumulating entitlements, and operating at speeds that no human-driven review cycle was ever designed to address.</p><p>SACR has been researching this market closely. What we found is not that organizations lack awareness of identity risk. It is that they have accepted a governance model built around detection and reporting at a moment when the threat environment demands detection, remediation, and verification as a single continuous loop. The organizations that close that loop will prevent breaches. The ones that do not will continue documenting them.</p><p>This report documents the evolution of ISPM across three distinct phases from periodic review to continuous visibility. Our goal is to make the case that the market has entered a third phase, which we call <em><strong>Agentic ISPM</strong></em>. The defining characteristic of this phase is not that AI is embedded in the interface. It is that posture findings can be translated into proposed, approved, executed, verified, and documented control changes without waiting for a human to open a ticket.</p><p></p><h3>Introducing Agentic ISPM </h3><p>We believe that Agentic ISPM is the next architectural evolution of identity security posture management. Where Continuous ISPM made risk visible in real time, Agentic ISPM makes risk <em>actionable</em> in real time. The defining capability is closed-loop remediation where the system does not merely surface a posture finding and wait, it can propose a corrective action, route it for human approval where policy requires, execute it, verify the outcome, and produce auditable evidence of every step, all within a governed, policy-bounded framework. Agentic ISPM represents a fundamental architectural shift from static, reactive identity governance to autonomous, continuous, and closed-loop control required to secure operations at machine speed.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ny02!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88bf9977-9484-4760-9122-d3b3984788a1_2354x1338.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ny02!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88bf9977-9484-4760-9122-d3b3984788a1_2354x1338.png 424w, https://substackcdn.com/image/fetch/$s_!ny02!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88bf9977-9484-4760-9122-d3b3984788a1_2354x1338.png 848w, https://substackcdn.com/image/fetch/$s_!ny02!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88bf9977-9484-4760-9122-d3b3984788a1_2354x1338.png 1272w, https://substackcdn.com/image/fetch/$s_!ny02!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88bf9977-9484-4760-9122-d3b3984788a1_2354x1338.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ny02!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88bf9977-9484-4760-9122-d3b3984788a1_2354x1338.png" width="1456" height="828" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/88bf9977-9484-4760-9122-d3b3984788a1_2354x1338.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:828,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:553468,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://softwareanalyst.substack.com/i/201332633?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88bf9977-9484-4760-9122-d3b3984788a1_2354x1338.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ny02!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88bf9977-9484-4760-9122-d3b3984788a1_2354x1338.png 424w, https://substackcdn.com/image/fetch/$s_!ny02!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88bf9977-9484-4760-9122-d3b3984788a1_2354x1338.png 848w, https://substackcdn.com/image/fetch/$s_!ny02!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88bf9977-9484-4760-9122-d3b3984788a1_2354x1338.png 1272w, https://substackcdn.com/image/fetch/$s_!ny02!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88bf9977-9484-4760-9122-d3b3984788a1_2354x1338.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>The distinction from earlier ISPM is not artificial. Continuous ISPM reduced the latency between a misconfiguration appearing and a human being notified. Agentic ISPM reduces the latency between notification and resolution, addressing a gap that most mature ISPM programs have been unable to close. It does this by aligning the non-deterministic behavioural signals generated by human users, machine identities, and AI agents with deterministic policy enforcement: the system reasons about context, but the controls it applies are bounded, verifiable, and reversible.</p><p>The result is a shift from posture management as a monitoring discipline to posture management as a control discipline. The question changes from <em>what risks exist in our environment</em> to <em>what risks exist, what has been done about them, and how do we know it worked. Moving forward, we recommend that IAM leaders and </em>buyer evaluation focus on verified remediation, which should focus on delivery of: write-back, change verification, instant rollback in the event of problems and clear lineage evidence for auditability. </p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Software Analyst Cyber Research! Subscribe for free to receive new cybersecurity reports and analysis.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><p></p><h3>What This Report Argues</h3><p>Identity Security Posture Management emerged as the answer to a specific and urgent question: which identities, privileges, authentication policies, and access paths in our environment are unsafe right now? Not last quarter. Not at the last certification campaign. Right now.</p><p>For most enterprise programs, ISPM filled a real gap. It moved identity risk management from scheduled reviews to continuous visibility, from generic compliance findings to exploitability-mapped posture signals, from quarterly blind spots to ongoing assessment of the misconfigurations that attackers actually rely on. That was meaningful progress and it remains the foundation every mature identity program needs. The foundation is not the problem. The problem is that the environment has changed in a way that the foundation alone cannot address. AI agents are arriving in enterprise workflows as active participants: reasoning, calling tools, accessing sensitive systems, and chaining actions across services at machine speed. These agents require identities. They accumulate entitlements. They operate entirely outside the behavioral baselines that traditional identity programs were built to monitor. ISPM, as originally conceived, was not designed to govern them.</p><p>The market has reached a third phase. SACR calls it Agentic ISPM, and this report makes the case for why it represents the most significant architectural shift in identity security governance since the move from periodic access reviews to continuous visibility.</p><h2><strong>Identity Security Agentic Posture Remediation</strong></h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vS5W!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e63924e-ff2b-43d6-9267-a751694559a5_2064x1154.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vS5W!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e63924e-ff2b-43d6-9267-a751694559a5_2064x1154.png 424w, https://substackcdn.com/image/fetch/$s_!vS5W!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e63924e-ff2b-43d6-9267-a751694559a5_2064x1154.png 848w, https://substackcdn.com/image/fetch/$s_!vS5W!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e63924e-ff2b-43d6-9267-a751694559a5_2064x1154.png 1272w, https://substackcdn.com/image/fetch/$s_!vS5W!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e63924e-ff2b-43d6-9267-a751694559a5_2064x1154.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vS5W!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e63924e-ff2b-43d6-9267-a751694559a5_2064x1154.png" width="1456" height="814" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2e63924e-ff2b-43d6-9267-a751694559a5_2064x1154.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:814,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2397249,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://softwareanalyst.substack.com/i/201332633?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e63924e-ff2b-43d6-9267-a751694559a5_2064x1154.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vS5W!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e63924e-ff2b-43d6-9267-a751694559a5_2064x1154.png 424w, https://substackcdn.com/image/fetch/$s_!vS5W!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e63924e-ff2b-43d6-9267-a751694559a5_2064x1154.png 848w, https://substackcdn.com/image/fetch/$s_!vS5W!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e63924e-ff2b-43d6-9267-a751694559a5_2064x1154.png 1272w, https://substackcdn.com/image/fetch/$s_!vS5W!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e63924e-ff2b-43d6-9267-a751694559a5_2064x1154.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><h3><strong>Market Map Rationale </strong></h3><p>This map organizes the identity security posture management vendor landscape according to remediation maturity. Specifically, the degree to which each platform can translate a posture finding into a governed, verified, and reversible control change without requiring a human to manually execute the fix.</p><p>Three tiers reflect three meaningful capability thresholds.</p><ol><li><p><strong>Agentic Remediation</strong> vendors have demonstrated closed-loop write-back: the platform makes changes directly to identity control planes, confirms outcomes, produces audit-grade evidence, and can restore prior states if a change creates operational risk. All five requirements- write-back, approval gating, verification, rollback, and evidence logging must be demonstrably met. When evidence was incomplete, vendors defaulted to the Guided tier.</p></li><li><p><strong>Guided Remediation</strong> vendors automate actions such as ticket creation, workflow triggers, and access review initiation, but cannot independently verify that a fix was applied or maintain rollback semantics across the full remediation cycle. This represents the current practical standard for most enterprise deployments.</p></li><li><p><strong>Manual Posture Remediation</strong> vendors deliver continuous posture analysis and prescriptive remediation guidance, routing all execution to human administrators.</p></li></ol><p>Tier placement measures remediation maturity only, not posture analysis depth, surface coverage, or overall product quality. The map answers one question: given a posture finding, how far can this platform take the response? That question matters because the bottleneck in mature ISPM programs is no longer detection. It is the gap between detection and verified remediation, and closing that gap is what the Agentic tier has been built to do.</p><p>Vendors are included if they provide continuous posture analysis across at least one major identity surface and offer a documented remediation workflow. Static dashboards and pure-play PAM or IGA solutions without ISPM use cases are excluded. Two known gaps require ongoing research: deep-tier NHI visibility across multi-cloud environments, and the long-term reliability of fully autonomous remediation agents at enterprise scale. Buyers should treat both as open questions in their own evaluations.</p><p></p><div><hr></div><h2>Evolution of Identity Security Posture</h2><p>Identity security posture management evolved because traditional identity programs were not designed to continuously answer the most operationally important question in enterprise security: which identities, privileges, authentication policies, and access paths are unsafe right now?</p><p>Historically, identity and access management relied on periodic reviews, manual entitlement cleanups, access certification campaigns, and ticket-driven remediation. That model was adequate when the enterprise identity estate was primarily human-centric and relatively slow-moving. Administrators could review workforce access, validate role assignments, clean up stale privileges, and enforce authentication policies on a scheduled basis without losing significant ground between cycles.</p><p>The problem is that modern identity environments no longer move on a quarterly review cycle. Cloud infrastructure, SaaS applications, service accounts, API keys, workload identities, and now AI agents continuously create new access paths and new posture drift. The gap between the last review and the current risk state is where most identity-based attacks find their footing.</p><h4>Phase One: Periodic IAM Reviews</h4><p>The traditional model centered on scheduled access reviews, manual certification campaigns, and ticket-based remediation. Its strength was standardization. It forced organizations to periodically ask who had access, whether that access was still justified, and whether any privileges needed to be removed or adjusted.</p><p>Its weakness was latency. A quarterly access review creates a blind spot that spans months. In that window, users change roles, contractors leave without complete offboarding, service accounts accumulate stale privileges, applications are added without integration into governance workflows, and authentication policies drift as exceptions accumulate. Attackers do not wait for certification campaigns. The model also becomes structurally weaker as non-human identities and AI agents grow to outnumber human users, because their access patterns are more dynamic, harder to interpret, and entirely unsuited to manual review cycles.</p><h4>Phase Two: Continuous ISPM</h4><p>Continuous ISPM improved the model by making posture assessment ongoing rather than periodic. It continuously evaluates identity systems, directories, authentication policies, privileges, group memberships, application permissions, and identity configurations to identify risk before it becomes an incident path.</p><p>The core advance was that identity posture findings could now be mapped to exploitability, blast radius, and operational risk rather than treated as generic compliance gaps. A weak MFA policy, a stale privileged account, an exposed service principal, or a legacy authentication pathway could be understood as part of a specific attack path rather than an abstract policy deviation. Continuous ISPM became the preventative layer in the identity stack: it gave security and identity teams the ability to understand where their environment was weak and which misconfigurations created the most material risk, in real time.</p><p>The limitation that emerged was equally important. Most Continuous ISPM workflows still depend on human-speed remediation. The system identifies the posture issue continuously, but the fix still requires a ticket, an access review, a workflow approval, or an administrator making a manual change. In environments where the identity estate changes at cloud and automation speeds, continuous visibility without timely remediation produces a better-informed backlog rather than a more secure environment.</p><h4>Phase Three: Agentic ISPM</h4><p>Agentic ISPM represents the current frontier: a shift from continuous posture visibility to governed, closed-loop posture control. The defining difference is not that AI has been added to the interface. It is that posture findings can be translated into proposed, approved, executed, verified, and documented control changes without waiting for a human to process each one through a manual queue.</p><p>In an Agentic ISPM model, the system does not merely report that an account is overprivileged, that a legacy authentication protocol is exposed, or that a service account has accumulated stale privileges. It can recommend or execute a bounded remediation action, route high-impact changes for human approval, verify that the fix was applied correctly, produce audit-grade evidence of the change, and maintain rollback semantics if the action creates operational risk. This is the shift from ISPM as a reporting tool to ISPM as a control system.</p><p>The benefit is speed and precision. Agentic ISPM reduces time-to-remediation for identity risks that would otherwise accumulate in ticket queues or review campaigns. It can right-size privileged access, disable risky authentication paths, clean up stale accounts, assign ownership to unmanaged identities, and enforce guardrails around AI agents and non-human identities at a pace that matches the speed at which those risks appear.</p><p>The risk is equally important to state plainly. Autonomous remediation introduces real concerns around reliability, overcorrection, and operational breakage. That is why Agentic ISPM must be governed rather than blindly autonomous. High-impact controls require human-in-the-loop approval, deterministic policy boundaries, blast-radius analysis, verification loops, evidence logs, and rollback mechanisms. Remediation that cannot be verified and reversed is not mature Agentic ISPM. It is risky automation with better branding.</p><p>The practical takeaway for IAM leaders is direct. Periodic IAM reviews reduce governance gaps. Continuous ISPM reduces posture drift. Agentic ISPM reduces time-to-remediation under machine-speed identity change. Each phase addressed a real limitation of the one before it. The question for any program today is not which phase matters most. It is whether the current program reflects the pace at which the identity environment is actually changing.</p><div><hr></div><h3><strong>How MITRE ATT&amp;CK Techniques Mapped to ISPM</strong></h3><p>The claim that misconfiguration drives identity breach more consistently than phishing or zero-day exploitation is not a theoretical position. It is what the adversary behavior data shows. The techniques in the MITRE ATT&amp;CK framework that are most frequently used against enterprise identity infrastructure do not require novel attack chains. They require finding the configuration gaps that most identity programs have not yet closed. The mapping below connects specific ATT&amp;CK techniques to the ISPM checks that address them, and to the documented frequency with which those techniques appear in real breach investigations. The occurrence rates are drawn from the 2025 Verizon DBIR, the NHIMG 2025 State of NHI Security report, DarkAnalytics 2025, Red Canary 2025, CrowdStrike GTR 2025, and SecurityToday 2026.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-J2T!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33aee0f5-3475-4f14-9360-ed17ef7d5d67_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-J2T!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33aee0f5-3475-4f14-9360-ed17ef7d5d67_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!-J2T!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33aee0f5-3475-4f14-9360-ed17ef7d5d67_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!-J2T!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33aee0f5-3475-4f14-9360-ed17ef7d5d67_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!-J2T!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33aee0f5-3475-4f14-9360-ed17ef7d5d67_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-J2T!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33aee0f5-3475-4f14-9360-ed17ef7d5d67_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/33aee0f5-3475-4f14-9360-ed17ef7d5d67_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:&quot;&quot;,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!-J2T!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33aee0f5-3475-4f14-9360-ed17ef7d5d67_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!-J2T!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33aee0f5-3475-4f14-9360-ed17ef7d5d67_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!-J2T!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33aee0f5-3475-4f14-9360-ed17ef7d5d67_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!-J2T!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33aee0f5-3475-4f14-9360-ed17ef7d5d67_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Three findings carry particular weight for IAM leaders reading this report.</p><ol><li><p><strong>Password spraying</strong>, mapped to T1110.003, appears in approximately 18% of identity initial-access incidents. The primary ISPM control is legacy authentication blocking and lockout policy enforcement. This is not a sophisticated defense. It is a configuration that most environments are capable of implementing and that continuous posture management surfaces as a finding when it drifts. The frequency of this technique in breach investigations reflects how often that configuration has not been maintained.</p></li><li><p><strong>Stale and orphaned accounts,</strong> mapped to T1078, affect all three identity populations simultaneously: human users, non-human identities, and AI agents. According to NHIMG 2025, 97% of non-human identities carry excessive privileges. That figure does not reflect a sophisticated attack campaign. It reflects governance neglect at scale, and it represents the single largest unaddressed exposure in most enterprise identity programs today.</p></li><li><p><strong>Supply chain and federated identity techniques</strong>, mapped to T1195 and T1550.001, appear in 92% of organizations that expose non-human identities to third parties without adequate governance controls. Golden SAML operates at less than 5% occurrence but carries catastrophic blast radius when it appears, as the SolarWinds investigation confirmed. Both techniques require ISPM coverage that spans on-premises directory configuration and cloud IdP synchronization simultaneously. Single-surface tools cannot identify the precondition.</p><p></p></li></ol><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5iIm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa089971e-5ca5-4362-8580-c32425c0c9ab_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5iIm!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa089971e-5ca5-4362-8580-c32425c0c9ab_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!5iIm!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa089971e-5ca5-4362-8580-c32425c0c9ab_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!5iIm!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa089971e-5ca5-4362-8580-c32425c0c9ab_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!5iIm!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa089971e-5ca5-4362-8580-c32425c0c9ab_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5iIm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa089971e-5ca5-4362-8580-c32425c0c9ab_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a089971e-5ca5-4362-8580-c32425c0c9ab_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:&quot;&quot;,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!5iIm!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa089971e-5ca5-4362-8580-c32425c0c9ab_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!5iIm!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa089971e-5ca5-4362-8580-c32425c0c9ab_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!5iIm!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa089971e-5ca5-4362-8580-c32425c0c9ab_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!5iIm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa089971e-5ca5-4362-8580-c32425c0c9ab_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The MITRE mapping establishes what ISPM needs to address. The benchmark data that follows addresses a different question: whether agentic remediation has reached the reliability threshold where it can be trusted to address those conditions autonomously, and under what constraints that trust is currently warranted.</p><p></p><h2><strong>ISPM Benchmarks: Sola Results by Overall Performance by Domain (%)</strong></h2><p>The central question about Agentic ISPM is not conceptual. Most IAM leaders accept that autonomous, governed remediation would be valuable if it worked reliably. The question they are actually asking is whether it works reliably enough, across the identity surfaces that matter to their environments, to be trusted with real control changes rather than draft tickets.</p><p>The Sola Visibility ISPM Benchmark, published in January 2026, provides the first systematic answer. It evaluated agentic AI performance against core ISPM tasks in real enterprise environments across AWS, Okta, and Google Workspace, measuring three dimensions: expert accuracy, the degree to which agentic responses matched what a human expert would produce; expert success, the rate at which agentic actions achieved the intended outcome; and LLM-as-judge, an independent model evaluation of response quality. The overall weighted results were 84% expert accuracy, 77% expert success, and 82% LLM-as-judge.</p><p>Those numbers mean different things depending on which surface and which task type a buyer is evaluating. Reading them as a single average obscures the most important signal in the data.</p><p><strong>Where agentic ISPM is ready to act.</strong> AWS posture tasks achieved 95% expert accuracy and 95% expert success. These results reflect the relative maturity of cloud IAM signal quality. AWS permission models are precise and well-structured, and the posture questions ISPM needs to answer about AWS identity configurations are largely deterministic. At 95% accuracy and success, agentic remediation of AWS posture findings is mature enough to support autonomous execution for lower-impact changes, with human approval reserved for high-impact IAM policy modifications.</p><p><strong>Where human oversight remains essential.</strong> Okta posture tasks achieved 65% expert accuracy and 50% expert success. This is the most operationally significant result in the benchmark for most enterprise buyers, because Okta is one of the two or three most common IdP environments in large-scale enterprise deployments. A 50% expert success rate means that in half of evaluated Okta posture tasks, the agentic system did not achieve the intended outcome. That result does not support autonomous remediation of Okta configurations without human oversight. It reflects a genuine difference in complexity: Okta posture analysis requires reasoning about conditional access policy logic, group membership inheritance, application assignment scope, and authentication policy exceptions in combination. These are context-dependent questions that require organizational knowledge beyond what technical signals alone supply.</p><p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hCZE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0944079-0cf1-410f-bae8-188171d505d8_1080x1350.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hCZE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0944079-0cf1-410f-bae8-188171d505d8_1080x1350.png 424w, https://substackcdn.com/image/fetch/$s_!hCZE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0944079-0cf1-410f-bae8-188171d505d8_1080x1350.png 848w, https://substackcdn.com/image/fetch/$s_!hCZE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0944079-0cf1-410f-bae8-188171d505d8_1080x1350.png 1272w, https://substackcdn.com/image/fetch/$s_!hCZE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0944079-0cf1-410f-bae8-188171d505d8_1080x1350.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hCZE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0944079-0cf1-410f-bae8-188171d505d8_1080x1350.png" width="553" height="691.25" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c0944079-0cf1-410f-bae8-188171d505d8_1080x1350.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1350,&quot;width&quot;:1080,&quot;resizeWidth&quot;:553,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!hCZE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0944079-0cf1-410f-bae8-188171d505d8_1080x1350.png 424w, https://substackcdn.com/image/fetch/$s_!hCZE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0944079-0cf1-410f-bae8-188171d505d8_1080x1350.png 848w, https://substackcdn.com/image/fetch/$s_!hCZE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0944079-0cf1-410f-bae8-188171d505d8_1080x1350.png 1272w, https://substackcdn.com/image/fetch/$s_!hCZE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0944079-0cf1-410f-bae8-188171d505d8_1080x1350.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p><strong>What the benchmark means for buyers.</strong> </p><p>Three conclusions follow directly from the data. For AWS and comparable cloud IAM environments, agentic remediation is mature enough to support autonomous execution of lower-impact changes with governed approval for high-impact modifications. For Okta and other IdP environments requiring contextual organizational reasoning, agentic assistance with human-in-the-loop review is the appropriate starting point today. For inventory and non-human identity governance tasks, agentic discovery and prioritization are ready; agentic remediation of those findings benefits from human review where ownership attribution is ambiguous. The approval threshold across all three domains will shift as vendor fine-tuning on organization-specific identity data matures. Buyers who track the benchmark as it evolves will have the clearest signal of when that shift is warranted.</p><p></p><div><hr></div><h2>Why the Foundation Still Matters</h2><p>As agentic capabilities have captured market attention, a quieter but more damaging narrative has taken hold: that foundational ISPM is a solved problem, a baseline capability that mature organizations have already addressed and moved beyond. The breach data does not support that narrative, and IAM leaders who accept it are accepting a material gap in their programs.</p><p>Identity posture drift remains the leading precondition for identity-based attacks. Not phishing. Not zero-day exploitation. Misconfiguration is the condition that attackers most consistently rely on to establish initial access, move laterally, and maintain persistence. The attack chain is well understood: legacy authentication enabled creates a credential exposure opportunity; an overprivileged account provides the blast radius needed for lateral movement; a stale privileged account provides persistence without active monitoring. Each element of that chain is a posture failure. Each is, in principle, preventable. Most organizations are still not preventing them continuously or at the speed their environments demand.</p><p>Agentic ISPM does not replace that foundation. It accelerates and governs the response to it. Two converging crises explain why that acceleration is now urgent.</p><p><strong>The first crisis is the pace of drift itself.</strong> Configuration drift is not a single event. It is the compounding effect of small, individually unremarkable changes that accumulate over time into exploitable conditions. Cloud infrastructure, SaaS adoption, and DevOps automation have produced identity environments that change continuously. Access paths are created and modified by deployment pipelines, provisioning tools, and developers working faster than any quarterly review cycle can track. By the time a certification campaign runs, the access state being reviewed may bear little resemblance to the state that existed two weeks earlier. Continuous ISPM was built to close that gap. Agentic ISPM is built to close what remains: the distance between detecting a drift condition and resolving it before an attacker discovers it first.</p><p><strong>The second crisis is the failure of human-scale governance at machine speed.</strong> Traditional identity governance was designed for a human-centric access environment. Its review cycles and manual remediation workflows are calibrated to human-speed change and human-legible access patterns. That design assumption no longer holds. Non-human identities, including service accounts, API keys, workload credentials, and autonomous AI agents, outnumber human users in most enterprise environments, in some cases by a factor of fifty to one. They accumulate privileges through automation rather than deliberate assignment. They are frequently created without ownership attribution, which means that when their risk state changes, there is no one to notify and no remediation workflow to trigger.</p><p>The introduction of AI agents intensifies this problem qualitatively, not just quantitatively. Unlike service accounts, which are relatively predictable in their behavior, AI agents can reason, plan, and take action across multiple systems simultaneously. They adapt based on context, chain operations together, and delegate access in ways that are difficult to anticipate and harder to audit after the fact. An AI agent holding standing access to a sensitive system, operating with a credential shared across tasks, represents a high-velocity incident path that traditional human-speed review processes are structurally unable to close. Some analyst projections suggest that by 2027, AI agents will reduce the time required to exploit account exposures by approximately 50 percent. At that speed, periodic governance is not a partial solution. It is no solution at all.</p><div><hr></div><h3>Regulatory Frameworks Are Enforcing What Good Practice On Identity Posture Recommends</h3><p>Regulatory pressure is no longer a secondary driver of ISPM adoption. Several major frameworks have moved from recommending identity hygiene practices to mandating specific, auditable outcomes that continuous posture management is uniquely positioned to satisfy.</p><ul><li><p><strong>NIS2</strong> requires organizations to demonstrate active access controls, including MFA enforcement and least-privilege access, and to produce evidence of continuous monitoring and incident readiness. </p></li><li><p><strong>DORA</strong> requires evidence of privileged account inventory and regular access reviews, along with tracking and documentation of MFA exceptions across the organization.</p></li><li><p><strong>SEC cybersecurity disclosure requirements</strong> demand audit-grade forensic evidence and governance documentation sufficient to support board-level reporting on material cybersecurity risk. Organizations without that capability must reconstruct the same evidence after the fact, under adverse conditions, with an incomplete record.</p><p></p></li></ul><p>These frameworks establish a minimum operational standard that continuous, manual identity governance cannot meet at the pace regulatory expectations now demand. The organizations that will satisfy these requirements most cleanly are those that have built continuous posture management into the ongoing operation of their identity program. </p><div><hr></div><h3>The Practical Takeaway for IAM Leaders</h3><p>The strategic argument for ISPM investment does not rest on any single driver. It rests on the convergence of three: the documented persistence of identity posture drift as the primary breach precondition, the structural inability of human-scale governance to address machine-speed identity change, and regulatory frameworks that are moving the compliance floor upward toward the operational standard that effective ISPM already represents.</p><p>For IAM leaders, the relevant question is not whether to invest in continuous identity posture management. It is whether the current program reflects the pace at which the identity environment is actually changing, covers the full population of identities that need to be governed including non-human identities and AI agents, and connects posture findings to remediation at a speed that closes the gap before it is exploited.</p><p>The organizations that treat ISPM as a compliance checkbox will extract compliance value from it. The organizations that treat it as operational infrastructure will extract security value from it. In an environment defined by identity posture drift, non-human identity sprawl, and autonomous agents operating outside existing governance frameworks, the difference between those two outcomes is the difference between an identity program that prevents breaches and one that documents them.</p><p></p><div><hr></div><h3>The Convergence Happening In Identity </h3><p>ISPM has moved from a specialist capability to a strategic infrastructure layer. Its growth reflects a fundamental reorientation in how enterprises think about security architecture: the perimeter is no longer a network boundary. It is an identity. Every access decision, every authentication event, every entitlement granted or revoked is a point at which security is either enforced or compromised. In that environment, the platform that continuously governs identity posture and can act on what it finds sits at the center of the enterprise security stack, not at its edge.</p><p>That shift has exposed a structural problem that most identity programs have not yet resolved. The disciplines responsible for identity security- governance, privileged access management, and threat detection were built as separate functions, each with its own tooling, its own operational cadence, and its own blind spots. IGA governs who has access and whether that access is justified, but depends on review cycles that may already be stale by the time they run. PAM secures and monitors privileged accounts, but its scope typically ends where the definition of &#8220;privileged&#8221; ends leaving service accounts, API credentials, and AI agents in a governance gap. ITDR detects and responds to active attacks, but by the time it is engaged, a misconfiguration has already been exploited.</p><p>ISPM addresses this structural problem by operating as the shared intelligence layer across all three disciplines. As agentic capabilities mature, this loop is becoming faster, more autonomous, and more tightly integrated. ISPM is no longer a collection of siloed posture assessment tools that hand off to separate remediation systems. It is converging with the broader identity platform:  IGA, PAM, ITDR, and increasingly the agentic execution layers described later in this report into a unified workflow that can take a posture finding from detection to verified remediation without requiring a human to manually coordinate the handoff between systems. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!iE1j!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a701c86-169c-477d-80d6-86507b9e946c_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!iE1j!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a701c86-169c-477d-80d6-86507b9e946c_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!iE1j!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a701c86-169c-477d-80d6-86507b9e946c_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!iE1j!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a701c86-169c-477d-80d6-86507b9e946c_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!iE1j!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a701c86-169c-477d-80d6-86507b9e946c_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!iE1j!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a701c86-169c-477d-80d6-86507b9e946c_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7a701c86-169c-477d-80d6-86507b9e946c_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!iE1j!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a701c86-169c-477d-80d6-86507b9e946c_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!iE1j!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a701c86-169c-477d-80d6-86507b9e946c_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!iE1j!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a701c86-169c-477d-80d6-86507b9e946c_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!iE1j!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a701c86-169c-477d-80d6-86507b9e946c_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>These areas are increasingly overlapping as ISPM transforms from a collection of siloed point tools into a unified workflow in wider IAM tools and how they might merge with Emerging Agentic Identity Access Platforms (AIAP). When ISPM identifies and prioritizes misconfigurations or posture drift, it routes remediations through IGA-style attestations, PAM-style privileged change controls, and ITDR and SIEM pipelines for correlation. </p><p>This integrated approach creates a single loop from discovery to remediation to audit trail. Modern identity platforms have been converging to meet buyer demands for unified visibility, compliant reporting, and safe automation, while ISPM serves as the connective tissue that translates identity settings into measurable, defensible risk reduction and is also evolving to accommodate agentics for various analysis, reporting, remediation and workflow activities.</p><h3></h3><div><hr></div><h3>The Future of Identity Security: Continuous Posture-to-Runtime Control</h3><p>The convergence described above is not simply a product trend. It points toward an architectural model that represents the logical endpoint of the ISPM evolution: a unified, closed-loop control plane in which real-time risk posture directly informs access enforcement at the moment an identity- human, non-human, or agentic  attempts to act.</p><p>SACR calls this model Continuous Posture-to-Runtime Control. Its defining property is the elimination of the gap between knowing that a risk exists and preventing it from being exploited. In current ISPM deployments, that gap is filled by human remediation workflows; a finding is generated, a ticket is created, an administrator makes a change. In the Continuous Posture-to-Runtime model, the posture signal feeds directly into the authorization decision. An agent flagged as high-risk does not wait for a human to review the finding and revoke its access. Its access is constrained or revoked at the moment the risk condition is detected, without human latency in the loop.</p><p></p><h4><strong>Prediction: Capability Matrix For the ISPM and AIAP Convergence</strong></h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!cRXp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a04f78a-de7b-477a-b324-50497ed59fa4_1080x1350.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!cRXp!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a04f78a-de7b-477a-b324-50497ed59fa4_1080x1350.png 424w, https://substackcdn.com/image/fetch/$s_!cRXp!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a04f78a-de7b-477a-b324-50497ed59fa4_1080x1350.png 848w, https://substackcdn.com/image/fetch/$s_!cRXp!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a04f78a-de7b-477a-b324-50497ed59fa4_1080x1350.png 1272w, https://substackcdn.com/image/fetch/$s_!cRXp!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a04f78a-de7b-477a-b324-50497ed59fa4_1080x1350.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!cRXp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a04f78a-de7b-477a-b324-50497ed59fa4_1080x1350.png" width="607" height="758.75" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1a04f78a-de7b-477a-b324-50497ed59fa4_1080x1350.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1350,&quot;width&quot;:1080,&quot;resizeWidth&quot;:607,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!cRXp!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a04f78a-de7b-477a-b324-50497ed59fa4_1080x1350.png 424w, https://substackcdn.com/image/fetch/$s_!cRXp!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a04f78a-de7b-477a-b324-50497ed59fa4_1080x1350.png 848w, https://substackcdn.com/image/fetch/$s_!cRXp!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a04f78a-de7b-477a-b324-50497ed59fa4_1080x1350.png 1272w, https://substackcdn.com/image/fetch/$s_!cRXp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a04f78a-de7b-477a-b324-50497ed59fa4_1080x1350.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This model requires the convergence of two capabilities that have, until recently, evolved on separate tracks: Identity Security Posture Management and what are emerging as <a href="https://softwareanalyst.io/reports/emerging-agentic-identity-access-platforms-aiap/">Agentic Identity Access Platforms</a>: the runtime authorization and credential brokering layer that governs what identities can do at the moment of action, not just what they are permitted to do in principle.</p><p>For a deeper analysis of this transition, see the <a href="https://softwareanalyst.io/reports/emerging-agentic-identity-access-platforms-aiap/">SACR report on AIAP.</a> By 2029, SACR believes that identity for AI agents will no longer be static; it will be a transient state, granted, monitored, and revoked in real time (see also&nbsp;<a href="https://softwareanalyst.io/reports/the-runtime-enforcement-challenge-and-the-emerging-vendor-landscape/">Runtime Security for AI Agents</a>). Organizations that fail to adopt an agentic broker and runtime security risk leaving their infrastructure vulnerable to the exploitability of static, long-lived credentials. SACR will be exploring Runtime Identity Security Enforcement in future notes.</p><h4>An Integrated Operational Model</h4><p>The ISPM and AIAP convergence over time represents the architectural foundation of Continuous Posture-to-Runtime control, a unified, closed-loop control plane designed to govern machine-speed autonomy. This integrated model is structured around the four operational phases of Agentic Access Management (AAM), aligning the ISPM function (posture/risk-finding) with AIAP execution and the three layers of agent runtime security. Read more in our report above. </p><h4></h4><p></p><div><hr></div><h2><strong>Agentic Remediation</strong></h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!fHbQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8c19b20-0961-4efb-b6c9-7aec75568ed3_2264x1242.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!fHbQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8c19b20-0961-4efb-b6c9-7aec75568ed3_2264x1242.png 424w, https://substackcdn.com/image/fetch/$s_!fHbQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8c19b20-0961-4efb-b6c9-7aec75568ed3_2264x1242.png 848w, https://substackcdn.com/image/fetch/$s_!fHbQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8c19b20-0961-4efb-b6c9-7aec75568ed3_2264x1242.png 1272w, https://substackcdn.com/image/fetch/$s_!fHbQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8c19b20-0961-4efb-b6c9-7aec75568ed3_2264x1242.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!fHbQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8c19b20-0961-4efb-b6c9-7aec75568ed3_2264x1242.png" width="1456" height="799" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a8c19b20-0961-4efb-b6c9-7aec75568ed3_2264x1242.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:799,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:359396,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://softwareanalyst.substack.com/i/201332633?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8c19b20-0961-4efb-b6c9-7aec75568ed3_2264x1242.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!fHbQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8c19b20-0961-4efb-b6c9-7aec75568ed3_2264x1242.png 424w, https://substackcdn.com/image/fetch/$s_!fHbQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8c19b20-0961-4efb-b6c9-7aec75568ed3_2264x1242.png 848w, https://substackcdn.com/image/fetch/$s_!fHbQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8c19b20-0961-4efb-b6c9-7aec75568ed3_2264x1242.png 1272w, https://substackcdn.com/image/fetch/$s_!fHbQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8c19b20-0961-4efb-b6c9-7aec75568ed3_2264x1242.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><h4><strong>The New Battleground for ISPM Capabilities</strong></h4><p>Agentic AI is not just a risk driver, it ultimately changes what good ISPM looks like as it becomes more and more capable of delivering reliability and efficiency for enterprises. The differentiator in the application of AI and agentics (at least today) is predominantly agentic remediation, which provides tools with the ability to turn posture findings into safe, reversible, evidence-producing changes at scale using various AI agents for various functions and domains. Use cases that are lightweight, or lower risk operations (for example, agentic review, prioritization, explanations for identity and access management team operators, or for audit sampling) are all lower risk activities that can be agentic-enabled without as much risk.  Agentic adoption will still be reliant on enabling factors to gain adoption, the most important aspect being reliability and accuracy as called out by the Sola benchmark testing and vendor verification claims (See <a href="https://arxiv.org/pdf/2601.07880">SOLA-VISIBILITY-ISPM</a>).</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HyP-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa520f486-a130-4915-837f-79e44579d5c4_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HyP-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa520f486-a130-4915-837f-79e44579d5c4_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!HyP-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa520f486-a130-4915-837f-79e44579d5c4_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!HyP-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa520f486-a130-4915-837f-79e44579d5c4_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!HyP-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa520f486-a130-4915-837f-79e44579d5c4_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HyP-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa520f486-a130-4915-837f-79e44579d5c4_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a520f486-a130-4915-837f-79e44579d5c4_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!HyP-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa520f486-a130-4915-837f-79e44579d5c4_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!HyP-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa520f486-a130-4915-837f-79e44579d5c4_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!HyP-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa520f486-a130-4915-837f-79e44579d5c4_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!HyP-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa520f486-a130-4915-837f-79e44579d5c4_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Typical ISPM Remediation Workflow</strong></p><p>The typical ISPM remediation workflow operates as a closed-loop control system that moves through five critical stages: detect, decide, remediate, verify, and evidence. This automated cycle relies on several key enabling factors to ensure operational safety and reliability, including a change-control interface for human-in-the-loop approvals, rollback semantics to revert changes if necessary, a continuous verification loop to monitor for drift, and evidence-grade telemetry to provide a complete audit trail of every action taken.</p><p><strong>Implication:</strong> ISPM must be evaluated as a <strong>closed-loop control system</strong> (detect &#8594; decide &#8594; remediate &#8594; verify &#8594; evidence), not as a posture dashboard.</p><div><hr></div><h2><strong>Product Use Cases CISO Buyers Should Evaluate</strong></h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!UoKp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28ccd1b2-c349-4ec2-abaa-929bdaefb5cd_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!UoKp!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28ccd1b2-c349-4ec2-abaa-929bdaefb5cd_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!UoKp!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28ccd1b2-c349-4ec2-abaa-929bdaefb5cd_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!UoKp!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28ccd1b2-c349-4ec2-abaa-929bdaefb5cd_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!UoKp!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28ccd1b2-c349-4ec2-abaa-929bdaefb5cd_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!UoKp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28ccd1b2-c349-4ec2-abaa-929bdaefb5cd_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/28ccd1b2-c349-4ec2-abaa-929bdaefb5cd_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!UoKp!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28ccd1b2-c349-4ec2-abaa-929bdaefb5cd_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!UoKp!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28ccd1b2-c349-4ec2-abaa-929bdaefb5cd_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!UoKp!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28ccd1b2-c349-4ec2-abaa-929bdaefb5cd_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!UoKp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28ccd1b2-c349-4ec2-abaa-929bdaefb5cd_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><h3><strong>Agentic remediation capabilities (what to look out for)</strong></h3><p>The following capabilities delineate the fundamental transition from passive reporting toward a continuous, operationalized identity security control loop.</p><h4><strong>Evaluation framework: Qualitative Buyer Lenses</strong></h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!R2CH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12f84c9b-5756-44cc-92d5-e964b4d1da8a_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!R2CH!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12f84c9b-5756-44cc-92d5-e964b4d1da8a_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!R2CH!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12f84c9b-5756-44cc-92d5-e964b4d1da8a_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!R2CH!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12f84c9b-5756-44cc-92d5-e964b4d1da8a_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!R2CH!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12f84c9b-5756-44cc-92d5-e964b4d1da8a_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!R2CH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12f84c9b-5756-44cc-92d5-e964b4d1da8a_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/12f84c9b-5756-44cc-92d5-e964b4d1da8a_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!R2CH!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12f84c9b-5756-44cc-92d5-e964b4d1da8a_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!R2CH!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12f84c9b-5756-44cc-92d5-e964b4d1da8a_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!R2CH!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12f84c9b-5756-44cc-92d5-e964b4d1da8a_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!R2CH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12f84c9b-5756-44cc-92d5-e964b4d1da8a_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><ol><li><p><strong>Remediation Intent Modelling:</strong> Sophisticated systems must articulate remediation as an intent-based outcome, such as the elimination of risky legacy authentication pathways or the precision right-sizing of privileged memberships, rather than relying on static, manual runbooks.</p></li></ol><ol start="2"><li><p><strong>Autonomous Guardrails and Safe Automation:</strong> The platform must operationalize automation under strict constraints, incorporating definitive scope limits, blast-radius assessments, maintenance windows, and human-in-the-loop approval interfaces.</p></li></ol><ol start="3"><li><p><strong>Dependency-Aware Remediation Graphing:</strong> A mature posture requires the ability to predict breakage risk and organizational impact prior to execution, distinguishing between effective permissions and mere configured states.</p></li></ol><ol start="4"><li><p><strong>Audit-Grade Evidence and Rollback:</strong> To satisfy governance mandates, every action must produce evidence-grade artifacts, including before-and-after posture deltas, change actors, and verifiable rollback procedures.</p></li></ol><ol start="5"><li><p><strong>Precision Human-in-the-Loop Workflows:</strong> Where manual intervention is required, the workflow must be accelerated through high-context delivery, providing pre-filled tickets and exact diff visualizations to ensure implementation accuracy.</p></li></ol><ol start="6"><li><p><strong>Continuous Verification and Drift Prevention</strong>: Following remediation, the system must enter an autonomous re-check cycle to monitor for posture drift and prevent the reintroduction of known vulnerabilities.</p></li></ol><h3></h3><div><hr></div><h2><strong>Representative Vendor Profiles</strong></h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Gsw0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b12c23f-1e4d-487e-b64d-0e92c04d3d22_2274x1298.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Gsw0!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b12c23f-1e4d-487e-b64d-0e92c04d3d22_2274x1298.png 424w, https://substackcdn.com/image/fetch/$s_!Gsw0!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b12c23f-1e4d-487e-b64d-0e92c04d3d22_2274x1298.png 848w, https://substackcdn.com/image/fetch/$s_!Gsw0!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b12c23f-1e4d-487e-b64d-0e92c04d3d22_2274x1298.png 1272w, https://substackcdn.com/image/fetch/$s_!Gsw0!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b12c23f-1e4d-487e-b64d-0e92c04d3d22_2274x1298.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Gsw0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b12c23f-1e4d-487e-b64d-0e92c04d3d22_2274x1298.png" width="1456" height="831" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3b12c23f-1e4d-487e-b64d-0e92c04d3d22_2274x1298.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:831,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:577647,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://softwareanalyst.substack.com/i/201332633?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b12c23f-1e4d-487e-b64d-0e92c04d3d22_2274x1298.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Gsw0!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b12c23f-1e4d-487e-b64d-0e92c04d3d22_2274x1298.png 424w, https://substackcdn.com/image/fetch/$s_!Gsw0!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b12c23f-1e4d-487e-b64d-0e92c04d3d22_2274x1298.png 848w, https://substackcdn.com/image/fetch/$s_!Gsw0!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b12c23f-1e4d-487e-b64d-0e92c04d3d22_2274x1298.png 1272w, https://substackcdn.com/image/fetch/$s_!Gsw0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b12c23f-1e4d-487e-b64d-0e92c04d3d22_2274x1298.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em><strong>Inclusion Note:</strong> Profiles below are limited to vendors that have added agentic remediation capabilities to their ISPM functionality, enabling AI agent functions to drive actual remediation activities and workflows.</em></p><p><em>The vendors profiled in this section were selected on a single criterion: demonstrated capability to perform agentic remediation of identity-based risks, not claimed capability. Every vendor in the identity security market is currently describing its roadmap in agentic terms. The profiles below are not about roadmaps. They are about what each platform can demonstrably do today: whether it can write back to identity control planes, whether it can verify that a remediation action resolved the underlying finding, whether it can restore a prior state if a change creates operational risk, and whether it can produce audit-grade evidence of every step in that cycle.</em></p><p><em>Five vendors are profiled: Saviynt, Okta, CrowdStrike, Delinea, and Silverfort. Each approaches the Agentic ISPM problem from a different architectural starting point, IGA-native, endpoint and telemetry-native, PAM-native, and runtime enforcement-native respectively. That difference in starting point is not a ranking. It is the most important context for understanding which platform fits which environment and which buyer. A CISO standardized on the Falcon platform is evaluating a different set of tradeoffs than a CISO running a large IGA program with complex lifecycle governance requirements. The profiles are structured to surface those tradeoffs clearly rather than reduce every vendor to a feature checklist.</em></p><p></p><div><hr></div><h2><strong>Saviynt</strong></h2><h3>Vendor Profile</h3><p>Saviynt is a recognized leader in agentic identity governance and the first to ship production-grade posture management for AI agents and MCP servers, delivering the critical infrastructure enterprises need to govern autonomous identities at scale. The milestone reflected a deliberate architectural vision: bringing agentic ISPM and identity governance together into a single, unified control plane.  The result is the only IGA-native platform in this category that connects posture findings directly to the ownership, access, and compliance workflows that identity teams already operate.</p><p>Saviynt gives enterprises a unified view across human, non-human, and agentic identities spanning AWS, Google Cloud, and Microsoft Azure cloud platforms, so identity and security teams have a complete and governed picture of everything running in their environment.</p><p>Saviynt&#8217;s agent security story is easiest to understand as a closed-loop control system: you first establish <em>what an agent is and what it&#8217;s allowed to do</em>, then you continuously measure risk and context, and finally you enforce policy at the exact moment the agent takes action. That&#8217;s why their model is organized into three pillars: posture, governance, and runtime because each pillar supplies a distinct control layer, and the combined effect is what lets them claim end-to-end coverage &#8220;from registration to runtime enforcement.&#8221; </p><p>These three pillars then assemble into one coherent narrative:</p><ol><li><p><strong>Posture management (signal + risk context):</strong> They start by discovering agents, identities, apps, permissions, and activity and then correlate risk signals from the surrounding ecosystem. This pillar produces the <em>risk and exposure context</em> you need to make governance and runtime decisions credible (e.g., trust score, anomaly indicators, asset sensitivity).</p></li><li><p><strong>Lifecycle governance (control plane):</strong> This capability puts agents into a governed lifecycle: registration, owner assignment, access boundaries, and just&#8209;in&#8209;time controls. This is where you define &#8220;who is accountable,&#8221; &#8220;what is permitted,&#8221; and &#8220;under what constraints,&#8221; so policies aren&#8217;t ad hoc, they&#8217;re administratively managed and auditable. </p></li><li><p><strong>Runtime authorization (enforcement plane):</strong> Finally, you enforce those governance decisions <em>in the transaction path</em> through monitoring and intent assessment and token brokering/mediation. This is where policy becomes real: the system evaluates the runtime context and the governance state, then can block/flag/alert when the request violates policy or looks suspicious.</p></li></ol><p></p><h3><strong>Agentic Identity Security Capabilities</strong> </h3><ol><li><p><strong>Saviynt&#8217;s</strong> <strong>Agent Access Gateway</strong> is the control plane that defines and governs <em>which agents exist, who owns them, what they&#8217;re allowed to do, and under what conditions they can act</em> before you ever get to runtime. It operationalizes &#8220;agent identity&#8221; by treating agents as managed entities with lifecycle governance: registration, ownership assignment, scoped permissions, just-in-time access boundaries, and administrative guardrails (e.g., approval, certification, and recertification policies). This maps to Saviynt&#8217;s capability to bring traditional identity governance discipline (IGA) into the agent era: instead of letting agents sprawl as untracked automations, the gateway creates a governed inventory with explicit access boundaries and accountability, so that runtime enforcement has high-quality inputs (who/what the agent is, what it&#8217;s allowed to touch, and what policy must be true) and the organization can prove control through audit-ready governance artifacts.</p></li><li><p><strong>Saviynt&#8217;s Runtime Gateway</strong> functions as a real-time policy enforcement layer that sits in the execution path between an AI agent (or agent-enabled workflow) and the enterprise systems it tries to reach. It integrates with core identity providers like Okta and Entra ID for authentication context, then performs multi-layer authorization at the moment of action, separately validating the human/operator&#8217;s entitlements, whether the agent is allowed to be invoked for that purpose, and whether the agent is permitted to access the specific target resources. It also mediates tokens (including on-behalf-of flows) to preserve provenance and reduce direct credential exposure, while continuously evaluating runtime signals such as agent registration status, ownership validation, trust score, anomalous access patterns, and certification/compliance state. Net: this maps to Saviynt&#8217;s capability to make &#8220;agentic access&#8221; enforceable like any other identity transaction: inspectable, auditable, and blockable with policy outcomes that can block/flag/alert in-line.</p></li></ol><p></p><h3>ISPM Alignment (Saviynt)</h3><p>Saviynt ISPM delivers an end-to-end solution for AI identity security spanning discovery, governance, and runtime enforcement across human, non-human, and agentic identities. The platform continuously discovers AI agents, NHIs, and workforce identities, surfacing risks like orphaned accounts, missing guardrails, and excessive entitlements. </p><p>Every discovered identity is then governed with full accountability through ownership assignment, lifecycle management, and access approvals, with the Agentic Access Gateway enforcing entitlement boundaries at the moment an action is attempted. All findings and remediation actions are captured in an immutable audit trail mapped to NIST AI RMF, OWASP, MITRE, SOX, and HIPAA. Posture findings connect directly to the governance and runtime authorization workflows that identity teams already operate &#8212; turning visibility into action rather than leaving it as a standalone tool.</p><p><strong>Saviynt Agentic ISPM&#8217;s core capabilities include:</strong></p><ul><li><p><strong>Unified Visibility:</strong> Gain a centralized view of all AI agents and their underlying dependencies, including LLMs, tools, and data sources.</p></li><li><p><strong>Actionable Risk Findings: </strong>Clear visibility into the highest-priority vulnerabilities, ranked for efficient triage and response.</p></li><li><p><strong>Targeted Remediation:</strong> Take immediate action by assigning owners to orphaned identities, AI agents, registering shadow agents, or assigning missing guardrails while the overall platform has remediation across multiple types of identities and cloud platforms.</p></li><li><p><strong>Audit-Ready Timelines:</strong> Accelerate investigations and simplify compliance checks with a chronological timeline of all access and configuration changes.</p></li><li><p><strong>Dynamic Access Graphs:</strong> Visually map access pathways to identify what an agent can reach and limit its breach radius.</p></li></ul><h3>Use Cases and Pain Points Addressed</h3><ol><li><p><strong>Improve speed, visibility and observability of NHI and AI identities</strong></p><ul><li><p><strong>Enabling capability:</strong> Extend identity security posture management from humans to AI agents and NHIs without the need of a separate point solution. Improve application onboarding throughput (including disconnected apps).</p></li><li><p><strong>Detail:</strong> Unifies posture and governance for human, non-human, and agent identities in one platform. CUA-style agentic onboarding is positioned to reduce manual effort and close the identity integration gap to disconnected and nonstandard applications.</p></li></ul></li><li><p><strong>Enable closed-loop governance</strong></p><ul><li><p><strong>Enabling capability:</strong> Reduce remediation backlog by tying posture findings to agentic governance workflows.</p></li><li><p><strong>Detail:</strong> Uses IGA-native ownership/certification mechanisms to operationalize closed-loop governance of NHI and AI identity ownership, succession management, and entitlement management.</p></li></ul></li><li><p><strong>Control what agents are permitted to do</strong></p><ul><li><p><strong>Enabling capability:</strong> Runtime access management enforcement governed by identity, intent, context, and policy.</p></li><li><p><strong>Detail:</strong> Runtime authorization ensures every action is verified at the moment of execution, preventing misuse, limiting unintended behavior, and enforcing least-privileged access as conditions change.</p></li></ul></li></ol><p><br>Saviynt&#8217;s Agentic tier placement rests on one architectural decision that separates it from most competitors in this category: posture findings execute remediation within the same IGA-native governance framework that manages every other identity change in the environment. When Saviynt identifies an overprivileged service account or a stale agent credential, the remediation action is not an out-of-band automation event. It is a governed identity transaction carrying the same audit trail, approval chain, and rollback semantics as any human access review decision. That is a meaningful distinction. Most agentic remediation tools operate outside the governance plane and produce a separate evidence record that identity teams must reconcile manually. Saviynt does not.</p><p>The platform is also the first in this category to ship production-grade posture management for AI agents and MCP servers, giving it early coverage of the NHI and agentic identity governance problem that is growing fastest in enterprise environments today.</p><p>The honest limitation is scope dependency. Saviynt&#8217;s core advantage is strongest in environments where IGA is already the operational center of the identity program. Organizations without a mature IGA foundation will get the remediation capability but not the governance integration that defines the platform&#8217;s differentiation. Buyers should know which of those two things they are actually purchasing before they shortlist.</p><p></p><h3>Key Recommendation</h3><p>Best fit for enterprises that want to extend posture management to NHI and AI agents without adding a separate tool. Saviynt provides a unique value proposition by connecting posture findings directly to existing governance and access workflows, facilitating proactive risk reduction through one-click remediation and agentic automation. It also offers easy discovery and onboarding of applications using agentics and AI to map various application capabilities to integrate rapidly, replacing manual human integration processes.</p><div><hr></div><h2>Okta</h2><h4>Vendor Profile</h4><p>Okta ISPM is the posture management layer of the world&#8217;s largest independent identity platform, built on the foundation of the Spera Security acquisition and now positioned as a core capability within the broader Okta for AI Agents solution. Its architectural center of gravity is its position inside the identity control plane itself: where most ISPM vendors connect to identity providers as external observers, Okta operates the IdP for a significant share of the enterprise market and extends posture visibility outward from that position across third-party identity providers, SaaS applications, cloud infrastructure, and on-premises Active Directory. The platform provides a unified view of non-human identities across these surfaces and applies more than 25 prioritized risk detections mapped to the OWASP Top 10 for NHIs to surface gaps like over-privileged or unrotated credentials. <a href="https://saviynt.com/blog/identity-security-for-and-by-ai-agents">Saviynt</a></p><p>The most significant recent development is Agent Discovery, announced in February 2026 to enable organizations to discover shadow AI, uncover hidden identity risks and misconfigurations of unknown and known agents, and map agents&#8217; potential blast radius. The capability is architecturally distinctive: it is powered by Okta&#8217;s browser plugin and leverages OAuth consent events, the authorization prompts users see when an app requests access to their data, to identify AI agents operating inside an organization. By surfacing these connections at the point of origin, organizations gain visibility into AI tools entering their environment before they evolve into backend API integrations or complex app-to-app connections. This addresses a real and growing problem: research shows that 90 percent of enterprise AI usage occurs via unauthorized personal accounts, with organizations facing an average of 223 shadow AI incidents per month. <a href="https://expertinsights.com/identity-and-access-management/top-identity-security-posture-management-ispm-solutions">Expert Insights + 3</a></p><h4>ISPM Alignment (Okta)</h4><p>Okta&#8217;s ISPM is aligned to discovery, prioritization, and guided remediation from inside the identity control plane, rather than autonomous closed-loop execution. The platform continuously assesses identity risk posture, uncovers misconfigurations such as SSO exceptions, MFA bypass conditions, orphaned accounts, and partially offboarded users, and routes findings through outbound integrations to the teams and systems that execute the fix. Recent releases have strengthened the operational layer around this model: role-based access control across the ISPM console with graduated permissions for issue responders and viewers, multiple outbound integration instances for routing findings to different teams, and expanding source coverage including Workday and Salesforce connected apps.</p><p>The key trade-off mirrors the inverse of Silverfort&#8217;s. Where Silverfort enforces at the authentication moment but is weaker on configuration baseline drift, Okta is strongest on configuration and entitlement posture across the identity fabric it already operates, but its remediation model remains primarily guided: findings generate actionable guidance, alerts, and workflow triggers rather than confirmed closed-loop write-back with independent verification and rollback semantics. This is why Okta sits in the Guided Remediation tier of the SACR market map. The placement is not a criticism of posture analysis depth, which is among the strongest in the market. It reflects the evidence threshold for the Agentic tier: demonstrated write-back, verification, rollback, and evidence logging as a complete cycle. Okta&#8217;s agent lifecycle vision, in which customers turn shadow agents into governed assets by assigning human owners and enforcing baseline security policies, points clearly in that direction, but the autonomous execution loop is not yet the demonstrated core of the offering. <a href="https://expertinsights.com/identity-and-access-management/top-identity-security-posture-management-ispm-solutions">Expert Insights</a></p><h4>Core Functions</h4><ul><li><p><strong>Agent Discovery for shadow AI:</strong> Detects OAuth consents at the point of origin to identify sanctioned and unsanctioned AI agents, mapping the relationship between the client app and the resource app and exposing granted scopes and blast radius.</p></li><li><p><strong>NHI posture across surfaces:</strong> Single view of non-human identity types across SaaS, identity providers, cloud infrastructure, and on-premises Active Directory, with prioritized risk detections mapped to the OWASP Top 10 for NHIs.</p></li><li><p><strong>IdP-native configuration posture:</strong> Continuous detection of SSO exceptions, MFA bypass and exclusion conditions, inconsistent policy enforcement, and offboarding gaps across Okta and third-party identity providers.</p></li><li><p><strong>Guided remediation routing:</strong> Outbound integrations, event hooks, and role-based workflows that route findings to the appropriate owner with actionable remediation context.</p></li></ul><h4>Key Recommendation</h4><p>Okta represents the natural ISPM choice for enterprises already standardized on Okta as their workforce identity provider, and the strongest available option for organizations whose most urgent posture problem is shadow AI and ungoverned agent sprawl at the application layer. Its discovery position is structurally unique: because agents authenticate and request consent through the identity layer Okta already operates, the platform sees agent creation at the moment it happens rather than reconstructing it afterward from logs. Organizations should shortlist Okta when their strategic priority is comprehensive posture visibility across the identity fabric, NHI and AI agent discovery at scale, and tight integration between posture findings and the IdP configuration surface those findings describe. Buyers whose primary requirement is autonomous closed-loop remediation with demonstrated write-back and rollback should evaluate Okta&#8217;s roadmap timing carefully against the Agentic tier vendors, or plan to pair Okta&#8217;s discovery and prioritization strength with an execution layer that closes the loop.</p><p></p><div><hr></div><h2><strong>CrowdStrike</strong></h2><h3>Vendor Profile</h3><p>CrowdStrike Falcon Next-Gen Identity is a real-time identity security platform that combines continuous identity posture management, modern privileged access with Zero Standing Privileges (ZSP), threat detection and response, and dynamic enforcement across hybrid environments through its one platform, one console architecture. Its architectural center of gravity utilizes pre-deployed Falcon sensors and cloud telemetry to surface and correlate risks across endpoint, identity, cloud and SaaS environments, connecting posture management directly to real-time enforcement  and automated remediation via Falcon Fusion SOAR. Recent acquisition of SGNL makes the Crowdstrike identity solution a continuous identity solution that comprises ITDR, Modernized Zero Standing Privileges, phishing-resistant MFA and extends to SaaS posture management with Falcon Shield.</p><p>CrowdStrike Falcon Identity is positioned as a strategic platform-incumbent play for organizations seeking to operationalize identity security within a converged EDR/XDR ecosystem. Its architectural center of gravity utilizes the pre-deployed Falcon sensor to surface risks across AD, Entra ID, and Okta, effectively converging ITDR and ISPM, and modern privileged access into a unified operational model. The primary value proposition lies in the telemetry correlation between identity, endpoint, and cloud, powered by Falcon Fusion SOAR for automated remediation. While the 2025 introduction of Entra Authentication Manager (EAM) provides inline auth control comparable to Silverfort, CrowdStrike uniquely connects identity posture, threat intelligence, and real-time enforcement  across the Falcon platform.</p><h3>Agentic ISPM Alignment (CrowdStrike)</h3><p><a href="https://www.crowdstrike.com/en-us/blog/crowdstrike-to-acquire-sgnl/">SGNL materially strengthens CrowdStrike&#8217;s ISPM story</a> because it moves Falcon Identity closer to continuous identity control rather than posture visibility alone. Before SGNL, CrowdStrike&#8217;s identity advantage was already strong in telemetry correlation: Falcon could combine endpoint, cloud, threat intelligence, and identity signals to detect risky identities, compromised accounts, lateral movement, and Active Directory or IdP misconfigurations. That made CrowdStrike credible in ITDR and identity posture assessment, especially for customers already standardized on Falcon. The gap was that posture insight still needed to connect more directly to real-time access decisions across SaaS, cloud, human users, non-human identities, and AI agents.</p><p>SGNL helps close that gap by adding a dynamic authorization layer. Instead of treating identity posture as a static finding or a ticket that someone must remediate later, SGNL enables access to be continuously evaluated based on identity, device, behavior, session context, and real-time risk. This is important for ISPM because the future of posture management is not just identifying that an account is overprivileged, stale, risky, or operating outside normal patterns. The more valuable capability is translating that posture signal into an enforceable control decision: grant, deny, revoke, step up authentication, shorten privilege duration, or route the change through approval.</p><p>This pushes CrowdStrike further into Agentic ISPM because it gives Falcon a clearer path from detection to posture-to-runtime control. Falcon can supply the risk intelligence and security context, while SGNL can help enforce access changes across SaaS and cloud environments where standing privileges, service accounts, and AI agents create fast-moving exposure. For CISOs, the strategic value is that identity posture becomes more operational: risky access can be constrained closer to the moment of use rather than discovered after the fact.</p><p>The key diligence question is whether CrowdStrike can prove full closed-loop remediation across customer environments: write-back, verification, rollback, audit evidence, and human-in-the-loop controls for high-impact changes. If those controls mature, SGNL makes CrowdStrike&#8217;s ISPM capabilities more than another posture dashboard; it strengthens the platform&#8217;s ability to govern identity risk continuously at runtime.</p><p>Broadly, CrowdStrike&#8217;s alignment is centered on the paradigm of Agentic Identity Posture Management (Agentic ISPM) as a core capability within the Falcon platform. By leveraging pre-deployed Falcon sensors, the architecture achieves a continuous Posture-to-Runtime Control model, correlating identity signals with endpoint and cloud telemetry in real-time. This integration transforms static posture into continuous, real-time identity protection and enforcement, utilizing Falcon Fusion SOAR to execute autonomous remediation across Active Directory and cloud environments. Furthermore, the 2025 introduction of Entra Authentication Manager (EAM) provides critical inline authentication enforcement, ensuring that agentic identities are governed by deterministic, intent-aware controls at the point of execution.</p><p></p><h3>Use Cases and Pain Points Addressed</h3><ol><li><p><strong>Unified  identity posture within the Falcon console</strong></p><ul><li><p><strong>Enabling capability:</strong> Co-location of ISPM data with endpoint and threat intelligence telemetry, requiring no additional vendor footprint for Falcon customers.</p></li></ul></li><li><p><strong>Real-time Entra ID auth enforcement (EAM)</strong></p><ul><li><p><strong>Enabling capability:</strong> EAM intercepts cloud authentication events to apply deterministic grant/block/challenge policies inline.</p></li><li><p><strong>Detail:</strong> Neutralizes credential-based risks in cloud IdP paths without necessitating a standalone authentication-interception tool.</p></li></ul></li><li><p><strong>Automated AD response via Falcon Fusion SOAR</strong></p><ul><li><p><strong>Enabling capability:</strong> Deterministic playbooks that automatically disable accounts, revoke memberships, or trigger MFA upon threat detection.</p></li><li><p><strong>Detail:</strong> Compresses the attacker&#8217;s window by reducing MTTR for identity-based tampering from hours to seconds.</p></li></ul></li></ol><h3>Key Recommendation</h3><p>CrowdStrike represents the optimal architectural choice for enterprises already standardized on the Falcon platform that require a unified control plane for identity and endpoint security. Organizations should prioritize this vendor when the strategic mandate focuses on consolidating identity posture, threat detection, and real-time enforcement within a unified Falcon platform architecture, unifying ITDR and ISPM telemetry under a single SOAR execution engine, to achieve measurable risk reduction. Shortlist CrowdStrike when the Falcon sensor is already deployed across the estate, multi-surface visibility (AD/Entra/Okta) must be co-located with threat intelligence, or deterministic, automated response workflows are a mandatory requirement for identity operational resilience.</p><div><hr></div><h2>Delinea</h2><h3>Vendor Profile</h3><p>Delinea is positioned primarily as a PAM-led identity security platform pursuing the most ambitious mid-market Agentic ISPM play in the privileged access segment. Its architectural center of gravity is the convergence of enterprise PAM (Secret Server, Privilege Manager) with a real-time agentic AI layer (Iris AI, GA August 2025) and a newly unified runtime authorization capability via the StrongDM merger (announced January 2026). The primary value proposition lies in the platform&#8217;s ability to extend traditional vaulting and JIT privilege elevation into continuous, evidence-based access decisions across human, non-human, and AI agent identities without requiring manual identity cataloging. Unlike identity-native ISPM vendors that start from IdP configuration analysis and extend toward remediation, Delinea starts from the privileged execution layer and extends toward posture, creating a differentiated &#8220;fix-first&#8221; orientation where the remediation path (credential rotation, JIT assignment, session termination, automated response actions for Entra ID and Okta) is natively embedded. The ITP/PCCE (Identity Threat Protection / Privileged Cloud &amp; Configuration Entitlement) module provides a structured checks library for identity posture with guided remediation and compliance mapping, while Iris AI promises to replace static rule-based access governance with real-time, context-aware decisioning. The acquisition of Authomize (2023) and Fastpath (2024) extends coverage into IGA-adjacent entitlement analysis and SaaS application access governance, though integration maturity across these acquisitions varies.</p><h3>ISPM Alignment (Delinea)</h3><p>Delinea&#8217;s alignment with the Agentic ISPM paradigm is anchored in the convergence of PAM-native execution capabilities with the Iris AI reasoning layer to establish a continuous Posture-to-Runtime Control model within the privileged access domain. The ITP/PCCE Identity Posture module provides the posture assessment and drift detection function (continuous monitoring of identity misconfiguration across Entra ID and Okta), while the automated response actions in the Cases workflow provide the remediation execution function, creating a partial closed-loop from detection through remediation. The StrongDM merger extends this control loop to runtime authorization for infrastructure and developer workflows, enabling just-in-time privilege at the point of execution rather than standing access. Iris AI is positioned as the intelligence layer that replaces static policy rules with real-time, context-aware access decisions, and represents one of the more complete agentic ISPM architectures in the PAM segment.</p><h4><strong>SACR Key Takeaway:</strong></h4><p>Delinea is the best fit for mid-market enterprises already running Delinea PAM, leveraging a unique fix-first remediation orientation by combining PAM-grade execution (JIT, session control) with ISPM assessment (ITP/PCCE) and emerging agentic decisioning (Iris AI) for privileged NHI and AI agent governance. However, organizations should note that its posture coverage for deep IdP configuration analysis is less proven than identity-native ISPM peers.</p><h2></h2><div><hr></div><h2><strong>Silverfort</strong></h2><h3><strong>Vendor Profile</strong></h3><p>Silverfort is a leading runtime identity security company that recently deepened its focus on the agentic era through its April 28, 2026, acquisition of Fabrix Security. This acquisition integrates Fabrix&#8217;s AI-native identity knowledge graph and AI-driven decisioning engine with Silverfort&#8217;s Runtime Access Protection (RAP) technology, enabling the first autonomous Identity Security Platform. Silverfort&#8217;s architectural center of gravity is its unique authentication-interception architecture, which positions it as a runtime identity control plane for AI agents, human, and machine identities across hybrid ecosystems. Silverfort&#8217;s strategic alliance with SentinelOne aims to create a unified identity-endpoint control plane to deliver real-time enforcement and autonomous containment of all identity types including Non-Human Identities (NHIs), AI agents, and humans.</p><h3>ISPM Alignment (Silverfort)</h3><p>Silverfort&#8217;s ISPM is aligned to runtime enforcement during authentication, rather than remediation after the fact. Where most ISPM tools open a ticket when a misconfiguration is found, Silverfort can deny or challenge the at-risk authentication in real-time. The key trade-off is that auth-time enforcement addresses behavioral and access-time risk better than it addresses IdP configuration baseline drift (e.g., fixing a misconfigured CA policy). Silverfort best complements configuration-analysis-heavy IdPs, IGA and PAM solutions; it does not replace them.</p><h3><strong>Core Functions</strong></h3><ul><li><p><strong>Universal MFA for legacy/on-prem access paths:</strong> Enforce MFA where CA can&#8217;t reach (e.g., AD-authenticated admin protocols and legacy apps).</p></li><li><p><strong>Authentication firewall containment:</strong> Deny/segment risky authentication attempts to contain lateral movement.</p></li><li><p><strong>ISPM risk scoring and posture hardening:</strong> Prioritize identity weaknesses and map them to enforceable controls.</p></li><li><p><strong>Entra EAM integration:</strong> Participate in Entra auth workflows where EAM is available.</p></li></ul><h3>Key Recommendation</h3><p>Silverfort represents a critical architectural shift for hybrid Active Directory (AD) enterprises that require real-time, inline enforcement against identity-based threats. While traditional Identity Security Posture Management (ISPM) tools focus on discovery and long-term remediation, Silverfort operates at the authentication plane, sitting inline with Kerberos, NTLM, LDAP, and RADIUS requests. This positioning is vital for governing legacy protocol exposure that Microsoft Conditional Access (CA) structurally cannot reach, such as NTLMv1 or administrative command-line tools. Organizations should shortlist Silverfort when their strategic priority is stopping attacks in-flight, achieving near-zero latency between detection and enforcement as a necessary complement to misconfiguration remediation. By enforcing phishing-resistant MFA and virtual fencing for service accounts, Silverfort effectively neutralizes lateral movement and credential theft in milliseconds, filling the critical gap in the existing identity control plane for heterogeneous environments.</p><p></p><div><hr></div><h1><strong>Buyer&#8217;s Lens / Practitioner Guidance</strong></h1><h2><strong>CISOs playbook &amp; where ISPM belongs</strong></h2><p>ISPM should be treated as a <strong>control-plane and posture layer</strong> that sits between identity infrastructure (IdP/IGA/PAM/endpoint/cloud identity) and operational security workflows (SecOps / IAM ops/platform engineering). The key question is ownership: who will operate posture findings and remediation day-to-day?</p><p></p><h3><strong>30/60/90 Day Implementation Strategy</strong></h3><p>Implementing an effective Agentic Identity Security Posture Management (ISPM) program requires a structured approach that evolves from initial discovery and baseline establishment to full autonomous maturity. The following strategy provides a phased framework for organizations to operationalize continuous identity risk reduction, ensuring security evolves at machine speed while maintaining governance and control.</p><p>The pilot design framework focuses on defining measurable success criteria, identifying necessary telemetry sources, and ensuring robust change control and rollback planning. Additionally, practitioners are encouraged to vet vendors on their inclusion criteria for identity posture signals, their specific write-back remediation capabilities, and their ability to provide evidence-grade validation for non-human identity posture.</p><p>The strategy follows a phased approach to transition from discovery to autonomous maturity:</p><ol><li><p><strong>30 Days (Discovery &amp; Baseline):</strong> Establish a defensible inventory of the identity estate by mapping human, non-human (NHI), and AI agent identities across all hybrid surfaces.</p></li><li><p><strong>60 Days (Remediation &amp; Drift):</strong> Execute remediation for the top 10 material misconfigurations and operationalize real-time drift monitoring with reversible workflows.</p></li><li><p><strong>90 Days (Autonomous Maturity):</strong> Deploy autonomous remediation for low-risk vulnerabilities to reduce MTTR and formalize audit-grade reporting for compliance.</p><p></p></li></ol><h3><strong>CISOs Call to Action: The Pivot to Posture-to-Runtime Control</strong></h3><p>The transition to agentic systems requires moving beyond detection-only dashboards to an integrated Continuous Posture-to-Runtime Control model. CISOs must prioritize an Identity Control Plane that establishes a unified, closed-loop system where real-time posture risk directly informs deterministic, intent-aware authorization and ephemeral access enforcement. By enforcing Zero Standing Privilege and enforcing a watch and terminate runtime layer, organizations can ensure that trust is withdrawn the moment an identity, whether human or agent, drifts from its approved baseline. This shift is not just a security upgrade, it is a mandate to ensure that identity remains the primary control plane in an era of machine-speed autonomy.</p><p></p><h3>Key Conclusion</h3><p>Identity Security Posture Management must fundamentally evolve from a reactive, manual discipline into Agentic ISPM, a continuous, autonomous, closed-loop control system that translates static misconfiguration findings into active, measurable risk reduction. This report emphasizes that CISOs must shift from detection-only postures to Agentic ISPM to manage the massive scale of non-human identities (NHIs) and AI Agents. </p><p></p><div><hr></div><h3><em>Evidence &amp; Methodology</em></h3><p>The findings and claims presented in this report are rigorously derived from a synthesis of vendor briefings, practitioner inputs, direct customer signals, and deep-dive technical documentation to ensure adherence to SACR evidence quality requirements.</p><p><em><strong>Citations</strong></em></p><ol><li><p><a href="https://23579664.fs1.hubspotusercontent-na1.net/hubfs/23579664/Assets/EL-The-NHI-Secrets-Risk-Report-H1-2025.pdf">Entro Labs: The NHI Secrets Risk Report H1 2025</a> </p></li><li><p><a href="http://ttps://arxiv.org/abs/2601.07880">Sola-Visibility-ISPM: Benchmarking Agentic AI for Identity Security Posture Management Visibility</a> </p></li><li><p>Sola-Visibility-ISPM: Benchmarking Agentic AI for Identity Security Posture Management Visibility (<a href="https://arxiv.org/abs/2601.07880">https://arxiv.org/abs/2601.07880</a>)</p><p></p></li></ol><h4><em>SACR Independence &amp; Vendor Review</em></h4><p>This report reflects SACR analyst judgment. Participating vendors were invited to review for factual accuracy (e.g., feature availability, integration support, terminology). Vendors did not control conclusions, comparative framing, or market definitions. Vendor disagreements are documented where relevant; factual inaccuracies are corrected upon validation.</p><p>SACR maintains independent research objectivity. All vendor feedback is reviewed for factual accuracy, but vendor dissatisfaction regarding placement or methodology will not influence analyst conclusions, which remain strictly evidence-based and SACR-owned.</p><p></p><div><hr></div><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Software Analyst Cyber Research! Subscribe for free to receive new cybersecurity reports and analysis to support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/p/why-cisos-must-re-think-identity/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/p/why-cisos-must-re-think-identity/comments"><span>Leave a comment</span></a></p><div class="directMessage button" data-attrs="{&quot;userId&quot;:6770950,&quot;userName&quot;:&quot;SACR&quot;,&quot;canDm&quot;:null,&quot;dmUpgradeOptions&quot;:null,&quot;isEditorNode&quot;:true}" data-component-name="DirectMessageToDOM"></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&quot;,&quot;text&quot;:&quot;Share Software Analyst Cyber Research&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share Software Analyst Cyber Research</span></a></p><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/subscribe?"><span>Subscribe now</span></a></p>]]></content:encoded></item><item><title><![CDATA[Introducing a New Cloud Security Category: Agentic Cloud Security Platforms (ACSP)]]></title><description><![CDATA[The evolution from posture to runtime that defines the control layer CNAPP never built. What happens to cloud security when applications can act on their own?]]></description><link>https://softwareanalyst.substack.com/p/introducing-a-new-cloud-security</link><guid isPermaLink="false">https://softwareanalyst.substack.com/p/introducing-a-new-cloud-security</guid><dc:creator><![CDATA[Sean Sosnowski]]></dc:creator><pubDate>Thu, 11 Jun 2026 13:30:26 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!YGne!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89043476-7543-45e3-b10d-944ed2f6aa05_856x1210.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>New Category Definition From SACR</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!YGne!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89043476-7543-45e3-b10d-944ed2f6aa05_856x1210.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!YGne!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89043476-7543-45e3-b10d-944ed2f6aa05_856x1210.png 424w, https://substackcdn.com/image/fetch/$s_!YGne!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89043476-7543-45e3-b10d-944ed2f6aa05_856x1210.png 848w, https://substackcdn.com/image/fetch/$s_!YGne!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89043476-7543-45e3-b10d-944ed2f6aa05_856x1210.png 1272w, https://substackcdn.com/image/fetch/$s_!YGne!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89043476-7543-45e3-b10d-944ed2f6aa05_856x1210.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!YGne!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89043476-7543-45e3-b10d-944ed2f6aa05_856x1210.png" width="398" height="562.5934579439253" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/89043476-7543-45e3-b10d-944ed2f6aa05_856x1210.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1210,&quot;width&quot;:856,&quot;resizeWidth&quot;:398,&quot;bytes&quot;:835365,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://softwareanalyst.substack.com/i/201171391?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89043476-7543-45e3-b10d-944ed2f6aa05_856x1210.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!YGne!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89043476-7543-45e3-b10d-944ed2f6aa05_856x1210.png 424w, https://substackcdn.com/image/fetch/$s_!YGne!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89043476-7543-45e3-b10d-944ed2f6aa05_856x1210.png 848w, https://substackcdn.com/image/fetch/$s_!YGne!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89043476-7543-45e3-b10d-944ed2f6aa05_856x1210.png 1272w, https://substackcdn.com/image/fetch/$s_!YGne!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89043476-7543-45e3-b10d-944ed2f6aa05_856x1210.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">caption...</figcaption></figure></div><p>Every era of cloud security has been defined by the question it was built to answer.</p><p>When enterprises first moved to the cloud, the question was simple and urgent: what do we even have? CSPM was born, and for the first time, the cloud became legible. Compliance frameworks attached themselves to that visibility, and posture management became the anchor purchase of cloud security.</p><p>But knowing what exists is not the same as knowing what it is doing. As containers and rapid deployment reshaped the cloud, a resource could look perfectly configured while its workload was actively compromised. CWPP emerged to answer the second question: what is actually running, and is it dangerous? Then attackers taught the market a third lesson. The most reliable path through a cloud environment was rarely a missing patch. It was permissions. CIEM rose to answer the hardest question yet: who, or what, has the ability to take action?</p><p>By the early 2020s, buyers were drowning in the tools these three questions had produced. CNAPP was the market&#8217;s answer to that exhaustion: posture, workload, identity, IaC checks, vulnerability context, and compliance evidence converged into one platform with one data model and one prioritization layer. That consolidation was necessary, and it worked. It remains the foundation of every serious cloud security program today.</p><p>But the question defining the next era is different from every question that came before. Not what exists. Not what is running. Not who has access. The question is: can you make the correct security decision while the action is still in motion?</p><p>Today, SACR is publishing our deepest piece of cloud security research to date: <strong>Agentic Cloud Security Platforms: The Shift to Runtime Security</strong>, coauthored by Sean Sosnowski, and Lawrence Pingree. In it, we define ACSP, the runtime control layer that connects CNAPP evidence to governed execution decisions: whether a workload, API call, identity action, model interaction, or agentic tool invocation should proceed, be constrained, be remediated, or be escalated.</p><p>We partnered with Palo Alto Networks, which has licensed our research to make the full report free for everyone.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.paloaltonetworks.com/cortex/cloud/sacr-acsp-report&quot;,&quot;text&quot;:&quot;Full Report&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.paloaltonetworks.com/cortex/cloud/sacr-acsp-report"><span>Full Report</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HPIM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3613fa5c-909d-41c3-916e-63094cd48937_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HPIM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3613fa5c-909d-41c3-916e-63094cd48937_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!HPIM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3613fa5c-909d-41c3-916e-63094cd48937_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!HPIM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3613fa5c-909d-41c3-916e-63094cd48937_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!HPIM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3613fa5c-909d-41c3-916e-63094cd48937_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HPIM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3613fa5c-909d-41c3-916e-63094cd48937_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3613fa5c-909d-41c3-916e-63094cd48937_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:610266,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://softwareanalyst.substack.com/i/201171391?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3613fa5c-909d-41c3-916e-63094cd48937_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!HPIM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3613fa5c-909d-41c3-916e-63094cd48937_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!HPIM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3613fa5c-909d-41c3-916e-63094cd48937_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!HPIM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3613fa5c-909d-41c3-916e-63094cd48937_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!HPIM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3613fa5c-909d-41c3-916e-63094cd48937_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: center;"><em><sup>Names are included only to anchor the market landscape. They are not presented as a complete universe, a capability ranking, or a statement that each provider currently delivers the full ACSP model.</sup></em></p><h1></h1><div><hr></div><h2>Key Takeaways From The Report</h2><p>CNAPP remains the foundation for cloud security visibility; ACSP defines the runtime control layer that connects evidence to governed action while workloads, identities, APIs, data flows, and AI agents are still in motion.</p><p>Modern cloud security has matured around visibility, yet the operating gap is control. CNAPP unified posture management, workload protection, entitlement analysis, IaC checks, vulnerability context, and compliance evidence into one operating model. That convergence remains necessary. Its limit is architectural: many platforms still rely on periodic telemetry, API-derived state, delayed correlation, and human remediation queues while cloud workloads, identities, APIs, and AI-mediated actions change in seconds.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1sPw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47a4af2b-b4f1-4bd2-b75d-ff365d1df947_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1sPw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47a4af2b-b4f1-4bd2-b75d-ff365d1df947_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!1sPw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47a4af2b-b4f1-4bd2-b75d-ff365d1df947_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!1sPw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47a4af2b-b4f1-4bd2-b75d-ff365d1df947_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!1sPw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47a4af2b-b4f1-4bd2-b75d-ff365d1df947_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1sPw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47a4af2b-b4f1-4bd2-b75d-ff365d1df947_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/47a4af2b-b4f1-4bd2-b75d-ff365d1df947_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!1sPw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47a4af2b-b4f1-4bd2-b75d-ff365d1df947_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!1sPw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47a4af2b-b4f1-4bd2-b75d-ff365d1df947_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!1sPw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47a4af2b-b4f1-4bd2-b75d-ff365d1df947_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!1sPw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47a4af2b-b4f1-4bd2-b75d-ff365d1df947_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Agentic Cloud Security Platforms (ACSP) define the next control layer for this environment. An ACSP connects CNAPP evidence to live execution decisions: whether a workload, API call, identity action, model interaction, or agentic tool invocation should proceed, be constrained, be remediated, or be escalated. The category is anchored in runtime discovery, runtime exposure management, identity-aware decisioning, application and API control, AI workload security, pre-deployment guardrails, developer feedback loops, and audit-grade proof of actions and outcomes. For CISOs, the decision is whether current cloud security investments can preserve CNAPP&#8217;s visibility while proving active risk, governing live actions, and producing measurable reductions in exposure, investigation time, and recurring remediation work.</p><p></p><h2>Five Core Themes On Cloud Security:</h2><ol><li><p><strong>CNAPP solved fragmentation, not control. The distinction is architectural, not cosmetic.</strong> The real achievement of CNAPP was rationalizing posture and workload visibility. The center of gravity remained scans, snapshots, graph analysis, and remediation queues. Those mechanisms were built for governance and triage, not for adjudicating live execution. This tension was embedded in CNAPP from day one, and it is now the central fault line in the market. Our view is that the vendors who acknowledge this honestly will define the next phase, and the vendors who keep selling visibility as control will spend the next three years defending shrinking ground.</p></li><li><p><strong>Cloud security has moved through four generations, and most platforms are still architected for the first three.</strong> The first generation was posture, inventory, and compliance. Generation two added runtime and workload depth. Generation three elevated identity and entitlements as attack paths. Generation four is AI and agentic execution, in which agents take action with delegated permissions.</p></li><li><p><strong>We define five minimum conditions a platform must meet to qualify as ACSP.</strong> They must observe live execution paths across workloads, APIs, identities, data flows, and AI interactions; distinguish theoretical exposure from active, reachable, exploitable risk; apply identity-aware policy to human, machine, and agentic actions; execute governed intervention; and preserve audit-grade records of every decision. Miss one, and you have a better CNAPP, not an ACSP.</p></li><li><p><strong>Runtime exposure management replaces ranked risk lists.</strong> CNAPP became very good at producing prioritized exposure queues without proving whether anything on them was live. ACSP inverts the question: is this component loaded into memory, reachable through the application path, exercisable given current identity and network context, and connected to data that matters? If not, it gets deprioritized. </p></li><li><p><strong>Decisions require a four plane context graph, bound together by identity.</strong> Code and delivery provenance, cloud configuration and permissions, runtime behavior, and data context, with identity as the connective tissue, because every meaningful action is taken by a human, machine, service, or agent with some level of authority. </p><p></p></li></ol><p>The report also includes our market landscape across AI coding security, platforms, and AI runtime vendors, included to anchor the market, not as a ranking. The full report covers the complete framework, the incident analysis, and the CISO evaluation criteria.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.paloaltonetworks.com/cortex/cloud/sacr-acsp-report&quot;,&quot;text&quot;:&quot;Full ACSP Report&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.paloaltonetworks.com/cortex/cloud/sacr-acsp-report"><span>Full ACSP Report</span></a></p><div><hr></div><h1>Authors</h1><ul><li><p><a href="https://www.linkedin.com/in/seansosnowski/">Sean Sosnowski</a> serves as the Research Director for Security Operations and Cloud Security at SACR, where he leads research on SOC strategy and operations, detection engineering, and the evolving role of automation and agentic AI in security workflows. Drawing on a decade of intelligence experience in the U.S. Marine Corps he has authored several analytic reports on emerging technologies and threats regarding sensitive national security and military operations.</p></li><li><p><span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Lawrence Pingree&quot;,&quot;id&quot;:410694540,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!7mcY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88d3e854-fe08-423b-8688-dc494e0c3ad4_144x144.png&quot;,&quot;uuid&quot;:&quot;4163af3c-a659-4d22-8039-97278309b40a&quot;}" data-component-name="MentionToDOM"></span> is head of research at SACR, leading Data and AI Security research at SACR, where he covers data protection, AI security, and agentic security models. He brings almost 17 years of analyst experience from Gartner, 30 years in cybersecurity and has authored over 300 research notes across cloud security, endpoint defence, SD-WAN, and AI security</p></li></ul><div><hr></div><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/p/introducing-a-new-cloud-security?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/p/introducing-a-new-cloud-security?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Software Analyst Cyber Research! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&quot;,&quot;text&quot;:&quot;Share Software Analyst Cyber Research&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share Software Analyst Cyber Research</span></a></p><div class="directMessage button" data-attrs="{&quot;userId&quot;:6770950,&quot;userName&quot;:&quot;SACR&quot;,&quot;canDm&quot;:null,&quot;dmUpgradeOptions&quot;:null,&quot;isEditorNode&quot;:true}" data-component-name="DirectMessageToDOM"></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/p/introducing-a-new-cloud-security/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/p/introducing-a-new-cloud-security/comments"><span>Leave a comment</span></a></p><h1></h1>]]></content:encoded></item><item><title><![CDATA[The Evolution of Human Risk Management (HRM) Across Cybersecurity]]></title><description><![CDATA[The Evolution of Security Awareness into the broader Continuous Risk Management & How HRM Is Evolving In An Agentic Era]]></description><link>https://softwareanalyst.substack.com/p/the-evolution-of-human-risk-management</link><guid isPermaLink="false">https://softwareanalyst.substack.com/p/the-evolution-of-human-risk-management</guid><dc:creator><![CDATA[Sean Sosnowski]]></dc:creator><pubDate>Thu, 21 May 2026 17:50:48 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!qYWF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd886d33c-a659-4225-8e60-7c04c7e86743_1956x1034.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h1>Author</h1><ul><li><p><a href="mailto:sean@softwareanalyst.ca">Sean Sosnowski</a> serves as the Research Director for Security Operations and Cloud Security at SACR, where he leads research on SOC strategy and operations and detection engineering. Drawing on a decade of intelligence experience in the U.S. Marine Corps.</p></li></ul><p></p><div><hr></div><h1>Executive Summary</h1><p>Human Risk Management (HRM) is undergoing a fundamental rewrite as the security environment shifts from periodic threats to continuous, AI-driven exposure. Traditional programs focused on annual training are no longer sufficient against adversaries using AI to increase the scale and plausibility of social engineering. The unit of risk has evolved to include machine-assisted work, where exposure resides at the intersection of human judgment and delegated actions through assistants and automation.</p><p>This is the first official coverage of the new category for <strong>Human Risk Management (HRM) for SACR.  </strong>The ecosystem map below illustrates how the market is converging across several previously disconnected domains. Traditional security awareness vendors continue to provide workforce engagement and simulation capabilities, while a newer generation of HRM platforms is building continuous measurement, contextual scoring, and operational response layers on top of those foundations. At the same time, adjacent categories, including email security, insider risk, identity governance, DLP, and non-human identity security, are increasingly intersecting with HRM as organizations attempt to operationalize people-linked exposure reduction.</p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!qYWF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd886d33c-a659-4225-8e60-7c04c7e86743_1956x1034.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!qYWF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd886d33c-a659-4225-8e60-7c04c7e86743_1956x1034.png 424w, https://substackcdn.com/image/fetch/$s_!qYWF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd886d33c-a659-4225-8e60-7c04c7e86743_1956x1034.png 848w, https://substackcdn.com/image/fetch/$s_!qYWF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd886d33c-a659-4225-8e60-7c04c7e86743_1956x1034.png 1272w, https://substackcdn.com/image/fetch/$s_!qYWF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd886d33c-a659-4225-8e60-7c04c7e86743_1956x1034.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!qYWF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd886d33c-a659-4225-8e60-7c04c7e86743_1956x1034.png" width="1456" height="770" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d886d33c-a659-4225-8e60-7c04c7e86743_1956x1034.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:770,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1922674,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://softwareanalyst.substack.com/i/198728564?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd886d33c-a659-4225-8e60-7c04c7e86743_1956x1034.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!qYWF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd886d33c-a659-4225-8e60-7c04c7e86743_1956x1034.png 424w, https://substackcdn.com/image/fetch/$s_!qYWF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd886d33c-a659-4225-8e60-7c04c7e86743_1956x1034.png 848w, https://substackcdn.com/image/fetch/$s_!qYWF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd886d33c-a659-4225-8e60-7c04c7e86743_1956x1034.png 1272w, https://substackcdn.com/image/fetch/$s_!qYWF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd886d33c-a659-4225-8e60-7c04c7e86743_1956x1034.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The market is also beginning to expand rapidly. This shift broadens the definition of human risk beyond employee behaviour alone and moves the category toward managing the combined exposure created by humans and agents working together. </p><p>This report examines Human Risk Management as an emerging security category rather than a single product segment. The ecosystem map should therefore be viewed as a framework for understanding the broader market direction, competitive landscape, and capability evolution shaping the future of people-centric cybersecurity operations.</p><p></p><p>Modern HRM is defined as the continuous practice of identifying, measuring, and reducing cyber risk across both human behavior and supervised workflows. Unlike the legacy model, which relied on calendar-based activity and simple click rates, the modern approach utilizes a capability stack built on contextual measurement and targeted intervention. By pulling telemetry from identity, behavior, and tool usage, organizations can generate precise risk scores that drive automated coaching or control changes. This new model incorporates agent visibility to govern the autonomy granted to AI tools, ensuring security teams can manage people-linked exposure in real-time.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QEeY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2359f738-0a1c-4500-b464-8f8569ce0802_1964x1012.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QEeY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2359f738-0a1c-4500-b464-8f8569ce0802_1964x1012.png 424w, https://substackcdn.com/image/fetch/$s_!QEeY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2359f738-0a1c-4500-b464-8f8569ce0802_1964x1012.png 848w, https://substackcdn.com/image/fetch/$s_!QEeY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2359f738-0a1c-4500-b464-8f8569ce0802_1964x1012.png 1272w, https://substackcdn.com/image/fetch/$s_!QEeY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2359f738-0a1c-4500-b464-8f8569ce0802_1964x1012.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QEeY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2359f738-0a1c-4500-b464-8f8569ce0802_1964x1012.png" width="1456" height="750" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2359f738-0a1c-4500-b464-8f8569ce0802_1964x1012.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:750,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:251488,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://softwareanalyst.substack.com/i/198728564?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2359f738-0a1c-4500-b464-8f8569ce0802_1964x1012.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!QEeY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2359f738-0a1c-4500-b464-8f8569ce0802_1964x1012.png 424w, https://substackcdn.com/image/fetch/$s_!QEeY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2359f738-0a1c-4500-b464-8f8569ce0802_1964x1012.png 848w, https://substackcdn.com/image/fetch/$s_!QEeY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2359f738-0a1c-4500-b464-8f8569ce0802_1964x1012.png 1272w, https://substackcdn.com/image/fetch/$s_!QEeY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2359f738-0a1c-4500-b464-8f8569ce0802_1964x1012.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>That creates the report&#8217;s practical standard: mature HRM programs should be evaluated by the quality of the human-risk model, the governance around intervention, and the ability to show exposure reduction over time. A platform that can generate training content or summarize campaign results is one part of the category. The stronger test is whether the program can connect people, workflows, and delegated action to explainable, proportionate decisions that security teams can defend. We explore <a href="http://cimento.ai">Cimento.ai</a> as one example of this market direction, where an awareness and simulation entry point extends toward contextual scoring, multi-turn testing, and governed response.</p><p><em>Disclosure: Cimento sponsored and collaborated on portions of this research paper, including product briefings, market discussions, and access to company perspectives used as part of the analysis. While Cimento provided financial support for the development of this report and served as a case-study participant, the research, market framing, analysis, conclusions, and opinions expressed in this paper are solely those of the authors. The report was designed to provide an independent view of the evolving Human Risk Management market, including broader industry trends, competitive dynamics, and category developments beyond any single vendor.</em></p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Software Analyst Cyber Research! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><h1>Why Human Risk Management Is Being Rewritten</h1><p>Human Risk Management is being rewritten because the human decision point has changed. For years, the category was organized around a relatively bounded model: employees received periodic education, completed simulations, and were measured through training or click-based indicators. That model matched a narrower view of exposure. Today, the risk forms around live decisions made across channels, roles, workflows, and automated systems.</p><p>The first pressure is the expansion of social engineering into the normal fabric of work. Attacks now move through email, chat, SMS, voice, collaboration tools, and other channels employees use to make daily decisions. The risk is shaped by timing and context: a finance approval, a help-desk request, an executive instruction, or a workflow exception. This makes periodic simulation a weaker proxy for the conditions employees actually face.</p><p>AI intensifies that shift by making deception more plausible and easier to personalize. Attackers can produce messages that fit a person&#8217;s role, authority, current responsibilities, and expected communication style. The visible markers that once helped users identify suspicious messages become less reliable. The security question moves closer to judgment under pressure: whether the employee can interpret intent, context, and consequence in the moment.</p><p>At the same time, daily work is becoming more delegated. Employees increasingly rely on copilots, inbox assistants, workflow automation, and other tools that summarize information, draft responses, route decisions, or trigger actions. Human risk now extends into the systems acting around the user. Exposure depends on what the person can access, what the tool can do, and how much trust the employee places in the output or recommended action.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!43XN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ba164ae-d080-4707-90e2-37457b86d153_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!43XN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ba164ae-d080-4707-90e2-37457b86d153_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!43XN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ba164ae-d080-4707-90e2-37457b86d153_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!43XN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ba164ae-d080-4707-90e2-37457b86d153_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!43XN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ba164ae-d080-4707-90e2-37457b86d153_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!43XN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ba164ae-d080-4707-90e2-37457b86d153_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0ba164ae-d080-4707-90e2-37457b86d153_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!43XN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ba164ae-d080-4707-90e2-37457b86d153_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!43XN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ba164ae-d080-4707-90e2-37457b86d153_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!43XN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ba164ae-d080-4707-90e2-37457b86d153_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!43XN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ba164ae-d080-4707-90e2-37457b86d153_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This is the catalyst for redefining the category. Human Risk Management has to account for people, permissions, workflows, channels, and delegated action as one connected risk surface. The category is moving toward continuous analysis of where exposure concentrates, how behavior changes under realistic conditions, and what interventions reduce risk before a human-linked decision becomes an operational failure.</p><h1>Defining Human Risk Management in the AI Era</h1><p>Human Risk Management is the continuous practice of identifying, measuring, and reducing cyber risk arising from human behavior, susceptibility, judgment, and decision-making across the workforce. In an AI-shaped environment, this scope includes the machine-assisted and delegated actions employees initiate, configure, or supervise. The category provides security teams with a framework to make people-linked exposure measurable, comparable, and manageable over time.</p><p>Agent risk belongs inside Human Risk Management when the exposure traces back to employee sponsorship, granted permissions, supervision, or risky delegated behavior. A user who connects an assistant to sensitive data, authorizes a workflow, or relies on automated output during a high-impact decision is creating human-linked exposure through delegated action. Adjacent domains still own model controls, application security, data governance, identity lifecycle, and infrastructure policy. HRM supplies the behavioral and workflow context that shows where human judgment activates or amplifies those risks.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5soZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecd79993-7cd1-4cd0-af7b-756d4ea7cf71_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5soZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecd79993-7cd1-4cd0-af7b-756d4ea7cf71_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!5soZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecd79993-7cd1-4cd0-af7b-756d4ea7cf71_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!5soZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecd79993-7cd1-4cd0-af7b-756d4ea7cf71_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!5soZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecd79993-7cd1-4cd0-af7b-756d4ea7cf71_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5soZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecd79993-7cd1-4cd0-af7b-756d4ea7cf71_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ecd79993-7cd1-4cd0-af7b-756d4ea7cf71_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!5soZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecd79993-7cd1-4cd0-af7b-756d4ea7cf71_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!5soZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecd79993-7cd1-4cd0-af7b-756d4ea7cf71_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!5soZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecd79993-7cd1-4cd0-af7b-756d4ea7cf71_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!5soZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecd79993-7cd1-4cd0-af7b-756d4ea7cf71_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Its core capability set combines learning, simulation, contextual measurement, and remediation into a continuous loop. Signals from user behavior and operating context feed a risk model, which in turn informs coaching, realistic testing, or light friction. These resulting actions reduce exposure and generate new evidence about behavioral changes, with training remaining a foundational element of the cycle.</p><p>This definition provides usable boundaries by distinguishing it from adjacent disciplines. While insider risk management focuses on harmful activity by trusted users and workforce identity supplies access context, Human Risk Management serves a specific operating purpose: the continuous reduction of cyber exposure created or activated by people during everyday work.</p><p>Ultimately, a platform belongs in this category when its primary purpose is to continuously measure and reduce risk arising from people and their supervised workflows. This includes social engineering defense and agent risk, where human judgment leads to machine action. By participating in a broader measurement-to-intervention loop, the category creates a clear center of gravity for managing modern people-linked exposure.</p><h1>The Legacy Model</h1><p>The legacy model of human risk management emerged from a practical enterprise need to educate large populations consistently, document program activity, and raise the baseline level of security awareness across the workforce. Awareness training, policy reinforcement, and phishing simulations gave security teams a repeatable program structure. Leaders could report coverage, show evidence of participation, and demonstrate that the human layer was receiving attention. In many organizations, that model created the first durable operating system for people-focused security.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!UNC6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88f2d071-6b23-4c62-97c3-05f292264c77_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!UNC6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88f2d071-6b23-4c62-97c3-05f292264c77_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!UNC6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88f2d071-6b23-4c62-97c3-05f292264c77_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!UNC6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88f2d071-6b23-4c62-97c3-05f292264c77_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!UNC6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88f2d071-6b23-4c62-97c3-05f292264c77_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!UNC6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88f2d071-6b23-4c62-97c3-05f292264c77_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/88f2d071-6b23-4c62-97c3-05f292264c77_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!UNC6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88f2d071-6b23-4c62-97c3-05f292264c77_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!UNC6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88f2d071-6b23-4c62-97c3-05f292264c77_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!UNC6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88f2d071-6b23-4c62-97c3-05f292264c77_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!UNC6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88f2d071-6b23-4c62-97c3-05f292264c77_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Its operating logic was built around a calendar. Training arrived on an annual or quarterly cadence. Simulations were launched as discrete campaigns. Measurement centered on completions, click rates, and reporting rates. That structure made the program easy to administer and easy to explain. It also meant that activity was measured more precisely than exposure. A team could identify who finished a module or failed a test. It had a thinner view into which users were becoming riskier, which roles were more exposed, or which workflows carried the greatest leverage for an attacker.</p><p>The model also reflected the threat assumptions of its time. Email sat at the center of the attack surface, and the risky event was usually framed as a single moment: a click, a credential submission, or a failure to report. Users were often grouped into broad segments, with limited adaptation to role, privilege, or current operating context. When someone failed, the default response was another training assignment or another simulation. That approach supported broad coverage, but it produced limited insight into changing conditions around the user.</p><p>Those limits are more visible now because the environment around employees has changed. Communication happens across several channels. Work increasingly moves through collaboration tools, SaaS workflows, and AI-mediated tasks. High-risk behavior often becomes clear only when multiple signals are considered together. The legacy model still contributes value as a foundation for awareness and reinforcement. Its center of gravity sits in periodic program management, while the category itself is moving toward continuous risk management.</p><p>The practical migration path starts by preserving what the legacy model already does well: compliance evidence, baseline education, reporting culture, and a repeatable program cadence. The next layer adds role-aware simulation, continuous signal collection, dynamic risk grouping, and handoffs into the controls that already govern access, messaging, data movement, and workflow execution. Success metrics should also move from activity alone toward repeat-risk reduction, reporting speed, high-risk workflow coverage, and evidence that intervention is reducing exposure without adding broad friction.</p><h1>How AI Changes Human Risk Management</h1><p>AI changes human risk management in two connected ways. It improves attacker economics, and it changes how employees make decisions. Attackers can generate convincing language quickly, imitate tone with greater accuracy, and tailor lures with far less manual effort. Social engineering can now move across email, chat, and voice with a higher level of consistency. The underlying threats remain phishing, impersonation, coercion, and misuse: AI changes their scale, speed, and realism.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_uNX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F572612d7-4c15-40f1-8d8d-3b95ead036e5_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_uNX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F572612d7-4c15-40f1-8d8d-3b95ead036e5_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!_uNX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F572612d7-4c15-40f1-8d8d-3b95ead036e5_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!_uNX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F572612d7-4c15-40f1-8d8d-3b95ead036e5_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!_uNX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F572612d7-4c15-40f1-8d8d-3b95ead036e5_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_uNX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F572612d7-4c15-40f1-8d8d-3b95ead036e5_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/572612d7-4c15-40f1-8d8d-3b95ead036e5_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!_uNX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F572612d7-4c15-40f1-8d8d-3b95ead036e5_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!_uNX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F572612d7-4c15-40f1-8d8d-3b95ead036e5_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!_uNX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F572612d7-4c15-40f1-8d8d-3b95ead036e5_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!_uNX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F572612d7-4c15-40f1-8d8d-3b95ead036e5_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>At the same time, employees increasingly work through systems that summarize messages, draft responses, retrieve information, and initiate actions. That changes the shape of the decision itself. A suspicious request may be interpreted first by an assistant. A response may be drafted before a user slows down to verify context. A workflow may execute with only light supervision once the user decides to trust the tool. The security-relevant event therefore extends beyond a single human act and begins to include the software layer that mediates attention, judgment, and execution.</p><p>This shift changes the unit of analysis for the category. Security teams now need to understand the person, the workflow, and the delegated action as one system of exposure. A periodic awareness cadence does not provide a current view of that system in motion. Risk now depends on role, access, recent behavior, tool usage, and the quality of oversight around automated tasks. Those variables change continuously. Continuous measurement and targeted intervention become more important because the conditions of risk are moving every day.</p><p>An HRM system becomes useful when it can interpret a small set of events in context. A finance approver receiving a late-stage payment request during a reporting window, a help-desk operator facing account recovery pressure, and an employee connecting an assistant to sensitive data all create different risk patterns. The common requirement is to combine behavior, role, access, and workflow context before deciding whether the right response is coaching, simulation, approval review, or a control change.</p><p>Agent risk enters here as an extension of human risk, especially when delegated action carries real authority. Employees choose which assistants to use, connect them to internal data, grant permissions, define tasks, and decide how much autonomy to allow. The agent acts with the context and authority provided by its human sponsor. That relationship keeps human judgment at the center of the problem. Some of the new exposure comes from approved copilots. Some comes from improvised shadow automation launched by employees trying to move faster. In both cases, the delegated behavior inherits human choices about trust, access, and supervision.</p><p>AI expands the category into new workflows while preserving its core logic. The central question is still how people create, amplify, or reduce enterprise exposure. The difference is that those outcomes now unfold through a blended system of human decisions and machine-assisted action. Human Risk Management has to account for that blended system if it is going to remain operationally useful.</p><h1>The Modern Capability Stack of Human Risk Management</h1><p>The modern capability stack begins with awareness and training, though their role is now more specific. Training remains essential because organizations still need shared language, secure habits, and reinforcement at scale. In the modern model, training becomes one intervention layer inside a broader operating system. The goal is to improve decisions at the moment of risk and measure whether exposure is actually falling over time. Simulation evolves with that goal. Single-message phishing tests give way to role-aware, multi-turn scenarios that better reflect how real attacks build credibility and pressure across several touches.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!WcGR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c9fb253-16c7-4e33-95a8-615b7f2a182b_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!WcGR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c9fb253-16c7-4e33-95a8-615b7f2a182b_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!WcGR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c9fb253-16c7-4e33-95a8-615b7f2a182b_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!WcGR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c9fb253-16c7-4e33-95a8-615b7f2a182b_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!WcGR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c9fb253-16c7-4e33-95a8-615b7f2a182b_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!WcGR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c9fb253-16c7-4e33-95a8-615b7f2a182b_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5c9fb253-16c7-4e33-95a8-615b7f2a182b_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!WcGR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c9fb253-16c7-4e33-95a8-615b7f2a182b_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!WcGR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c9fb253-16c7-4e33-95a8-615b7f2a182b_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!WcGR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c9fb253-16c7-4e33-95a8-615b7f2a182b_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!WcGR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c9fb253-16c7-4e33-95a8-615b7f2a182b_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>A stronger operating model also requires a richer signal base. Useful platforms pull selective telemetry from training outcomes, reporting behavior, identity context, endpoint or MDM data, and related workflow signals. The goal is to assemble enough context to explain why a person or group is exposed. A finance leader during a sensitive reporting window, a new engineer with fresh access, and an employee using ungoverned automation tools each present a different risk profile even when surface behavior appears similar. The quality of the model depends on how well those contextual differences are captured.</p><p>Contextual risk scoring becomes the operating center of the stack. A useful score needs to reflect the company, the role, the environment, and the moment. The same behavior can indicate elevated risk in one organization and routine work in another. That makes generic scoring less useful than a model grounded in company-specific context and first-party outcomes. In practice, the score becomes the mechanism that turns fragmented signals into a living picture of who is most exposed, who is becoming riskier, and which delegated workflows need closer supervision.</p><p>A human-risk score becomes operationally useful when it can be explained, calibrated, and challenged. Security teams need to understand which signals contribute to the score, how role and privilege change the interpretation, how false positives are reviewed, and how privacy-sensitive inputs are governed. The score also needs evidence of outcome value: users or groups placed into an intervention path should show measurable improvement, reduced repeat exposure, or a clearer control decision than the organization could have made from campaign metrics alone.</p><p>Once that picture exists, the stack has to drive action. Risk insight should determine who gets targeted coaching, who enters a more realistic simulation path, and which cases move into operational review. Some outcomes remain inside the platform as guidance, nudges, or reporting prompts. Others should flow into identity, IT, or data protection systems as suggested control changes, approval steps, or restricted workflow paths. Human review remains important for higher-impact responses such as access changes or workflow restrictions, because operational trust matters alongside automation speed.</p><p>Agent visibility extends the same stack into delegated execution. As assistants and agents become ordinary parts of work, the platform needs to map which employees are using them, what permissions those tools hold, and which workflows carry meaningful business impact. That visibility supports an agent-aware risk model grounded in the sponsoring human, the delegated task, and the authority behind that task. The result is a modern human risk management function that continuously measures behavioral exposure, adapts intervention to context, and governs delegated action before it turns into incident response.</p><h2>Automated Remediation &amp; Adaptive Control</h2><p>Automated remediation is the point where the modern human risk model becomes operational. The value of a risk score increases when it places a person, group, or workflow into the right response path using current evidence, business context, and the potential impact of the action. The goal is to reduce exposure while keeping everyday work usable for employees and teams without evidence of elevated risk.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!iisL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaecb800-1824-4b83-ac1a-120e438047a5_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!iisL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaecb800-1824-4b83-ac1a-120e438047a5_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!iisL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaecb800-1824-4b83-ac1a-120e438047a5_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!iisL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaecb800-1824-4b83-ac1a-120e438047a5_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!iisL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaecb800-1824-4b83-ac1a-120e438047a5_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!iisL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaecb800-1824-4b83-ac1a-120e438047a5_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/caecb800-1824-4b83-ac1a-120e438047a5_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!iisL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaecb800-1824-4b83-ac1a-120e438047a5_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!iisL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaecb800-1824-4b83-ac1a-120e438047a5_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!iisL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaecb800-1824-4b83-ac1a-120e438047a5_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!iisL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaecb800-1824-4b83-ac1a-120e438047a5_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The first remediation layer is behavioral correction. When a user repeatedly clicks on simulated or real phishing attempts, misses training expectations, mishandles malware warnings, or creates a data-handling concern, the response should be timely and specific. A short nudge, targeted training assignment, reporting prompt, or scenario-specific explanation is more useful when it arrives close to the event that created the signal. These interventions should be adjustable by channel and behavior so the program can reinforce the relevant decision and preserve a lower-friction baseline for the rest of the workforce.</p><p>The stronger pattern is dynamic risk grouping. Security teams can define criteria using risk scores, repeated events, role sensitivity, privilege, current attack exposure, or other context that matters in their environment. Users then move into or out of groups as new evidence arrives. This makes remediation adaptive and reversible. A user whose behavior improves can return to a lower-friction path, while a user whose risk increases can receive more coaching, additional review, or stronger control treatment. The operating benefit is that the response state follows current behavior, reducing reliance on static lists or repeated manual updates.</p><p>Those dynamic groups can also drive downstream controls. A higher-risk group may receive stricter email inspection, more prominent prompts, additional data-movement restrictions, identity-driven step-up requirements, or closer review in related security tools. The important shift is that the human-risk model becomes a policy signal for systems that already govern messages, access, data movement, endpoints, and workflow execution. This allows the organization to use existing controls more selectively. Heavy friction can be concentrated where current evidence supports it, while lower-risk users continue to work under a normal control posture.</p><p>Automated remediation needs governance because the response can affect employee trust, business continuity, and legal or privacy boundaries. Low-impact actions such as nudges, short training, or reminders can usually run automatically once the rule is approved. Medium-impact actions may require predefined policy paths, such as adding a user to a temporary group or increasing inspection for a limited period. Higher-impact actions, including access restriction, workflow blocking, or data-movement enforcement, should preserve human review, auditability, and a clear rollback path. The platform should explain which evidence triggered the response, who owns the decision, and what condition returns the user or workflow to a lower-friction state.</p><p>Governance should also define decision rights by response impact. Low-impact actions such as nudges, short coaching, or reminders can run automatically once the policy has been approved. Medium-impact actions such as temporary group movement, increased inspection, or additional review should have an owner, an expiration condition, and an audit trail. High-impact actions such as access restriction, workflow blocking, or data-movement enforcement should require security, identity, HR or legal, and business-owner review because those decisions affect trust, continuity, and accountability.</p><p>The same logic extends into AI-assisted and delegated work. If an employee launches an unsanctioned assistant, grants broad permissions to a workflow tool, or connects automation to sensitive data, the response can begin with guidance and registration requirements before moving into approval steps or permission changes. In this setting, remediation governs the relationship between the person, the delegated task, and the authority behind that task. It gives the organization a way to act before human risk turns into incident response.</p><p>Automated remediation is, therefore, a test of whether Human Risk Management can convert visibility into measurable reduction. The mature program needs a feedback loop that shows whether nudges changed behavior, whether risk groups shrank or stabilized, whether downstream controls reduced exposure, and whether friction stayed proportional to the risk. That evidence keeps remediation tied to outcomes and gives security leaders a practical way to manage human-linked exposure as a live operating variable.</p><p>Automated remediation is a test of whether Human Risk Management can convert visibility into measurable reduction. Mature programs should track whether high-risk groups shrink or stabilize, whether repeated risky behavior falls by role or workflow, whether users report suspicious activity faster, and whether downstream actions are reversed because the original signal was weak. They should also measure business friction and employee-impacting errors. That evidence keeps remediation tied to outcomes and gives security leaders a practical way to manage human-linked exposure as a live operating variable.</p><h1>Human Risk Market Landscape</h1><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1SVI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83abf012-5201-4e42-9466-453ee1194977_1994x1112.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1SVI!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83abf012-5201-4e42-9466-453ee1194977_1994x1112.png 424w, https://substackcdn.com/image/fetch/$s_!1SVI!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83abf012-5201-4e42-9466-453ee1194977_1994x1112.png 848w, https://substackcdn.com/image/fetch/$s_!1SVI!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83abf012-5201-4e42-9466-453ee1194977_1994x1112.png 1272w, https://substackcdn.com/image/fetch/$s_!1SVI!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83abf012-5201-4e42-9466-453ee1194977_1994x1112.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1SVI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83abf012-5201-4e42-9466-453ee1194977_1994x1112.png" width="1456" height="812" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/83abf012-5201-4e42-9466-453ee1194977_1994x1112.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:812,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2116656,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://softwareanalyst.substack.com/i/198728564?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83abf012-5201-4e42-9466-453ee1194977_1994x1112.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!1SVI!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83abf012-5201-4e42-9466-453ee1194977_1994x1112.png 424w, https://substackcdn.com/image/fetch/$s_!1SVI!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83abf012-5201-4e42-9466-453ee1194977_1994x1112.png 848w, https://substackcdn.com/image/fetch/$s_!1SVI!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83abf012-5201-4e42-9466-453ee1194977_1994x1112.png 1272w, https://substackcdn.com/image/fetch/$s_!1SVI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83abf012-5201-4e42-9466-453ee1194977_1994x1112.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>The Human Risk Management market is forming around a broader operating problem than whether employees complete training or click simulated phish. Security teams increasingly need to translate evidence about people, workflows, permissions, and delegated actions into decisions that reduce exposure. The accompanying market map should therefore be read less as a vendor directory and more as a maturity model: engagement creates behavioral surface area, measurement makes it visible, realistic testing improves signal quality, control linkage turns signal into intervention, and delegated action extends the model to agents, service accounts, automations, and workflows acting on a user&#8217;s behalf.</p><ol><li><p>The first layer is engagement and awareness. This remains the most familiar entry point because it gives security teams reach across the workforce through training, nudges, reporting behavior, microlearning, and phishing education. KnowBe4 represents the established scale of the category, while vendors such as Hoxhunt, SoSafe, and CybSafe show the shift toward adaptive engagement and behavior-aware learning. The limitation is that engagement alone can overstate progress when completion rates or click metrics become the main proxy for exposure reduction.</p><p></p></li><li><p>The second layer is human risk intelligence. This layer converts behavioral, organizational, and security telemetry into a risk model that can explain where exposure is concentrated and why it is changing. OutThink, Living Security, Mimecast, Proofpoint, Frame Security, and Cimento illustrate different paths toward quantified human-risk posture, from behavior analytics and real threat exposure to contextual scoring and remediation. The value is prioritization across users, teams, and workflows. The limitation is that measurement remains descriptive unless it can drive intervention.</p><p></p></li><li><p>The third layer is realistic testing and simulation. Social engineering increasingly depends on timing, repetition, impersonation, channel movement, and workflow pressure, so simulation has to move closer to business-process realism. Cofense, Proofpoint, Hoxhunt, Frame Security, and Cimento represent different approaches to testing human exposure through phishing, reporting workflows, role-aware scenarios, deepfake-style pressure, or multi-channel simulation. The goal is to understand how people respond when an attack looks like normal work.</p><p></p></li><li><p>The fourth layer is control linkage and response. HRM becomes operational when a risk signal can inform coaching, access review, escalation, policy adjustment, email-security action, data-security response, identity governance, or another proportionate control. Mimecast and Proofpoint are important examples because their human-risk offerings can connect awareness, email security, real phishing exposure, and insider-risk signals. Microsoft, Okta, SailPoint, and CyberArk sit at the edge of this layer as control-plane adjacencies. They supply enforcement paths when human-risk evidence needs to affect permissions, conditional access, privileged access, or workflow controls.</p></li><li><p>The fifth layer is delegated action and agent governance. As employees use copilots, assistants, service accounts, AI agents, and workflow automation, human risk extends into systems acting around or on behalf of the user. This layer is relevant where automated action can be traced back to a human owner, sponsor, approval, or delegated authority. Microsoft Entra Agent ID and SailPoint show how major identity platforms are beginning to treat agents as governable identities, while specialists such as Astrix, Oasis, Entro, and Clutch illustrate the emerging non-human identity control surface. The specific boundary boundary is relevant to the map only where automated action connects to human accountability and exposure reduction.</p></li></ol><p></p><p>The existing vendor landscape reflects different starting points into the same control problem. Awareness vendors begin with behavior change. Email-security and phishing-response vendors begin with the threat path where human exposure most often materializes. Identity, access, and non-human identity vendors begin with what a person, account, service, or delegated workflow is allowed to do. The strategic center of HRM is the connection between these views. A mature program should be able to explain which human-linked exposures matter, test them realistically, and trigger responses that are proportional to the risk.</p><p>This makes operating depth the practical market question. Basic offerings administer content, run simulations, and report outcomes. More advanced offerings combine behavioral context, risk scoring, realistic simulation, workflow-aware intervention, and control handoffs. The category direction is a capability model that connects evidence about people, workflows, permissions, and delegated action to decisions that reduce exposure over time.</p><p>Cimento should be read against that map as an emerging connective-layer example. Its entry point is the familiar awareness and phishing workflow, but its category relevance comes from using those workflows as signal sources for contextual scoring, multi-channel simulation, and governed response. In the market map, Cimento sits between engagement, human risk intelligence, realistic testing, and control linkage, with delegated-action and agent-risk governance as the forward edge of the thesis. The opportunity is the operating loop that turns human, workflow, permission, and delegated-action context into exposure reduction.</p><h1>Case Study Vendor: Cimento</h1><p>The following profile should be read as one example of this broader category direction. It illustrates how a vendor can start from a familiar awareness and phishing budget line, then move toward risk intelligence, contextual scoring, realistic simulation, and governed response. The profile frames one emerging path through a fragmented landscape where buyers are trying to connect human behavior, workflow context, and delegated action into an operating model for exposure reduction.</p><h2>Overview</h2><p>This report&#8217;s core argument is that Human Risk Management is becoming a continuous security function centered on measurement, contextual scoring, realistic simulation, and operational response. Cimento is relevant to that thesis because it starts in a familiar security awareness and phishing budget line, then uses that wedge to build a broader human risk intelligence layer.</p><p>Cimento&#8217;s positioning centers on multi-channel phishing tests, behavior-based risk measurement, and personalized training that adapts to employee behavior. Training is the entry point, while the strategic product is a unified human risk score that can absorb first-party outcomes, role context, security tool signals, and company-specific risk conditions, including AI agent and human behavior. In that model, the platform becomes a continuously updated view of which employees, teams, workflows, and Agents carry elevated exposure.</p><p>The company is especially useful as a profile in this report because it shows how the category can expand while preserving its practical buyer entry point. Security teams still need training, phishing simulations, compliance evidence, and user reporting. Cimento&#8217;s bet is that those workflows can become the data foundation for a more operational system: targeted simulation, adaptive coaching, risk-based review, permission and access remediation, and eventually agent-aware human risk governance.</p><h2>Product &amp; Architecture</h2><p>Cimento&#8217;s operating model can be summarized as a loop: integrate, test, train, and translate risk into action. The platform connects to HRIS, SIEM, MDM, identity, and related security systems to understand employee context. It then runs phishing simulations across email, SMS, voice, and related channels, measures behavior in those interactions, and adapts short training or coaching to the user and scenario.</p><p>The risk score is the center of the architecture. Real-time scoring that goes beyond clicks by tracking decisions, response times, reporting behavior, role context, and access level. The score is open, company-contextual, and grounded in both first-party simulation outcomes and embedded security integrations. A finance executive during an earnings period, a departing employee with sensitive access, and an engineer adopting AI tools can carry different risks even when their surface behavior appears similar.</p><p>Cimento&#8217;s most distinctive near-term product idea is multi-turn simulation. Traditional phishing programs usually test a single message or a single action. Cimento is building simulations that unfold across several user touch points and channels, with the campaign adapting based on whether a user reports, ignores, engages, or escalates. That makes the test closer to modern social engineering, where attackers build credibility over time and use multiple channels to increase pressure.</p><p>The next layer is response orchestration. Cimento&#8217;s narrative positions the platform as a governable recommendation layer: surface the risky user or workflow, recommend a configuration change, and let the security team approve the next step. That could include suggested changes in identity, ITSM, DLP/CASB, remote access, or similar downstream controls. The important architectural move is the handoff from user-risk evidence to operational control, with human review preserved for consequential action.</p><p>Cimento&#8217;s agent-risk story extends the same model into delegated execution. In the company&#8217;s framing, agents inherit risk from the human who launches, connects, supervises, and authorizes them. The roadmap includes an agent registry that maps tools back to employee sponsors, agent permissions, and the composite risk profile created by the human, plus the agent&#8217;s access surface. Agent-to-agent social engineering simulation remains earlier-stage, while the human-sponsored model fits the report&#8217;s broader view that agent exposure often starts as a human risk problem.</p><h2>Human Risk Narrative</h2><p>Cimento maps to the report&#8217;s argument in three ways.</p><p>First, it treats training and phishing as a data acquisition layer. The company can enter through a known budget category, then use every training assignment, simulation result, report, and risky interaction as evidence for a more useful risk model. That is the category shift in miniature: the campaign becomes a signal source, while the persistent risk state becomes the operating object.</p><p>Second, it makes simulation more realistic. AI has improved attacker economics, and social engineering increasingly works through timing, context, and multiple touches. Cimento&#8217;s multi-turn model aligns testing with that reality by measuring behavior across a sequence and treating susceptibility as a pattern that forms over time. This matters because the modern HRM stack needs to evaluate decision-making under pressure, across channels, and over time.</p><p>Third, it links human risk to downstream control decisions. A high-risk score has limited operational value if the next action is another generic training assignment. Cimento&#8217;s roadmap points toward risk-based recommendations that can flow into identity, data protection, access, and security operations workflows. That is where the category begins to extend from program administration into continuous risk management.</p><p>The agent extension is strategically important because it keeps the human sponsor visible. Microsoft and other platform providers are moving toward explicit agent identity, lifecycle, access, and sponsorship models. Cimento&#8217;s version approaches the problem from the employee side: understand the human, map the tools they use, classify the agent&#8217;s permission surface, and apply simulation or review where the combined exposure is highest.</p><h2>Product and Technical Notes</h2><p>The current product appears closest to next-generation security awareness and phishing simulation, with a broader risk intelligence roadmap layered on top. That matters for calibration. Cimento&#8217;s near-term credibility will come from making training, simulation, reporting, and measurement meaningfully better than incumbent workflows. Its long-term differentiation depends on whether the unified risk score becomes trusted enough to drive security operations decisions.</p><p>The score itself needs careful validation. The company describes a forward-looking, contextual model that uses company-specific context, first-party outcomes, and security integrations. Buyers will need to understand which signals are used, how they are weighted, how the model handles false positives, and how a security team can explain the score to HR, legal, compliance, and business owners.</p><p>The multi-channel and multi-turn model also creates practical constraints. Email simulation is familiar. SMS, voice, deepfake calls, and employee-owned devices introduce legal, privacy, and change-management questions. Cimento appears aware of that boundary and has discussed voice and mobile as powerful, deployment-sensitive channels. The strongest near-term use cases may be high-risk populations, regulated workflows, and environments already experiencing real external pressure across channels such as Telegram, WhatsApp, or SMS.</p><p>The agent registry roadmap is promising, though still early. The clearest near-term path is visibility through MDM, endpoint, identity, and tool-usage signals, then tying that usage back to the sponsoring employee. The harder questions are how Cimento will detect short-lived agents, classify permissions consistently, and distinguish risky agent behavior from risky human intent. Those questions should remain open product validation points.</p><h2>Competition and Positioning</h2><p>Cimento sits between several market layers. It overlaps with incumbent awareness and phishing-security vendors. It also overlaps with broader human risk platforms and related vendors that emphasize continuous scoring, adaptive training, behavioral signals, and control response. These layers include vendors such as KnowBe4, Proofpoint, and Mimecast, as well as CybSafe, Hoxhunt, and SoSafe.</p><p>The Competitive dynamic is different across these groups. KnowBe4 has scale, content depth, and market familiarity in awareness and phishing simulation. Mimecast and Proofpoint bring email security, insider risk, DLP, and policy control adjacency that can connect human risk scores to enforcement workflows. Hoxhunt, SoSafe, and Frame Security compete closer to the HRM thesis through behavior change, measurable risk, and targeted intervention and simulation. Cimento&#8217;s pressure is showing that their multi-channel testing, contextual score, and follow-on actions produce a stronger outcome compared to existing market alternatives.</p><p>The differentiation Cimento is pursuing is the combination of a low-friction SAT/phishing entry point, a company-contextual risk score, multi-turn social engineering simulation, and a human-plus-agent roadmap. Its strongest positioning centers on turning training and simulation into a risk intelligence layer that becomes more valuable as more employees and workflows pass through the platform.</p><p>That positioning also creates pressure. Incumbents can add AI-generated training, risk dashboards, threat-informed templates, and adaptive grouping into existing suites. Modern HRM vendors are already emphasizing live scoring and automated control response. Cimento will need to prove that its score is more contextual, that its simulations produce better signal, and that its downstream recommendations reduce exposure while limiting operational friction.</p><h2>Implications for The Modern HRM Stack</h2><p>If Cimento works as intended, it becomes a useful example of where Human Risk Management is heading. Completion metrics remain background evidence, while the operating layer centers on a living model of employee-linked exposure. The value would come from knowing which users and workflows are becoming riskier, which simulations reflect realistic attack behavior, and which interventions should move into review, coaching, or downstream control adjustment.</p><p>For buyers, the evaluation should focus on evidence quality. The key questions are whether the risk score is explainable, whether the integrations provide enough context, whether multi-turn simulation changes behavior, and whether recommended control actions are governable. Agent-risk capabilities should be evaluated as an emerging extension of the same human-risk model, especially in AI-native companies where employee-launched tools already create visibility and accountability gaps.</p><p>Cimento is therefore best positioned in the report as one emerging category example within the broader market. It shows how the market can start from security awareness, move into behavior-based risk intelligence, and extend into agent-aware governance as employees delegate more work to AI systems. The strategic importance is the direction of travel: Human Risk Management becomes a continuous operational layer for the person, the workflow, and the delegated action.</p><h1>Practitioner Takeaways</h1><p>Practitioners should treat Human Risk Management as a continuous operating model for exposure reduction, with training and simulation serving as signal inputs inside a broader risk loop. The first step is ownership. Security leaders should decide how awareness, security operations, identity, privacy, legal, and business owners participate in the program before automation is expanded. That ownership model should define which teams provide signals, which teams approve interventions, and which teams are accountable for employee-impacting decisions.</p><p>The next step is evidence quality. Buyers should inventory the signals they already have, identify two or three high-risk workflows, and test whether a platform can explain risk in those specific contexts. A useful pilot should show how the human-risk model handles role sensitivity, access level, reporting behavior, simulation outcomes, and workflow context. The evaluation should also require vendors to show score explanations, integration evidence, false-positive handling, and outcome tracking.</p><p>Practitioners should also define response thresholds before connecting HRM to downstream controls. Low-impact coaching can move quickly, while higher-impact actions need clear approval paths, auditability, and rollback. Agent-risk capabilities should be evaluated through the same lens: the immediate need is visibility into employee sponsorship, granted permissions, and delegated workflows, followed by proportional intervention when the combined human and machine exposure becomes material.</p><h1>Conclusion</h1><p>Human Risk Management is becoming a continuous security discipline because people-linked exposure now changes with the pace of work. AI increases the scale and realism of social engineering, while also changing how employees review information, trust systems, and delegate action. The category therefore has to account for behavior, context, workflow, and machine-assisted execution as connected parts of the same risk surface.</p><p>The strongest HRM programs will preserve the useful foundation of awareness and simulation while expanding their operating depth. The center of the program should be a contextual model that explains where exposure is concentrated, why it is changing, and which interventions are likely to reduce it. That model becomes more valuable when it draws from first-party evidence and feeds decisions across coaching, review, and downstream control systems.</p><p>This shift also raises the standard for governance. Measuring human risk touches employee trust, privacy, legal boundaries, and business accountability. Mature programs will need transparent scoring, clear ownership, careful approval paths, and a feedback loop that proves whether interventions improve outcomes. In that form, Human Risk Management becomes a practical layer for managing the person, the workflow, and the delegated action as one system of enterprise exposure.</p><p>The maturity test for Human Risk Management is whether the program can connect people, workflows, and delegated action to governed decisions that reduce exposure. Transparent scoring, clear ownership, privacy-aware controls, proportional intervention, and measurable outcomes are the operating requirements. In that form, HRM becomes a practical layer for managing human-linked exposure as a live enterprise variable, with governance strong enough to preserve trust while intervention becomes more precise.</p><div><hr></div><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/subscribe?"><span>Subscribe now</span></a></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Software Analyst Cyber Research! Subscribe for free to receive new cybersecurity reports and analysis.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/p/the-evolution-of-human-risk-management/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/p/the-evolution-of-human-risk-management/comments"><span>Leave a comment</span></a></p><div class="directMessage button" data-attrs="{&quot;userId&quot;:6770950,&quot;userName&quot;:&quot;SACR&quot;,&quot;canDm&quot;:null,&quot;dmUpgradeOptions&quot;:null,&quot;isEditorNode&quot;:true}" data-component-name="DirectMessageToDOM"></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&quot;,&quot;text&quot;:&quot;Share Software Analyst Cyber Research&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share Software Analyst Cyber Research</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Closing the Operational Gap In Modern SecOps: Why Human Speed Fails Against Machine Attacks]]></title><description><![CDATA[How AI-Native Detection, Context Graphs, and Decision-Grade Cases Are Reshaping Security Operations]]></description><link>https://softwareanalyst.substack.com/p/closing-the-operational-gap-in-modern</link><guid isPermaLink="false">https://softwareanalyst.substack.com/p/closing-the-operational-gap-in-modern</guid><dc:creator><![CDATA[SACR]]></dc:creator><pubDate>Tue, 19 May 2026 18:59:17 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!NVss!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F529bd1ff-c44b-4fe2-8790-c7e4eedc385c_1920x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>Executive Summary</h2><p>The primary challenge facing security operations is the operational tempo mismatch, where attackers move at machine speed while defenders are limited by human processes, manual context assembly, and high-latency approvals. The bottleneck is not alert volume, but the effort required to create a decision-grade case from fragmented data across identity, endpoint, and cloud systems. This problem is intensified by generic detections that lack organizational context, forcing analysts to manually reconstruct the severity and scope of every alert.</p><p>AI-augmented attack workflows also change the detection problem. The defender must identify, interpret, and act on fast-changing behavior while the adversary can generate variants, test paths, and adapt around static logic. Detection programs therefore need the same speed shift that Mythos and other security centric models give vulnerability management. Continuous validation, local context, adaptive detection engineering, and agentic investigation that turns emerging activity into evidence-supported cases. The long-term direction is an operating model in which AI helps defenders detect, test, prioritize, and contain at the same tempo attackers can experiment and move.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NVss!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F529bd1ff-c44b-4fe2-8790-c7e4eedc385c_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NVss!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F529bd1ff-c44b-4fe2-8790-c7e4eedc385c_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!NVss!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F529bd1ff-c44b-4fe2-8790-c7e4eedc385c_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!NVss!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F529bd1ff-c44b-4fe2-8790-c7e4eedc385c_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!NVss!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F529bd1ff-c44b-4fe2-8790-c7e4eedc385c_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NVss!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F529bd1ff-c44b-4fe2-8790-c7e4eedc385c_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/529bd1ff-c44b-4fe2-8790-c7e4eedc385c_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1222019,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://softwareanalyst.substack.com/i/198441185?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F529bd1ff-c44b-4fe2-8790-c7e4eedc385c_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NVss!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F529bd1ff-c44b-4fe2-8790-c7e4eedc385c_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!NVss!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F529bd1ff-c44b-4fe2-8790-c7e4eedc385c_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!NVss!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F529bd1ff-c44b-4fe2-8790-c7e4eedc385c_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!NVss!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F529bd1ff-c44b-4fe2-8790-c7e4eedc385c_1920x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Existing security architectures exacerbate the issue by optimizing for signal surfacing rather than decision support. Evidence is fragmented across disparate systems, and brittle correlation logic fails when activity spans domains or involves novel sequences. The critical missing requirement is a continuously usable model of Organizational Context, a living graph that links identities, assets, and business criticality in real-time. Adopting a Hybrid Analytics operating model with a mature context layer is essential to shift the SOC&#8217;s focus from event reconstruction to automated validation and response judgment.</p><p>The path forward requires transforming isolated alerts into evidence-supported cases via agentic, cross-domain investigation. This evolution must lead to a staged model of Autonomous Containment, where low-blast-radius actions are automated within stable, auditable guardrails. <a href="https://artemissecurity.com/">Artemis Security</a> is examined as a practical implementation of the model: an AI-native SecOps decision runtime designed to connect environmental context, adaptive detection, investigation, and scalable autonomous response. The core objective is to reduce the attacker&#8217;s window of opportunity by prioritizing the inspection and reversibility of actions, thereby significantly reducing time-to-decision and time-to-containment.</p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Software Analyst Cyber Research! Subscribe for free to receive new cybersecurity reports and analysis</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><div><hr></div><p></p><h1>Defining the Problem: Defenders Operate Too Slowly</h1><p>Security operations centers increasingly treat detections as hypotheses that must become response actions. The timing problem remains the central constraint. Attackers benefit from automation, repeatable tradecraft, and AI-assisted workflows that compress the interval between initial access and material impact. Defenders still carry approvals, handoffs, and human review on the critical path. The result is a mismatch in operational tempo with attackers moving at machine speed while the SOC assembles context at human speed.</p><p>Threat Detection faces the same compression problem. From an adversarial perspective,  Mythos and other related models accelerate the interval between attacker intent, technique selection, execution, and adaptation. Security programs built around static rules, periodic content reviews, manual tuning, ticket-based investigation, and delayed context enrichment struggle in this environment because attackers can vary behavior faster than defenders can validate, tune, and operationalize new detection logic. Vulnerability management addresses exposure before exploitation. Threat detection addresses the live operating window once activity begins, when weak signals must become validated cases quickly enough to support containment. The practical requirement is AI-augmented detection and investigation that can reason over local context, test hypotheses against current telemetry, generate or adjust detection logic, and convert emerging activity into reviewable cases before the response window closes.</p><p>The practical bottleneck is the effort required to turn scattered signals into an actionable storyline. A case is the operational container; the storyline is the time-ordered, context-enriched explanation of behavior inside it. That storyline supports containment, escalation, or further investigation. Analysts still spend large amounts of time retrieving evidence, reconciling naming differences, and deciding whether separate events belong to one chain of activity. Cross-team communication adds more latency when ownership, business criticality, or dependency information sits outside security tooling. The SOC therefore becomes a manual context assembly line.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!64_A!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf696414-56b6-4e82-aac2-fd5d1d0092b4_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!64_A!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf696414-56b6-4e82-aac2-fd5d1d0092b4_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!64_A!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf696414-56b6-4e82-aac2-fd5d1d0092b4_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!64_A!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf696414-56b6-4e82-aac2-fd5d1d0092b4_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!64_A!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf696414-56b6-4e82-aac2-fd5d1d0092b4_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!64_A!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf696414-56b6-4e82-aac2-fd5d1d0092b4_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cf696414-56b6-4e82-aac2-fd5d1d0092b4_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!64_A!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf696414-56b6-4e82-aac2-fd5d1d0092b4_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!64_A!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf696414-56b6-4e82-aac2-fd5d1d0092b4_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!64_A!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf696414-56b6-4e82-aac2-fd5d1d0092b4_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!64_A!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf696414-56b6-4e82-aac2-fd5d1d0092b4_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Detection is rarely the slow stage. Modern tools can produce alerts immediately, yet the step from signal to response action still depends on local judgment about who is involved, what systems are affected, and how much business risk is attached to the proposed response. Generic detections intensify that burden because they carry limited organizational context. Each alert becomes a local reconstruction project. Response speed is therefore tightly coupled to context quality. When containment depends on repeated lookups, each candidate case waits until someone can estimate impact and blast radius with enough confidence to act. Alert volume compounds that queue. Noise consumes triage time, triage creates backlog, and backlog extends the window in which an attacker can move before containment.</p><h1>Why Current Architecture Breaks</h1><p>Many detection architectures are optimized to surface signals and only partially support response actions. They can identify suspicious events and group them into incidents, yet they often leave the storyline to the analyst. The core operational questions remain open: what happened, why it matters in this environment, and what action is justified now. When risk, asset criticality, and ownership are absent from the signal, triage teams rebuild that picture case by case.</p><p>Fragmentation makes that problem worse. Enterprise investigations routinely require movement across SIEM, SOAR, endpoint, identity, cloud, and SaaS security consoles. Each console may have its own object model, severity logic, retention policy, and workflow assumptions. Analysts, therefore, spend critical minutes translating between tools, checking whether identifiers refer to the same entity, and manually carrying facts from one interface into another. Multi-vendor environments can produce strong local detections while still creating a slow global investigation.</p><p>This fragmentation increases handoffs, lookup time, and uncertainty. Evidence relevant to one incident may sit across major telemetry systems and various operational records. Cross-domain investigations are routine, yet many architectures still assume that correlation will happen through narrow identifiers or static rules. That approach degrades when activity spans domains, when attackers vary a familiar sequence, or when the analyst needs to connect technical events to organizational consequences. Correlation itself is often brittle and shallow. Rules work well for known patterns with stable fields, yet they capture novelty poorly and rarely express the full behavioral chain that matters in an investigation. Pipeline complexity adds further fragility. Schema drift, parser failures, ingestion gaps, and broken joins can quietly erode the evidentiary path while dashboards still show detections as deployed. The result is uncertainty disguised as coverage.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!XguU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe626e94b-54f0-46e7-9b64-a8bd748cae39_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!XguU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe626e94b-54f0-46e7-9b64-a8bd748cae39_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!XguU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe626e94b-54f0-46e7-9b64-a8bd748cae39_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!XguU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe626e94b-54f0-46e7-9b64-a8bd748cae39_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!XguU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe626e94b-54f0-46e7-9b64-a8bd748cae39_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!XguU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe626e94b-54f0-46e7-9b64-a8bd748cae39_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e626e94b-54f0-46e7-9b64-a8bd748cae39_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!XguU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe626e94b-54f0-46e7-9b64-a8bd748cae39_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!XguU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe626e94b-54f0-46e7-9b64-a8bd748cae39_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!XguU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe626e94b-54f0-46e7-9b64-a8bd748cae39_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!XguU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe626e94b-54f0-46e7-9b64-a8bd748cae39_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Cost and latency pressures deepen the architectural tradeoff. Full centralization improves query convenience, though cost rises quickly at telemetry scale. Pure federation reduces some storage pressure, though it adds latency when investigators need immediate answers. Analysts then escalate disruptive decisions with incomplete context about blast radius, asset importance, or likely business effect. Volume overwhelms investigation capacity, and engineering effort is absorbed by false-positive management while investigative capability grows more slowly than the attack surface.</p><h1>The Missing Requirement: Organizational Context</h1><p>The missing requirement is a continuously usable model of organizational context. Security decisions depend on understanding the relationships among identities, assets, permissions, ownership, criticality, and related dependencies. In practice, this means a living context graph that becomes the central architectural object for investigation and response. Current security frameworks increasingly formalize this requirement by treating inventories, entitlements, operational flows, and mission impact as part of the detection and response foundation. Without that layer, an alert remains an isolated technical artifact with limited operational meaning.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!UgZk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7845eada-49c9-4215-9569-69f03966f8b9_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!UgZk!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7845eada-49c9-4215-9569-69f03966f8b9_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!UgZk!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7845eada-49c9-4215-9569-69f03966f8b9_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!UgZk!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7845eada-49c9-4215-9569-69f03966f8b9_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!UgZk!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7845eada-49c9-4215-9569-69f03966f8b9_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!UgZk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7845eada-49c9-4215-9569-69f03966f8b9_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7845eada-49c9-4215-9569-69f03966f8b9_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!UgZk!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7845eada-49c9-4215-9569-69f03966f8b9_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!UgZk!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7845eada-49c9-4215-9569-69f03966f8b9_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!UgZk!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7845eada-49c9-4215-9569-69f03966f8b9_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!UgZk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7845eada-49c9-4215-9569-69f03966f8b9_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The graph changes the quality of judgment because it supplies the decision dependencies required to interpret behavior locally. It helps determine whether a suspicious login belongs to a privileged account, whether the accessed system sits on a production path, whether the target workload supports downstream services, and whether containment would interrupt a critical business function. These relationships allow teams to estimate operational risk with precision. They also matter because modern incidents frequently cross organizational boundaries, which raises the value of understanding supplier dependencies, delegated access, and exposure paths before acting.</p><p>The graph must span domains and stay fresh. Modern attack paths commonly move through identity, endpoint, cloud, and application layers within the same chain of activity. A useful investigative model connects entities and events across those layers in near real time and stays synchronized with identity providers, cloud resource managers, configuration systems, and related authoritative sources. Freshness matters because impact estimation depends on current relationships. A stale dependency graph can create false confidence and distort containment choices.</p><p>At the implementation level, the living graph should be populated from existing telemetry, configuration, identity, and related pipeline tooling. It should also be exposed to agents through a controlled interface, including MCP-compatible access where appropriate, so investigative agents can query current context without hard-coding knowledge of every source system. The graph then becomes a shared decision surface: tools feed it, agents reason over it, and cases inherit current business context from it.</p><p>A mature, living graph and context layer changes how investigations are assembled. Software agents can query the graph and underlying sources directly to validate alerts, collect supporting evidence, and surface the small set of facts that drive a response action. Analysts then spend less time retrieving data and more time judging scope, business impact, and response options. The operational product is a context-enriched storyline that can be inspected, challenged, and acted on.</p><h1>Hybrid Analytics as the Operating Model</h1><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!clJa!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9724e25-7cfd-4acb-89f2-4a173bbc03d6_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!clJa!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9724e25-7cfd-4acb-89f2-4a173bbc03d6_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!clJa!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9724e25-7cfd-4acb-89f2-4a173bbc03d6_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!clJa!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9724e25-7cfd-4acb-89f2-4a173bbc03d6_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!clJa!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9724e25-7cfd-4acb-89f2-4a173bbc03d6_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!clJa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9724e25-7cfd-4acb-89f2-4a173bbc03d6_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c9724e25-7cfd-4acb-89f2-4a173bbc03d6_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!clJa!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9724e25-7cfd-4acb-89f2-4a173bbc03d6_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!clJa!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9724e25-7cfd-4acb-89f2-4a173bbc03d6_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!clJa!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9724e25-7cfd-4acb-89f2-4a173bbc03d6_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!clJa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9724e25-7cfd-4acb-89f2-4a173bbc03d6_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>A workable operating model balances speed, depth, and cost. The most time-sensitive detections and decision inputs need low-latency access close to the analytic engine, while lower-frequency or historical evidence can remain in remote systems that are queried when deeper context is required. This is a hybrid analytics model: keep hot-path data close to the decision point and reach back selectively for depth. The hot-path is the data, context, and derived state needed inside the response decision window.</p><p>This approach treats data placement as an operational design choice. Common decision inputs should be pre-positioned for rapid access: current identity state, asset criticality, entitlement context, recent high-value telemetry, and relevant graph relationships. Long-tail history and specialized evidence can remain federated until a case justifies the additional cost or latency. Cheap sensing can surface candidates broadly, and targeted retrieval can add depth where it improves the response action.</p><p>The operating sequence is straightforward. First, the platform keeps the hot path current through normalization, enrichment, and continuous graph refresh. Second, detections promote candidate cases into storyline assembly when they meet policy or confidence thresholds. Third, agents query the graph and selected source systems to fill evidence gaps, test alternative explanations, and identify the likely blast radius. Fourth, the resulting case presents a response recommendation with supporting evidence, uncertainty, and expected business effect.</p><p>Hybrid analytics also creates a stronger foundation for continuous baselining and case assembly. When the critical context required for common investigations is already positioned for rapid access, analysts and automated agents can evaluate meaning faster. Agents perform targeted retrieval from deeper sources; analysts spend less time manually gathering evidence and more time reviewing judgment, scope, and action eligibility. The architecture is then tuned around time-to-decision as a measurable operating metric.</p><p>This design depends on continuous coverage validation. Selective architectures fail quickly when required fields, pivots, or joins drift out of availability. Teams should measure whether hot-path inputs remain fresh, whether federated retrieval meets case latency targets, and whether missing context delays containment. Hybrid analytics succeeds when the system can assemble a decision-grade storyline inside the operational window available for response.</p><h1>Evolution from Alerts to Agentic Storyline Assembly</h1><p>The operational unit of value in modern security is the case, which transforms isolated alerts into explicit hypotheses supported by assembled evidence and impact framing. A strong case must consistently answer what happened, why it matters, and what to do next, shifting incident response from simple detection to the reconstruction of events, storyline of sequences and scope. This transition ensures that analysts act on complete narratives rather than fragmented technical signals.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7D0Z!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bb5869c-6f3c-4575-b466-56fff3bfaa0a_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7D0Z!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bb5869c-6f3c-4575-b466-56fff3bfaa0a_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!7D0Z!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bb5869c-6f3c-4575-b466-56fff3bfaa0a_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!7D0Z!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bb5869c-6f3c-4575-b466-56fff3bfaa0a_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!7D0Z!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bb5869c-6f3c-4575-b466-56fff3bfaa0a_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7D0Z!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bb5869c-6f3c-4575-b466-56fff3bfaa0a_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4bb5869c-6f3c-4575-b466-56fff3bfaa0a_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!7D0Z!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bb5869c-6f3c-4575-b466-56fff3bfaa0a_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!7D0Z!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bb5869c-6f3c-4575-b466-56fff3bfaa0a_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!7D0Z!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bb5869c-6f3c-4575-b466-56fff3bfaa0a_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!7D0Z!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bb5869c-6f3c-4575-b466-56fff3bfaa0a_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>Examples of Events, Incidents vs Storyline:</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vHKD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe115dab1-9b2d-4d46-bafb-20e703e669c9_1080x1350.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vHKD!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe115dab1-9b2d-4d46-bafb-20e703e669c9_1080x1350.png 424w, https://substackcdn.com/image/fetch/$s_!vHKD!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe115dab1-9b2d-4d46-bafb-20e703e669c9_1080x1350.png 848w, https://substackcdn.com/image/fetch/$s_!vHKD!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe115dab1-9b2d-4d46-bafb-20e703e669c9_1080x1350.png 1272w, https://substackcdn.com/image/fetch/$s_!vHKD!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe115dab1-9b2d-4d46-bafb-20e703e669c9_1080x1350.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vHKD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe115dab1-9b2d-4d46-bafb-20e703e669c9_1080x1350.png" width="1080" height="1350" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e115dab1-9b2d-4d46-bafb-20e703e669c9_1080x1350.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1350,&quot;width&quot;:1080,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vHKD!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe115dab1-9b2d-4d46-bafb-20e703e669c9_1080x1350.png 424w, https://substackcdn.com/image/fetch/$s_!vHKD!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe115dab1-9b2d-4d46-bafb-20e703e669c9_1080x1350.png 848w, https://substackcdn.com/image/fetch/$s_!vHKD!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe115dab1-9b2d-4d46-bafb-20e703e669c9_1080x1350.png 1272w, https://substackcdn.com/image/fetch/$s_!vHKD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe115dab1-9b2d-4d46-bafb-20e703e669c9_1080x1350.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Incident:</p><h3><strong>SOC Incident (Traditional View)</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!69Rt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45752efd-46e9-4810-b6e5-02c1a090bd99_1080x1350.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!69Rt!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45752efd-46e9-4810-b6e5-02c1a090bd99_1080x1350.png 424w, https://substackcdn.com/image/fetch/$s_!69Rt!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45752efd-46e9-4810-b6e5-02c1a090bd99_1080x1350.png 848w, https://substackcdn.com/image/fetch/$s_!69Rt!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45752efd-46e9-4810-b6e5-02c1a090bd99_1080x1350.png 1272w, https://substackcdn.com/image/fetch/$s_!69Rt!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45752efd-46e9-4810-b6e5-02c1a090bd99_1080x1350.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!69Rt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45752efd-46e9-4810-b6e5-02c1a090bd99_1080x1350.png" width="1080" height="1350" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/45752efd-46e9-4810-b6e5-02c1a090bd99_1080x1350.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1350,&quot;width&quot;:1080,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!69Rt!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45752efd-46e9-4810-b6e5-02c1a090bd99_1080x1350.png 424w, https://substackcdn.com/image/fetch/$s_!69Rt!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45752efd-46e9-4810-b6e5-02c1a090bd99_1080x1350.png 848w, https://substackcdn.com/image/fetch/$s_!69Rt!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45752efd-46e9-4810-b6e5-02c1a090bd99_1080x1350.png 1272w, https://substackcdn.com/image/fetch/$s_!69Rt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45752efd-46e9-4810-b6e5-02c1a090bd99_1080x1350.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Cross-domain assembly is central to that shift. A meaningful storyline often has to connect identity, endpoint, cloud, and network evidence into one behavioral chain. That assembly should happen through agentic evidence-gathering that queries the context graph and source systems directly. Agents can validate the initial signal, collect the pivots that shaped the case, and turn isolated events into an inspectable explanation. Human effort is then concentrated on validation, trade-offs, and final judgment.</p><h3><strong>Incident Storyline</strong></h3><h3><strong>LLM Summation With Business [Context Elements] Retrieved In Realtime</strong></h3><p>The system&#8217;s <strong>[operational maintenance]</strong> protocols were triggered by the <strong>[service-level scheduling]</strong> engine, ensuring <strong>[business continuity]</strong> by automatically executing critical background health checks. This seamless background process maintains the <strong>[infrastructure reliability]</strong> necessary to support <strong>[high-stakes research output]</strong> and <strong>[project-critical performance]</strong> for your professional operations.</p><p>Context Source Elements (Business Context Examples)</p><h3><strong>Context Mapping in the Enterprise SOC</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!yR5e!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4019ac79-5b08-458d-90c7-4348f4b80c19_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!yR5e!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4019ac79-5b08-458d-90c7-4348f4b80c19_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!yR5e!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4019ac79-5b08-458d-90c7-4348f4b80c19_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!yR5e!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4019ac79-5b08-458d-90c7-4348f4b80c19_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!yR5e!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4019ac79-5b08-458d-90c7-4348f4b80c19_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!yR5e!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4019ac79-5b08-458d-90c7-4348f4b80c19_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4019ac79-5b08-458d-90c7-4348f4b80c19_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!yR5e!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4019ac79-5b08-458d-90c7-4348f4b80c19_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!yR5e!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4019ac79-5b08-458d-90c7-4348f4b80c19_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!yR5e!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4019ac79-5b08-458d-90c7-4348f4b80c19_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!yR5e!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4019ac79-5b08-458d-90c7-4348f4b80c19_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>A compact example illustrates the difference. A raw event may show an impossible-travel login for a privileged user. A traditional incident may add related events such as a new token, unusual cloud console activity, and access to a sensitive workload. A storyline adds local context: the user owns a production service, the accessed workload supports a revenue process, the activity occurred outside the user&#8217;s normal pattern, and containment would affect a defined dependency path. The response discussion can then focus on scoped actions, such as token invalidation, step-up verification, or temporary privilege reduction.</p><p>This is why the case contract matters. A useful storyline needs a time-ordered evidence trail, the key pivots that shaped the narrative, scope indicators, and a confidence statement that makes assumptions and gaps visible. When a system recommends action, it should also produce a replayable artifact that records what evidence was pulled, what context sources were consulted, and what policy thresholds were applied. Inspectability makes faster responses governable.</p><p>A subset of candidates deserves this level of work. The system should promote the signals that justify deeper investigation, because the purpose of the model is to concentrate scarce analyst attention where it changes the outcome. Transparent confidence scoring supports that prioritization and reduces unsupported precision. Decision quality improves when uncertainty is explicit, and review effort begins from a standardized evidence bundle.</p><h1>The Practical Path to Autonomous Containment</h1><p>Faster investigation matters when it produces faster, safer response actions. Real-time defense remains difficult when every action depends on manual lookup, informal coordination, and high-latency approval. The practical path forward extends from agentic storyline assembly into guided response, then selective automation. The early objective is to reduce avoidable delay for actions that are reversible, well-scoped, and defensible under policy.</p><p>This suggests a staged model. First, the system assembles the storyline, estimates business impact, and prepares a recommended response while a human remains in the approval loop. Next, organizations automate low-blast-radius steps such as session revocation, token invalidation, or isolation of non-critical assets when the context graph shows that business risk is limited. Broader autonomy becomes practical when guardrails are tied to asset criticality, dependency awareness, recovery paths, and scoped permissions.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!mZ1g!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffdce9d96-1575-41e2-92ed-bf534882ed52_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!mZ1g!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffdce9d96-1575-41e2-92ed-bf534882ed52_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!mZ1g!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffdce9d96-1575-41e2-92ed-bf534882ed52_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!mZ1g!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffdce9d96-1575-41e2-92ed-bf534882ed52_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!mZ1g!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffdce9d96-1575-41e2-92ed-bf534882ed52_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!mZ1g!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffdce9d96-1575-41e2-92ed-bf534882ed52_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fdce9d96-1575-41e2-92ed-bf534882ed52_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!mZ1g!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffdce9d96-1575-41e2-92ed-bf534882ed52_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!mZ1g!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffdce9d96-1575-41e2-92ed-bf534882ed52_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!mZ1g!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffdce9d96-1575-41e2-92ed-bf534882ed52_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!mZ1g!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffdce9d96-1575-41e2-92ed-bf534882ed52_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The storyline becomes the control surface for governed action. It should show the behavioral chain, affected entities, confidence level, operational impact, and policy basis for the recommended response. That structure allows the organization to classify action risk clearly and decide which steps can be executed automatically, require approval, or need business-owner review.</p><p>The core requirement is trust grounded in inspectability. Teams rely on automated containment when they can reconstruct why a decision was made, what evidence was considered, what context sources were consulted, what threshold justified the action, and how the action can be reversed. The operational prize is meaningful because shorter time-to-decision and time-to-containment reduce the opportunity window available to the attacker. Autonomous response becomes viable when the system combines speed with bounded operational risk.</p><p>The control model matters as much as the detection model. Changes to thresholds, suppressions, routing logic, and automation eligibility should be treated as production changes that are reviewable, testable, and reversible. Approval gates, policy constraints, explicit eligibility rules, and prevalidated recovery procedures make autonomous action operationally credible.</p><h1>The Artemis Platform</h1><h2>Profile Summary</h2><p><a href="https://artemissecurity.com/">Artemis Security</a> is an AI-native security operations platform designed to compress the interval between detection, investigation, and response. It fits this report as a practical implementation of the operating model described earlier: a living context graph, hybrid analytics, agentic storyline assembly, and governed response.</p><p>The platform builds a continuously updated model of the customer environment, uses that model to generate and tune detections against local telemetry, and applies agents to investigate alerts across connected sources. Its intended output is autonomous protection that is built by a decision-grade case that explains what happened, why it matters in the local environment, which evidence supports the conclusion, what remains uncertain, and which response options are appropriate.</p><p>The earlier Artemis profile from <a href="https://softwareanalyst.substack.com/p/the-future-of-detection-engineering">The Future of Detection Engineering in Security Operations</a> treated the company primarily as an upstream detection and context engine. That framing remains useful, and the stronger report fit is now broader. Artemis is positioned around the full loop from adaptive detection to evidence-backed investigation, response-ready case assembly, and automated response. The core objective is faster, governable containment, with detection quality serving that outcome.</p><h2>Market Context</h2><p>Artemis reflects a broader shift in SecOps from alert production toward decision-grade case output. Detection-as-code improved rule discipline, and many teams still struggle with rule drift, uneven telemetry, and manual interpretation. Artemis addresses that maintenance burden by using AI agents and a structured environment model to generate customer-specific detections, investigate activity across connected sources, suggest the right action to take for the case created, and help the customer take it with the click of a button.</p><p>For this report&#8217;s taxonomy, Artemis is a candidate for the decision-runtime layer of the stack. It overlaps with AI SOC tools, next-generation SIEM initiatives, detection engineering acceleration, and investigation automation. Its differentiation is the attempt to make customer-specific detection, investigation, and response loops reliable at scale without pushing hidden operational work back onto the SOC.</p><h2>Product Architecture &amp; Workflow</h2><p>Artemis begins with environmental intelligence. The platform builds a living model of users, AI agents, assets, access relationships, normal behavior, and business context. It allows the system to evaluate a login, cloud API call, endpoint event, or SaaS action against who the actor is, what they normally do, what they can access, and which assets matter.</p><p>That context layer supports adaptive detection engineering. Artemis can take threat intelligence, analyst intent, or hunting questions as inputs, map relevant behaviors to the customer&#8217;s telemetry, and generate detections tuned to local structure and risk. Natural-language detection building and threat hunting reduce dependence on specialized query languages for common workflows. The underlying system still includes the disciplines of detection-as-code: versioning, review, testing, deployment gates, and rollback.</p><p>The platform also fits the hybrid analytics model. Artemis can connect to log sources directly and also query security data where it lives, whether it&#8217;s existing security systems like EDR, data stores like S3, or data warehouses. Common decision context stays close to the case workflow, and deeper evidence is retrieved when a case justifies the cost or latency. This matters in environments where evidence sits across SIEMs, cloud logs, identity systems, endpoint telemetry, and various SaaS sources.</p><p>When a detection fires, Artemis agents form hypotheses, query relevant sources, correlate signals, including alerts created by other security vendors, and produce a structured report with storyline, evidence, severity assessment, and response options. Identity, cloud, and endpoint sources are useful examples because they show how source-specific expertise can be encoded into the investigation. The product&#8217;s credibility depends on whether the output remains auditable, with evidence and reasoning visible enough for analyst review.</p><p>The response layer is the governance test. Artemis can become more valuable as it moves closer to containment. That proximity raises the requirement for policy boundaries, blast-radius awareness, approval paths, and rollback mechanics before recommendations can support execution. Autonomous action becomes credible when the case record shows the evidence used, the context consulted, the threshold applied, and the recovery path available.</p><h2>Strategic Strengths</h2><p>Artemis&#8217; primary strategic strength is the integration of adaptive detection with environmental modeling. Many AI SOC products begin after an alert already exists. Artemis moves upstream to influence the quality of the signal before it reaches the analyst, then carries that context forward into investigation and response.</p><p>A second strength is alignment with hybrid data economics. Enterprises increasingly spread security data across different cost and latency tiers. Artemis&#8217; retrieval model gives it a way to preserve investigative depth and control ingest cost, especially in environments with evidence distributed across cloud, identity, endpoint, and SaaS systems.</p><p>A third strength is the consistency of the product narrative. Artemis has a clear answer to why AI matters in SecOps: AI is useful when it reasons over a structured model of the environment and produces reviewable cases. That framing is stronger than generic copilot positioning because it ties AI capability to a concrete architectural dependency.</p><p>Reported customer outcomes support the thesis, including higher detection coverage, environment-specific intelligence within 24 hours, and substantial reductions in mean time to resolution. These claims should be treated as deployment-specific evidence. The right validation questions are baseline process, alert mix, response scope, degree of automation, and how much work was included in the measurement.</p><h2>Trust and Validation Checkpoints</h2><p>Artemis raises the right buyer questions because it asks AI to reason over sensitive evidence and propose action. Cases and detections need clear provenance: cited evidence, visible assumptions, uncertainty, and an audit trail that analysts can inspect. Confidence scores are useful only when paired with the evidence path that produced them.</p><p>Coverage health is equally important. Adaptive systems need to distinguish low activity from missing visibility. If telemetry gaps, schema drift, or broken integrations are interpreted as a clean environment, the platform can create silent coverage failure. Artemis needs to surface the health of the evidence plane as clearly as it surfaces the case output.</p><p>Data handling also matters because the platform operates on sensitive security evidence. Dedicated environments, tenant separation, and model-training exclusions are material procurement details that should be verified directly. These controls become more important as the system moves from investigation assistance toward response recommendations.</p><h2>Competitive Positioning</h2><p>Artemis competes across several adjacent categories: AI SOC, next-generation SIEM, detection engineering automation, investigation automation, and response orchestration. Its strongest position is the full loop from context to detection generation, investigation, and response-ready case assembly. If that loop performs consistently, Artemis functions as a context-driven decision runtime for SecOps.</p><p>The main competitive risk is fragmentation of the value proposition. If the living environment model drifts, the platform can collapse into point capabilities such as rule generation, chat-based hunting, and narrative summarization. The central test is whether Artemis can make every stage of the workflow more reliable because each stage inherits the same current model of organizational context.</p><h2>Bottom Line</h2><p>Artemis is best read as a bet that decision-grade cases are becoming the new output format of the SOC. Detections and investigations become more valuable when they inherit a continuously updated model of the customer environment. The strategic question is whether Artemis can preserve trust through governance, provenance, and bounded autonomy as it compresses the path from signal to response.</p><h1>Practitioner Takeaways</h1><p>Practitioners should treat the case as the unit of SecOps modernization. The highest-value measurement is whether the organization can move from signal to decision with enough evidence, context, and confidence to justify action. Time-to-decision and time-to-containment should sit beside conventional alert metrics because they show whether detection output is becoming operational judgment.</p><p>The context layer should be managed as production infrastructure. A living graph only helps when it stays current, so identity state, asset criticality, entitlements, ownership, dependency paths, and recent high-value telemetry need active refresh, monitoring, and testing. The same discipline should apply to the hot path. Common decision inputs should remain close to the case workflow, while deeper evidence can be retrieved when the case justifies added cost or latency. In practical terms, data placement becomes an operating choice tied directly to response speed.</p><p>Storylines also need to be inspectable enough to support action. Each case should show the behavioral chain, supporting evidence, key pivots, assumptions, uncertainty, and response rationale. That structure gives analysts a reviewable artifact they can challenge, approve, or use for containment. It also creates the foundation for selective autonomy because automated action becomes more credible when the organization can reconstruct why a recommendation was made and what recovery path is available.</p><p>Autonomy should begin with reversible actions and a narrow blast radius. Early automation should focus on bounded steps such as session revocation, token invalidation, and temporary privilege reduction. Higher-impact actions require explicit eligibility rules, approval paths, and rollback procedures. For buyers, the validation focus should therefore extend beyond feature coverage to evidence provenance, graph freshness, coverage health, tenant controls, action auditability, and recovery mechanics. The core question is whether Artemis improves decision quality while reducing response latency.</p><h1>Conclusion</h1><p>The SOC&#8217;s tempo problem is ultimately a context problem. Security teams can detect suspicious activity faster than they can assemble the local facts required to decide what action is justified. A living context graph, hybrid analytics model, and agentic storyline assembly give that decision process a stronger architectural base by linking evidence to identities, assets, dependencies, and business impact.</p><p>The strategic shift is from alert production to decision-grade case assembly. The case becomes the place where detection, investigation, business context, and response governance converge. When that case is supported by the current organizational context and a replayable evidence trail, analysts can spend less time rebuilding what happened and more time judging scope, impact, and action eligibility.</p><p>The practical direction for SecOps is clear: build systems that make judgment faster while keeping reasoning visible. Decision-grade cases should become the common output of detection, investigation, and response. The organizations that get there first will reduce avoidable latency during incidents and act within clear, auditable guardrails.</p><div><hr></div><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Software Analyst Cyber Research! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/p/closing-the-operational-gap-in-modern?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/p/closing-the-operational-gap-in-modern?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div class="directMessage button" data-attrs="{&quot;userId&quot;:6770950,&quot;userName&quot;:&quot;SACR&quot;,&quot;canDm&quot;:null,&quot;dmUpgradeOptions&quot;:null,&quot;isEditorNode&quot;:true}" data-component-name="DirectMessageToDOM"></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/p/closing-the-operational-gap-in-modern/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/p/closing-the-operational-gap-in-modern/comments"><span>Leave a comment</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&quot;,&quot;text&quot;:&quot;Share Software Analyst Cyber Research&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share Software Analyst Cyber Research</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Inside the New Cybersecurity Playbook for the AI Era]]></title><description><![CDATA[The future of cybersecurity in 2026: A 3-week live program designed to help security leaders cut through noise, analyze modern architectures and how SACR Analyzes 600+ security companies]]></description><link>https://softwareanalyst.substack.com/p/inside-the-new-cybersecurity-playbook</link><guid isPermaLink="false">https://softwareanalyst.substack.com/p/inside-the-new-cybersecurity-playbook</guid><dc:creator><![CDATA[SACR]]></dc:creator><pubDate>Mon, 18 May 2026 22:43:55 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!2QP0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88efafc4-87a3-40ac-9bcd-b33ee7782b47_1080x1920.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div><hr></div><h3>Cybersecurity Changing Dynamics After Mythos &amp; Daybreak </h3><p><em>By Francis Odum &amp; Lawrence Pingree</em></p><p>Cybersecurity has entered a new phase. Last week, we <a href="https://softwareanalyst.substack.com/p/the-cybersecurity-implications-of">published our perspectives</a> on Claude Mythos and OpenAI Cyber. The broader cybersecurity ecosystem is changing much faster than anyone would have anticipated. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2QP0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88efafc4-87a3-40ac-9bcd-b33ee7782b47_1080x1920.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2QP0!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88efafc4-87a3-40ac-9bcd-b33ee7782b47_1080x1920.jpeg 424w, https://substackcdn.com/image/fetch/$s_!2QP0!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88efafc4-87a3-40ac-9bcd-b33ee7782b47_1080x1920.jpeg 848w, https://substackcdn.com/image/fetch/$s_!2QP0!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88efafc4-87a3-40ac-9bcd-b33ee7782b47_1080x1920.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!2QP0!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88efafc4-87a3-40ac-9bcd-b33ee7782b47_1080x1920.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2QP0!,w_2400,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88efafc4-87a3-40ac-9bcd-b33ee7782b47_1080x1920.jpeg" width="222" height="394.6666666666667" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/88efafc4-87a3-40ac-9bcd-b33ee7782b47_1080x1920.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;large&quot;,&quot;height&quot;:1920,&quot;width&quot;:1080,&quot;resizeWidth&quot;:222,&quot;bytes&quot;:418627,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://softwareanalyst.substack.com/i/197366816?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88efafc4-87a3-40ac-9bcd-b33ee7782b47_1080x1920.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:&quot;center&quot;,&quot;offset&quot;:false}" class="sizing-large" alt="" srcset="https://substackcdn.com/image/fetch/$s_!2QP0!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88efafc4-87a3-40ac-9bcd-b33ee7782b47_1080x1920.jpeg 424w, https://substackcdn.com/image/fetch/$s_!2QP0!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88efafc4-87a3-40ac-9bcd-b33ee7782b47_1080x1920.jpeg 848w, https://substackcdn.com/image/fetch/$s_!2QP0!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88efafc4-87a3-40ac-9bcd-b33ee7782b47_1080x1920.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!2QP0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88efafc4-87a3-40ac-9bcd-b33ee7782b47_1080x1920.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The problem is <strong>no longer access</strong> to information.</p><p>The problem is signal overload. The rate of change in the past 6-7 months is faster than we saw from 2019 to 2025.</p><p>Every week:</p><ul><li><p>A new AI security category emerges</p></li><li><p>A new cybersecurity startup claims to redefine the market</p></li><li><p>A new vendor promises full platform consolidation in AI</p></li><li><p>A new breach or potential like Mythos shifts enterprise priorities overnight</p></li></ul><p>As a leading <strong>cybersecurity analyst firm </strong>covering multiple categories and markets, we experience this noise X10 more than the average practitioner.</p><p>Security leaders are drowning in noise.</p><p>And in 2026, that noise is accelerating.</p><ul><li><p>Mythos, Cyber 5.1, and now Daybreak are changing how defenders operate.</p></li><li><p>AI is changing how attacks are launched. </p></li><li><p>AI is changing how software is built.</p></li><li><p>AI is changing how security vendors position themselves.</p></li></ul><p>But beneath the noise, a much bigger shift is happening:</p><p>The cybersecurity market is reorganizing itself.</p><ul><li><p>Platform wars are intensifying.</p></li><li><p>Traditional architectures are breaking.</p></li><li><p>Identity is becoming the new control plane with agents</p></li><li><p>Entire categories are converging as we <a href="https://softwareanalyst.substack.com/p/the-convergence-of-ai-and-data-security">outlined with UADP</a> </p></li><li><p>The modern SOC is being rebuilt as we outlined in <a href="https://softwareanalyst.substack.com/p/the-future-of-detection-engineering">SOC detection engineering</a></p></li><li><p>Cloud runtime security is becoming foundational.</p></li><li><p>Data security and <a href="https://softwareanalyst.substack.com/p/the-great-dlp-reset-securing-data">next-gen DLP are becoming paramount</a> for AI strategies.</p></li></ul><div><hr></div><h3>Introducing the SACR Cybersecurity Program for AI </h3><h3>Live or On-demand Program </h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vIuO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa41d22b0-24ae-4db0-a611-e5469735908e_2430x820.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vIuO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa41d22b0-24ae-4db0-a611-e5469735908e_2430x820.png 424w, https://substackcdn.com/image/fetch/$s_!vIuO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa41d22b0-24ae-4db0-a611-e5469735908e_2430x820.png 848w, https://substackcdn.com/image/fetch/$s_!vIuO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa41d22b0-24ae-4db0-a611-e5469735908e_2430x820.png 1272w, https://substackcdn.com/image/fetch/$s_!vIuO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa41d22b0-24ae-4db0-a611-e5469735908e_2430x820.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vIuO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa41d22b0-24ae-4db0-a611-e5469735908e_2430x820.png" width="1456" height="491" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a41d22b0-24ae-4db0-a611-e5469735908e_2430x820.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:491,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:719192,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://softwareanalyst.substack.com/i/197366816?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa41d22b0-24ae-4db0-a611-e5469735908e_2430x820.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vIuO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa41d22b0-24ae-4db0-a611-e5469735908e_2430x820.png 424w, https://substackcdn.com/image/fetch/$s_!vIuO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa41d22b0-24ae-4db0-a611-e5469735908e_2430x820.png 848w, https://substackcdn.com/image/fetch/$s_!vIuO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa41d22b0-24ae-4db0-a611-e5469735908e_2430x820.png 1272w, https://substackcdn.com/image/fetch/$s_!vIuO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa41d22b0-24ae-4db0-a611-e5469735908e_2430x820.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://maven.com/cybersecuritybootcamp/cybersecurity-bootcamp-for-leaders&quot;,&quot;text&quot;:&quot;Cybersecurity Program&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://maven.com/cybersecuritybootcamp/cybersecurity-bootcamp-for-leaders"><span>Cybersecurity Program</span></a></p><p>Most professionals see the surface. Very few understand the underlying market structure as well as a research firm like ours. Not many <strong>understand market dynamics better than&nbsp;</strong>a&nbsp;<strong>cybersecurity</strong>&nbsp;<strong>analyst firm</strong>&nbsp;that sees and covers multiple domains across the market. We see much more than we talk about. </p><p>That distinction matters.</p><p>What <strong>makes this program unique</strong> is that it is not being taught by a traditional training company, certification vendor, or academic institution. It is being led by SACR, a cybersecurity analyst firm that spends every day researching the industry from the inside out.</p><p>We <strong>analyze over 600+ cybersecurity companies across cloud, identity, SOC, AI, application, and data security</strong>. We speak regularly with CISOs, security architects, founders, operators, investors, and product leaders across the market. Our job is not simply to understand how cybersecurity tools work. Our job is to understand why markets evolve, why certain vendors win, where architectures are changing, and how enterprise security leaders actually make decisions.</p><p>This bootcamp is essentially an opportunity to step inside that process.</p><h4>Outcome for the program</h4><p>Amidst the noise and an analyst firm that structures everything together, we want to provide our systems and frameworks for the leaders who want to understand the structure to make better decisions:</p><ul><li><p>Better vendor decisions</p></li><li><p>Better architecture decisions</p></li><li><p>Better budget decisions</p></li><li><p>Better hiring decisions</p></li><li><p>Better career decisions</p></li><li><p>Better investment decisions</p></li></ul><p>That is why we built the AI Cybersecurity Bootcamp for Cyber Leaders 2026.</p><div><hr></div><h1>This Is Not a Traditional Cybersecurity Course</h1><p>Most cybersecurity education is either:</p><ol><li><p>Too technical and disconnected from strategic reality</p></li><li><p>Too theoretical and disconnected from real-world operations</p></li><li><p>Too outdated for the AI era</p></li><li><p>Too broad to be practically useful</p></li></ol><p>This bootcamp was designed differently.</p><p>Over three intensive weeks, we teach participants to think about cybersecurity as elite operators, analysts, CISOs, investors, and market leaders do.</p><p>The program is also structured as an on-demand, i.e., if you don&#8217;t have time, keep up with every session </p><p>This is about developing a framework and seeing a real practicum.</p><p>SACR frameworks and systems for understanding cybersecurity:</p><ol><li><p>How modern security architectures are evolving</p></li><li><p>Why certain vendors win while others disappear</p></li><li><p>How AI is reshaping cybersecurity operations</p></li><li><p>Which categories matter versus which are hype</p></li><li><p>How enterprise buyers evaluate security platforms</p></li><li><p>How modern SOCs are transforming</p></li><li><p>Where cloud, identity, data, and AI security are heading next</p><p></p></li></ol><p>Our goal is simple:</p><p>By the end of the program, you should be able to walk into any cybersecurity conversation:  whether with a CISO, founder, investor, engineer, or board member, and actually understand what matters.</p><p></p><h2>Alumni Perspective </h2><p>We have hosted over <strong>200+ Previous students in the history of the program.</strong></p><p>Here is what <strong><a href="https://www.linkedin.com/in/adriana-verhagen-96442a42/">Adriana Verhagen</a></strong>, Senior Product Manager at <strong><a href="https://www.linkedin.com/company/guardsix/">Guardsix (formerly Logpoint)</a></strong>, has to say about our course: "Unlike theoretical certifications, this course bridges the gap between NIST principles and modern security architecture. It provides practical insights into using disruptive technologies to innovate and reduce costs, making security a team favorite."</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-NPd!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01ffb7bb-ce0d-4930-8c4b-9aedbfa10018_1200x1500.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-NPd!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01ffb7bb-ce0d-4930-8c4b-9aedbfa10018_1200x1500.jpeg 424w, https://substackcdn.com/image/fetch/$s_!-NPd!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01ffb7bb-ce0d-4930-8c4b-9aedbfa10018_1200x1500.jpeg 848w, https://substackcdn.com/image/fetch/$s_!-NPd!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01ffb7bb-ce0d-4930-8c4b-9aedbfa10018_1200x1500.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!-NPd!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01ffb7bb-ce0d-4930-8c4b-9aedbfa10018_1200x1500.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-NPd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01ffb7bb-ce0d-4930-8c4b-9aedbfa10018_1200x1500.jpeg" width="539" height="673.75" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/01ffb7bb-ce0d-4930-8c4b-9aedbfa10018_1200x1500.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1500,&quot;width&quot;:1200,&quot;resizeWidth&quot;:539,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;View image&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="View image" title="View image" srcset="https://substackcdn.com/image/fetch/$s_!-NPd!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01ffb7bb-ce0d-4930-8c4b-9aedbfa10018_1200x1500.jpeg 424w, https://substackcdn.com/image/fetch/$s_!-NPd!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01ffb7bb-ce0d-4930-8c4b-9aedbfa10018_1200x1500.jpeg 848w, https://substackcdn.com/image/fetch/$s_!-NPd!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01ffb7bb-ce0d-4930-8c4b-9aedbfa10018_1200x1500.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!-NPd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01ffb7bb-ce0d-4930-8c4b-9aedbfa10018_1200x1500.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h1>The Biggest Problem in Cybersecurity Today</h1><h3>Most People Understand Tools. Very Few Understand Systems.</h3><p>Modern cybersecurity is no longer a collection of isolated products.</p><p>It is an interconnected system.</p><ul><li><p>Cloud security affects identity.</p></li><li><p>Identity affects SaaS security.</p></li><li><p>Data security affects AI governance.</p></li><li><p>Runtime security affects SOC operations.</p></li><li><p>Detection engineering affects platform strategy.</p></li></ul><p>The modern security stack is converging.</p><p>Yet most professionals still think in silos.</p><p>That creates massive blind spots.</p><p>A security leader might understand endpoint security but not cloud runtime.<br>A cloud engineer may understand CNAPP but not identity architecture.<br>An investor may understand revenue growth but not technical differentiation.<br>A founder may understand product but not market timing.</p><p>This is exactly where the industry is struggling.</p><p>And this is where the bootcamp becomes valuable.</p><p>We focus heavily on helping students connect the dots across the entire security ecosystem.</p><p>Not just technically.</p><p>Strategically.</p><div><hr></div><h1>What Makes This Bootcamp Different</h1><h3>1. You Learn the Market Through Real Vendors</h3><p>We do not teach cybersecurity in abstraction.</p><p>We teach through the companies shaping the industry.</p><p>Participants will see live product demos, strategic breakdowns, and architectural discussions involving major security vendors, including:</p><ul><li><p>Wiz</p></li><li><p>Palo Alto Networks</p></li><li><p>CrowdStrike</p></li><li><p>Okta</p></li><li><p>Cyera</p></li><li><p>Cribl</p></li><li><p>Abnormal Security</p></li></ul><p>And more.</p><p>Instead of simply learning definitions, students learn:</p><ul><li><p>Why these companies matter</p></li><li><p>What technical problems they solve</p></li><li><p>How they differentiate</p></li><li><p>Where the market is going</p></li><li><p>How enterprise buyers evaluate them</p></li><li><p>Where platform convergence is happening</p></li></ul><p>This creates an entirely different level of understanding.</p><p>You stop seeing cybersecurity as isolated products.</p><p>You begin seeing the broader architecture and strategic landscape.</p><div><hr></div><h3>2. The Program Bridges Technical + Strategic Thinking</h3><p>One of the biggest gaps in cybersecurity education today is the disconnect between technical operators and strategic decision-makers.</p><p>Technical professionals often lack market context.</p><p>Executives often lack architectural depth.</p><p>This bootcamp bridges both worlds.</p><p>We intentionally teach:</p><ul><li><p>Technical foundations</p></li><li><p>Security architecture evolution</p></li><li><p>Market dynamics</p></li><li><p>Vendor positioning</p></li><li><p>Platform strategy</p></li><li><p>AI-driven transformation</p></li><li><p>Enterprise buying behavior</p></li><li><p>Future industry trends</p></li></ul><p>This is particularly valuable for:</p><ul><li><p>CISOs</p></li><li><p>Security architects</p></li><li><p>SOC leaders</p></li><li><p>Product managers</p></li><li><p>Cybersecurity founders</p></li><li><p>Enterprise technology leaders</p></li><li><p>Investors and analysts</p></li><li><p>Aspiring cybersecurity professionals</p></li></ul><p>The reality is simple:</p><p>The highest-value cybersecurity professionals in 2026 will not just understand tools.</p><p>They will understand systems, strategy, economics, and architecture.</p><div><hr></div><h3>3. We Teach Cybersecurity Through First-Principles Thinking</h3><p>The cybersecurity industry is full of recycled buzzwords around AI or agentic. However, over 80% of vendors lack robust AI security foundations. The key question, though, is how we define <strong>a good vs. an average cyber vendor.</strong></p><p>Most professionals cannot separate marketing from reality.</p><p>That creates confusion.</p><p>At SACR, our research process has always focused on first-principles analysis.</p><p>We ask:</p><ul><li><p>What problem actually exists?</p></li><li><p>Why does this category matter?</p></li><li><p>What architectural shift created this opportunity?</p></li><li><p>Is this a feature or a platform?</p></li><li><p>Is the market real or temporary?</p></li><li><p>Does the buyer behavior support this category?</p></li><li><p>Does this vendor actually have defensibility?</p></li></ul><p>This framework changes how people think.</p><p>Students consistently tell us the bootcamp helped them finally understand:</p><ul><li><p>Why cloud security evolved into CNAPP</p></li><li><p>Why identity is becoming central to security</p></li><li><p>Why runtime security matters</p></li><li><p>Why data security is exploding</p></li><li><p>Why the SOC is being rebuilt with AI</p></li><li><p>Why platform consolidation is accelerating</p></li></ul><p>The point is not memorization.</p><p>The point is developing analytical judgment.</p><div><hr></div><h3>A Rare Opportunity to Learn How Cybersecurity Analysts &amp; SACR Thinks before we develop frameworks </h3><p>This alone has become one of the biggest reasons many professionals join the program.</p><p>This bootcamp is essentially an opportunity to step inside the process that develops and creates reports.</p><p>Think about it this way: imagine if Gartner or a leading analyst firm opened up its internal thinking, frameworks, and methodologies and allowed practitioners direct access to how analysts study the cybersecurity industry. That is the spirit behind this program.</p><p>Participants are not just learning definitions or technical concepts. They are learning how cybersecurity analysts evaluate markets, identify trends, compare vendors, understand platform shifts, and separate real innovation from noise.</p><p>Throughout the program, we will share the same strategic frameworks, research methodologies, and market insights that we use internally when analyzing cybersecurity companies and advising industry leaders. This includes how we think about cloud security evolution, identity-centric architectures, SOC transformation, AI security, platform consolidation, runtime security, and the future direction of enterprise defense.</p><p>The reality is that most cybersecurity professionals only see a small slice of the industry from inside their own organization or role. Analysts sit in a unique position because we see patterns across the broader market. We see how hundreds of companies are positioning themselves, how enterprise buyers evaluate tools, where CISOs are prioritizing spending, and where the industry is actually moving beneath the surface-level hype.</p><p>That perspective is difficult to access.</p><p>This bootcamp is designed to open that world up to practitioners, security leaders, aspiring analysts, investors, founders, and anyone who wants a much deeper understanding of how modern cybersecurity operates at both a technical and strategic level.</p><p>The goal is not simply to teach cybersecurity.</p><p>The goal is to teach participants how to think about cybersecurity at the industry level.</p><p>By the end of the program, participants should walk away with a completely different lens for understanding the market &#8212; one grounded in real-world operator insight, enterprise security priorities, vendor analysis, and long-term architectural thinking.</p><p></p><div><hr></div><h1>Who This Bootcamp Is Really For</h1><p>This program is designed for people who want leverage.</p><p>Not just information.</p><p>The ideal student is someone who wants to:</p><ul><li><p>Become more strategic in cybersecurity</p></li><li><p>Understand the modern AI security stack deeply</p></li><li><p>Learn how enterprise security decisions are made</p></li><li><p>Improve vendor evaluation skills</p></li><li><p>Speak confidently with security leaders</p></li><li><p>Transition into cybersecurity leadership</p></li><li><p>Understand where the market is heading</p></li><li><p>Build long-term career advantage</p></li></ul><p>Some participants are highly technical.</p><p>Others are not.</p><p>What matters most is intellectual curiosity and the willingness to understand how cybersecurity actually works beneath the surface.</p><div><hr></div><h1>The AI Shift &amp; Why the Timing Matters</h1><p>This may be the most important transition the industry has seen in over a decade. The cybersecurity market is entering another major transition cycle.</p><p>Over the next 3&#8211;5 years, we will likely see:</p><ul><li><p>AI-driven restructuring of security operations</p></li><li><p>Expansion of identity-centric architectures</p></li><li><p>New security governance requirements around AI</p></li></ul><p>The professionals who understand these transitions early will have a massive advantage. Not just technically. Professionally. </p><p>This bootcamp dedicates significant attention to helping participants understand:</p><ul><li><p>Security for AI</p></li><li><p>AI for security</p></li><li><p>AI-driven SOC transformation</p></li><li><p>AI governance</p></li><li><p>Emerging AI security categories</p></li><li><p>The future security architecture around AI systems</p></li></ul><p>Cyber is becoming one of the central operational layers of modern enterprises. AI is not simply adding automation. It is changing the cybersecurity operating model. At the same time, enterprises are rushing to deploy AI internally without fully understanding the risks. </p><div><hr></div><h1>The Goal of the Bootcamp</h1><p>The goal is not to make you memorize categories. The goal is to change how you think. Our strongest differentiators you&#8217;ll get are:</p><ul><li><p>Access to analyst thinking</p></li><li><p>Exposure to real vendor/product analysis</p></li><li><p>Understanding market structure</p></li><li><p>CISO-informed perspectives</p></li><li><p>Pattern recognition across 600+ vendors</p></li><li><p>Frameworks for evaluating categories and hype</p></li><li><p>Strategic understanding beyond technical tooling</p></li></ul><p></p><p><strong>We want participants to leave with:</strong></p><ol><li><p>A mental framework for understanding cybersecurity markets</p></li><li><p>A stronger understanding of modern security architecture</p></li><li><p>Better judgment around vendor evaluation</p></li><li><p>Clearer insight into where the industry is going</p></li><li><p>Higher confidence in strategic cybersecurity discussions</p></li><li><p>Stronger positioning for leadership opportunities</p></li></ol><p>Most importantly:</p><p>We want students to stop reacting to cybersecurity noise and start thinking structurally. That is the real advantage.</p><p></p><div><hr></div><h2>AI Cybersecurity Bootcamp for Cyber Leaders</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xfD6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F996045d6-ec1f-43c0-a7fb-91991200a94e_832x1046.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xfD6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F996045d6-ec1f-43c0-a7fb-91991200a94e_832x1046.png 424w, https://substackcdn.com/image/fetch/$s_!xfD6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F996045d6-ec1f-43c0-a7fb-91991200a94e_832x1046.png 848w, https://substackcdn.com/image/fetch/$s_!xfD6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F996045d6-ec1f-43c0-a7fb-91991200a94e_832x1046.png 1272w, https://substackcdn.com/image/fetch/$s_!xfD6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F996045d6-ec1f-43c0-a7fb-91991200a94e_832x1046.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xfD6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F996045d6-ec1f-43c0-a7fb-91991200a94e_832x1046.png" width="274" height="344.47596153846155" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/996045d6-ec1f-43c0-a7fb-91991200a94e_832x1046.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1046,&quot;width&quot;:832,&quot;resizeWidth&quot;:274,&quot;bytes&quot;:840722,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://softwareanalyst.substack.com/i/197366816?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F996045d6-ec1f-43c0-a7fb-91991200a94e_832x1046.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!xfD6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F996045d6-ec1f-43c0-a7fb-91991200a94e_832x1046.png 424w, https://substackcdn.com/image/fetch/$s_!xfD6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F996045d6-ec1f-43c0-a7fb-91991200a94e_832x1046.png 848w, https://substackcdn.com/image/fetch/$s_!xfD6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F996045d6-ec1f-43c0-a7fb-91991200a94e_832x1046.png 1272w, https://substackcdn.com/image/fetch/$s_!xfD6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F996045d6-ec1f-43c0-a7fb-91991200a94e_832x1046.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>Live Cohort-Based Program // On-demand Program </h3><p>Taught by:</p><ul><li><p>Francis Odum: CEO &amp; Chief Cybersecurity Analyst, SACR</p></li><li><p>Lawrence Pingree: Head of Research, SACR  </p></li></ul><p>Enrollment is now open.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://maven.com/cybersecuritybootcamp/cybersecurity-bootcamp-for-leaders&quot;,&quot;text&quot;:&quot;Cybersecurity Bootcamp&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://maven.com/cybersecuritybootcamp/cybersecurity-bootcamp-for-leaders"><span>Cybersecurity Bootcamp</span></a></p><p>Explore the full curriculum and reserve your spot here. If you have any questions, inquiries or anything: please email me at: sarah@softwareanalyst.ca // nupur@softwareanalyst.ca  </p><div><hr></div><p><em>The leaders who can filter signal from noise will define the next decade.</em></p><p></p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Software Analyst Cyber Research! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div class="directMessage button" data-attrs="{&quot;userId&quot;:6770950,&quot;userName&quot;:&quot;SACR&quot;,&quot;canDm&quot;:null,&quot;dmUpgradeOptions&quot;:null,&quot;isEditorNode&quot;:true}" data-component-name="DirectMessageToDOM"></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/p/inside-the-new-cybersecurity-playbook/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/p/inside-the-new-cybersecurity-playbook/comments"><span>Leave a comment</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/p/inside-the-new-cybersecurity-playbook?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/p/inside-the-new-cybersecurity-playbook?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[The Cybersecurity Implications of Claude Mythos and OpenAI Cyber]]></title><description><![CDATA[How offensive and defensive AI agents are reshaping vulnerability economics, patch governance, and the future of software resilience]]></description><link>https://softwareanalyst.substack.com/p/the-cybersecurity-implications-of</link><guid isPermaLink="false">https://softwareanalyst.substack.com/p/the-cybersecurity-implications-of</guid><dc:creator><![CDATA[Francis Odum]]></dc:creator><pubDate>Mon, 11 May 2026 18:55:26 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!4X7b!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc09fadab-94c8-480a-b44e-e961d58723df_2014x1410.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div><hr></div><h1><strong>Core Thesis</strong></h1><p>By now, most security leaders have read the headlines on Mythos and what it could mean for the future of cybersecurity. The question is no longer whether Mythos matters. The real question is what it changes for enterprise security teams.</p><p>SACR spoke with CISOs about how they are interpreting Mythos, where they see the greatest organizational impact, and how they believe security programs need to evolve. This report summarizes those conversations and our conclusions.</p><p>Our core thesis is simple: Mythos compresses time across all of cybersecurity. It shortens the window between vulnerability discovery, exploit creation, and real world exploitation. Security programs built around human-paced workflows, periodic scanning, manual triage, ticket-based remediation, quarterly testing, and slow patch cycles were not designed for this environment.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4X7b!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc09fadab-94c8-480a-b44e-e961d58723df_2014x1410.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4X7b!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc09fadab-94c8-480a-b44e-e961d58723df_2014x1410.png 424w, https://substackcdn.com/image/fetch/$s_!4X7b!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc09fadab-94c8-480a-b44e-e961d58723df_2014x1410.png 848w, https://substackcdn.com/image/fetch/$s_!4X7b!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc09fadab-94c8-480a-b44e-e961d58723df_2014x1410.png 1272w, https://substackcdn.com/image/fetch/$s_!4X7b!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc09fadab-94c8-480a-b44e-e961d58723df_2014x1410.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4X7b!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc09fadab-94c8-480a-b44e-e961d58723df_2014x1410.png" width="1456" height="1019" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c09fadab-94c8-480a-b44e-e961d58723df_2014x1410.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1019,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2844281,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://softwareanalyst.substack.com/i/195066990?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc09fadab-94c8-480a-b44e-e961d58723df_2014x1410.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!4X7b!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc09fadab-94c8-480a-b44e-e961d58723df_2014x1410.png 424w, https://substackcdn.com/image/fetch/$s_!4X7b!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc09fadab-94c8-480a-b44e-e961d58723df_2014x1410.png 848w, https://substackcdn.com/image/fetch/$s_!4X7b!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc09fadab-94c8-480a-b44e-e961d58723df_2014x1410.png 1272w, https://substackcdn.com/image/fetch/$s_!4X7b!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc09fadab-94c8-480a-b44e-e961d58723df_2014x1410.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>This creates a new operating reality for CISOs. If attackers can use AI to find and weaponize weaknesses at machine speed, defenders will need to use AI to prevent, test, prioritize, remediate, and contain at comparable speed. AI fighting AI is becoming the only viable long-term defence strategy.</p><p>Runtime defense also becomes more important because prevention will still fail. When it does, organizations need enforcement closer to applications, identities, endpoints, browsers, and cloud control planes, paired with higher fidelity detection and faster containment. The goal is not simply to detect more. It is to reduce the blast radius before one exploit becomes a business-level incident. Organizations need the ability to patch quickly, validate changes through robust testing, deploy via canary releases, and roll back when something breaks. </p><p>In short, Mythos is not just a story about better offensive AI. It is a forcing function for a new security operating model. The organizations that adapt fastest will be the ones that can continuously find, validate, fix, contain, and recover at machine speed while preserving the governance, judgment, and operational discipline that enterprise security still requires.</p><p></p><div><hr></div><h3><strong>Co-authors:</strong></h3><ul><li><p><em><a href="mailto:francis@softwareanalyst.ca">Francis Odum</a> is the Founder/CEO of the Software Analyst Cyber Research, where he leads the firm&#8217;s research and engagement with cybersecurity leaders.</em></p></li><li><p><em><a href="https://www.linkedin.com/in/lawrencepingree/">Lawrence Pingree</a> is the Head of Data and AI Security at SACR, where he leads research on data protection, AI security, and agentic security models. He brings more than 10 years of analyst experience at Gartner and has authored over 300 research notes on cloud security, endpoint defence, SD-WAN, and AI security.</em></p></li><li><p><em><a href="mailto:sean@softwareanalyst.ca">Sean Sosnowski</a> serves as the Research Director for Security Operations and Cloud Security at SACR, where he leads research on SOC strategy and operations and detection engineering. Drawing on a decade of intelligence experience in the U.S. Marine Corps.</em></p></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Software Analyst Cyber Research! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><div><hr></div><h1><strong>Executive Summary</strong></h1><p>Anthropic's new frontier model, Claude Mythos Preview, represents a step change in cybersecurity risk, transforming software exploitation into an automatable industrial process. The model, currently in limited testing via Project Glasswing (launched Apr 7, 2026), demonstrates the capability to achieve over 83% accuracy in finding new vulnerabilities. This significantly lowers the barrier to entry and compresses the time required to develop working exploits, effectively making Zero Days sub-hour vulnerabilities.</p><p>Mythos can autonomously identify and exploit thousands of high-severity vulnerabilities across all major operating systems and web browsers, shifting the asymmetric advantage toward attackers. The primary challenge is now remediation speed, as the volume of AI-discovered vulnerabilities overwhelms the capacity of developers and owners. </p><p>In response, OpenAI released GPT-5.5 and GPT-5.4-Cyber, focusing on specialized defensive autonomous agents capable of advanced tasks like binary reverse engineering. This strategic shift, supported by the Trusted Access for Cyber (TAC) program, establishes a high-speed competition between offensive models and defensive frameworks.</p><p></p><p><strong>Key Takeaways</strong></p><ul><li><p>Exploitation windows are collapsing to sub-5 minutes, effectively making Zero Days &#8220;sub-hour&#8221; vulnerabilities.</p></li><li><p>The volume of AI-discovered bugs is currently overwhelming remediation capacity, requiring new commercial or consortium-led fixes.</p></li><li><p>Defenders must leverage models like Mythos for automated counter-signatures and proactive patching in critical infrastructure like Linux.</p></li></ul><p></p><h1><strong>Project Glasswing </strong></h1><h3>Critical Insights</h3><ul><li><p><a href="https://www.anthropic.com/project/glasswing">On Apr 7, 2026, Anthropic launched Project Glasswing</a>, explicitly positioning Mythos Preview as a model whose vulnerability discovery/exploitation capabilities are high enough that a broad release is unsafe right now.</p></li><li><p>Anthropic publicly acknowledged and began a limited test of a new frontier model referred to as Claude Mythos Preview, describing it as a step change in capability and their most capable model to date, currently trialled with early access customers.</p></li><li><p>Anthropic claims that Mythos Preview has already found thousands of high-severity vulnerabilities, including in every major operating system and web browser (and states the capability to produce working exploits under some test conditions).</p></li><li><p>A Reuters piece highlights immediate concern for banks and other legacy-heavy sectors, including reports of government discussions with financial institutions about the threat model and the practical consequences of a lowered exploitation skill barrier.</p></li><li><p>Media framing is converging on hacker superweapon vs security reckoning, with emphasis that the bigger story may be software security debt meeting near-autonomous exploitation.</p></li><li><p>Reports of third-party access to Mythos are being investigated at the time of this report's authoring. This highlights the risk that Mythos can be targeted by nation-states and other nefarious actors to gain an advantage through third-party compromise.</p></li></ul><p></p><h2><strong>Mythos is less a new threat actor and more an advancement of progressing capability</strong></h2><p></p><h2><strong>Claude Mythos &amp; Project Glasswing</strong></h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!cNbM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51fc51f9-b3b8-48da-9aba-c9e51d3bd672_1600x900.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!cNbM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51fc51f9-b3b8-48da-9aba-c9e51d3bd672_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!cNbM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51fc51f9-b3b8-48da-9aba-c9e51d3bd672_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!cNbM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51fc51f9-b3b8-48da-9aba-c9e51d3bd672_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!cNbM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51fc51f9-b3b8-48da-9aba-c9e51d3bd672_1600x900.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!cNbM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51fc51f9-b3b8-48da-9aba-c9e51d3bd672_1600x900.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/51fc51f9-b3b8-48da-9aba-c9e51d3bd672_1600x900.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!cNbM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51fc51f9-b3b8-48da-9aba-c9e51d3bd672_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!cNbM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51fc51f9-b3b8-48da-9aba-c9e51d3bd672_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!cNbM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51fc51f9-b3b8-48da-9aba-c9e51d3bd672_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!cNbM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51fc51f9-b3b8-48da-9aba-c9e51d3bd672_1600x900.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>While Mythos introduces unprecedented offensive pressure, it also establishes a new template for defensive governance. Project Glasswing can be interpreted as an emergent governance pattern for frontier cyber capabilities in the future:</p><ul><li><p>Restricted access to reduce near-term weaponization risk</p></li><li><p>Coordinated hardening of widely used / critical software</p></li><li><p>Pooled funding , usage credits and greater OSS support</p></li><li><p>structured learning capture to uplift industry practices</p></li></ul><p>Mythos is forcing a software security reckoning by exposing the real systemic weakness in most environments: not merely slow detection, but years of accumulated engineering and maintenance debt that left production software brittle, difficult to patch, and easy to break. As coverage notes, this is a wake-up call for organizations that have treated security as an afterthought in software development.</p><p>The central issue doesn&#8217;t revolve around a single benchmark result. If a model compresses the time and expertise required for vulnerability discovery, exploit construction, and validation, the practical effect is a higher volume of credible exploit attempts arriving faster than most organizations can patch safely. Under that pressure, the key variable becomes remediation capacity. The ability to validate fixes, tolerate controlled downtime, and ship reversible changes before exposure compounds. This frames Mythos as a software liability and operations problem as much as it is a detection problem.</p><p>The implication is stark: SOC excellence is demanded without secure production capability and becomes structurally insufficient, because faster investigation does not matter if fixes can&#8217;t be shipped safely and quickly. In a Mythos world, the most durable control becomes the ability to deliver safe, reversible change at high velocity, utilizing tight feedback loops, strong pre-deployment validation, canarying, and instant rollback so that mitigation and remediation can keep pace with industrialized exploitation.</p><ul><li><p><strong>Capabilities:</strong> Unlike general-purpose LLMs, Mythos can discover and exploit complex, high-severity bugs across operating systems and browsers. Notably, it successfully exploited a 27-year-old patched flaw in OpenBSD. This highlights Mythos&#8217;s capacity for vulnerability research on historical security fixes, implying that the entire backlog of previously fixed bugs is now effectively a fresh attack surface, as Mythos can chain or re-exploit subtle errors in the original patch.</p></li><li><p><strong>Project Glasswing:</strong> Anthropic&#8217;s defensive initiative providing Mythos access to select organizations (e.g., Apple, AWS, Microsoft) and $100 million in credits to help defenders prepare before the model becomes widely available.</p></li><li><p><strong>Anthropic Financial Support Offered:</strong> The firm is also donating $4 million to open-source security organizations to help reshape the cybersecurity landscape. This may need to widen to become an industry wide initiative to fund open source remediation.</p></li></ul><p></p><h2><strong>The Mythos Model: Expert Exploitation Capabilities and Risks Emerge</strong></h2><p>Anthropic&#8217;s latest LLM demonstrates a significant leap in cybersecurity reasoning, moving beyond simple code assistance to active exploitation.</p><ul><li><p><strong>Autonomous Exploitation:</strong> Mythos can identify and exploit vulnerabilities across all major operating systems and web browsers.</p></li><li><p><strong>Advanced Technical Sophistication:</strong> It has successfully chained four separate vulnerabilities to escape sandboxes, bypassed Kernel Address Space Layout Randomization (KASLR), and exploited complex race conditions.</p></li><li><p><strong>Low Barrier to Entry:</strong> The model allows users without deep security engineering backgrounds to generate complex exploits, such as 20-gadget ROP (Return-Oriented Programming) chains.</p></li><li><p><strong>Dual-Use Dilemma:</strong> The same reasoning improvements that help developers patch code also make the model a potent weapon for threat actors.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!A24r!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F537d5879-ebcf-45f8-939e-3d7c2b98e44f_1600x900.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!A24r!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F537d5879-ebcf-45f8-939e-3d7c2b98e44f_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!A24r!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F537d5879-ebcf-45f8-939e-3d7c2b98e44f_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!A24r!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F537d5879-ebcf-45f8-939e-3d7c2b98e44f_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!A24r!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F537d5879-ebcf-45f8-939e-3d7c2b98e44f_1600x900.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!A24r!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F537d5879-ebcf-45f8-939e-3d7c2b98e44f_1600x900.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/537d5879-ebcf-45f8-939e-3d7c2b98e44f_1600x900.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!A24r!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F537d5879-ebcf-45f8-939e-3d7c2b98e44f_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!A24r!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F537d5879-ebcf-45f8-939e-3d7c2b98e44f_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!A24r!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F537d5879-ebcf-45f8-939e-3d7c2b98e44f_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!A24r!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F537d5879-ebcf-45f8-939e-3d7c2b98e44f_1600x900.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>An AI Vulnerability Storm is a potential future</strong></h3><p>The CSA and security luminaries (including Jen Easterly and Bruce Schneier) argue that Mythos represents a sea change in risk:</p><ul><li><p><strong>Asymmetric Attacker Advantage:</strong> Attackers gain more from AI automation than defenders, as current patch cycles and risk metrics cannot keep pace with the volume of AI-discovered vulnerabilities.</p></li><li><p><strong>Increased Workload:</strong> Organizations should expect a dramatic increase in novel attacks and a volume of disclosures that exceeds all historical precedents if Mythos is released more widely.</p></li></ul><p></p><h2>AI Security Institute (AISI) Testing</h2><p>AI Security Institute&#8217;s (AISI) evaluation of Anthropic&#8217;s Claude Mythos Preview (released April 2026), highlighting a significant leap in autonomous cybersecurity capabilities compared to previous models. (<a href="https://www.aisi.gov.uk/blog/our-evaluation-of-claude-mythos-previews-cyber-capabilities">see here</a>)</p><p><strong>Key Findings: Capture-the-Flag (CTF)</strong></p><p>AISI utilized CTF challenges to measure the model&#8217;s ability to identify and exploit isolated vulnerabilities.</p><ul><li><p><strong>Expert-Level Breakthrough:</strong> Mythos Preview successfully completed expert-level tasks <strong>73% of the time</strong>.</p></li><li><p><strong>Historical Context:</strong> Prior to April 2025, no AI model was capable of completing tasks at this difficulty level.</p></li><li><p><strong>Rapid Progression:</strong> The model outperformed all previous frontier models, including Claude 4 Opus and GPT-5, across technical, apprentice, and practitioner levels</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Vh5G!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce0e3818-c9fd-4ca6-8144-59b1b18c9822_2048x1141.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Vh5G!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce0e3818-c9fd-4ca6-8144-59b1b18c9822_2048x1141.png 424w, https://substackcdn.com/image/fetch/$s_!Vh5G!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce0e3818-c9fd-4ca6-8144-59b1b18c9822_2048x1141.png 848w, https://substackcdn.com/image/fetch/$s_!Vh5G!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce0e3818-c9fd-4ca6-8144-59b1b18c9822_2048x1141.png 1272w, https://substackcdn.com/image/fetch/$s_!Vh5G!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce0e3818-c9fd-4ca6-8144-59b1b18c9822_2048x1141.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Vh5G!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce0e3818-c9fd-4ca6-8144-59b1b18c9822_2048x1141.png" width="1456" height="811" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ce0e3818-c9fd-4ca6-8144-59b1b18c9822_2048x1141.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:811,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Vh5G!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce0e3818-c9fd-4ca6-8144-59b1b18c9822_2048x1141.png 424w, https://substackcdn.com/image/fetch/$s_!Vh5G!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce0e3818-c9fd-4ca6-8144-59b1b18c9822_2048x1141.png 848w, https://substackcdn.com/image/fetch/$s_!Vh5G!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce0e3818-c9fd-4ca6-8144-59b1b18c9822_2048x1141.png 1272w, https://substackcdn.com/image/fetch/$s_!Vh5G!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce0e3818-c9fd-4ca6-8144-59b1b18c9822_2048x1141.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HdN_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6f40803-e58e-4575-8644-c61a476c88e8_2048x1141.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HdN_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6f40803-e58e-4575-8644-c61a476c88e8_2048x1141.png 424w, https://substackcdn.com/image/fetch/$s_!HdN_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6f40803-e58e-4575-8644-c61a476c88e8_2048x1141.png 848w, https://substackcdn.com/image/fetch/$s_!HdN_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6f40803-e58e-4575-8644-c61a476c88e8_2048x1141.png 1272w, https://substackcdn.com/image/fetch/$s_!HdN_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6f40803-e58e-4575-8644-c61a476c88e8_2048x1141.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HdN_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6f40803-e58e-4575-8644-c61a476c88e8_2048x1141.png" width="1456" height="811" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d6f40803-e58e-4575-8644-c61a476c88e8_2048x1141.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:811,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!HdN_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6f40803-e58e-4575-8644-c61a476c88e8_2048x1141.png 424w, https://substackcdn.com/image/fetch/$s_!HdN_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6f40803-e58e-4575-8644-c61a476c88e8_2048x1141.png 848w, https://substackcdn.com/image/fetch/$s_!HdN_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6f40803-e58e-4575-8644-c61a476c88e8_2048x1141.png 1272w, https://substackcdn.com/image/fetch/$s_!HdN_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6f40803-e58e-4575-8644-c61a476c88e8_2048x1141.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h4><strong>Mythos caused a shock that collapses the attacker's cost curve</strong>:</h4><ul><li><p>Most Notable Fact: It compresses the time and skills required to go from target selection to working exploit to repeatable exploitation.</p></li><li><p>Defensive advantage shifts from detecting faster to shipping less buggy software, properly constraining blast radius, and proving patch safety.</p></li><li><p>The security winners will treat exploitation as a continuous, automated supply chain and build a corresponding continuous prevention/patch pipeline.</p></li></ul><p></p><p>Three deltas implied by Anthropic&#8217;s own write-ups:</p><ol><li><p><strong>End-to-end exploitability</strong>: This is not just a spot bug or suggested fix, but produces a working exploit under realistic scaffolding, a significant progression on vulnerability exploitation.</p></li><li><p><strong>Lowered expertise barrier</strong>: Anthropic describes non-security engineers producing serious results quickly with the model.</p></li><li><p><strong>Acceleration to scale</strong>: If a model can reliably traverse the exploit chain, the limiting aspects become compute, access, and targeting, not human talent.</p></li></ol><h3><strong>Immediate implications (CISOs and Boards Should Know)</strong></h3><p><strong>A) Vulnerability economics flips</strong></p><ul><li><p>Expect more disclosures of new bugs that are being exploited, especially in legacy and bespoke environments (banks and critical infrastructure have been explicitly called out by multiple parties publicly).</p></li></ul><p><strong>B) Time-to-exploit compresses further</strong></p><ul><li><p>Security programs built around weekly or monthly remediation cadences will be structurally mismatched. This has likely already been the case for many enterprises, but the autonomous operation makes full autonomous exploitation a more pronounced reality, especially since agentic properties are accelerated (e.g., the ability to systematically move through various stages of attack).</p></li></ul><p><strong>C) Detection-only postures degrade</strong></p><ul><li><p>If exploit development becomes cheaper and faster, novelty increases and generic detections underperform. This acts as a forcing function, pushing enterprises to use AI and AI agents for defence and to ramp up speed to decisions, responses and emphasizes prevention over detection and response.</p></li></ul><h3>Figure 1. Proof of Adversarial Threat That Mythos Poses</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!w3u2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b2a2652-b118-45c4-8c5d-0c873711660b_1600x1000.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!w3u2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b2a2652-b118-45c4-8c5d-0c873711660b_1600x1000.png 424w, https://substackcdn.com/image/fetch/$s_!w3u2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b2a2652-b118-45c4-8c5d-0c873711660b_1600x1000.png 848w, https://substackcdn.com/image/fetch/$s_!w3u2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b2a2652-b118-45c4-8c5d-0c873711660b_1600x1000.png 1272w, https://substackcdn.com/image/fetch/$s_!w3u2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b2a2652-b118-45c4-8c5d-0c873711660b_1600x1000.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!w3u2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b2a2652-b118-45c4-8c5d-0c873711660b_1600x1000.png" width="1456" height="910" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6b2a2652-b118-45c4-8c5d-0c873711660b_1600x1000.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:910,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!w3u2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b2a2652-b118-45c4-8c5d-0c873711660b_1600x1000.png 424w, https://substackcdn.com/image/fetch/$s_!w3u2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b2a2652-b118-45c4-8c5d-0c873711660b_1600x1000.png 848w, https://substackcdn.com/image/fetch/$s_!w3u2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b2a2652-b118-45c4-8c5d-0c873711660b_1600x1000.png 1272w, https://substackcdn.com/image/fetch/$s_!w3u2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b2a2652-b118-45c4-8c5d-0c873711660b_1600x1000.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Source: <a href="https://www.aisi.gov.uk/blog/our-evaluation-of-claude-mythos-previews-cyber-capabilities">AI Institute </a>(April 13 2026)</p><div><hr></div><p></p><h2>OpenAI GPT-5.5 and GPT-5.4 (Cybersecurity) Released in tandem March/April</h2><p>In direct response to this shifting landscape, the introduction of GPT-5.5 and GPT-5.4-Cyber signifies a pivotal shift in OpenAI&#8217;s strategy toward specialized, autonomous agents for defensive operations. This marks a significant move toward using AI to counter AI-driven exploitation, creating a state of high-speed competition between offensive models like Mythos and defensive frameworks like OpenAI Cyber.</p><p>Key details of the GPT-5.5 announcement include:</p><ul><li><p><strong>Accelerated Release Cycles: </strong>The rapid transition from GPT-5.4 to 5.5 demonstrates an intensified development pace designed to maintain a competitive edge over frontier models like Anthropic&#8217;s Claude Mythos.</p></li><li><p><strong>Enhanced Reasoning and Persistence: </strong>GPT-5.5 exhibits more persistent behavior in coding tasks, utilizing fewer tokens while achieving more reliable tool integration compared to GPT-5.4 and Claude Opus 4.7.</p></li><li><p><strong>Specialized Defensive Capabilities: </strong>The GPT-5.4-Cyber variant introduces binary reverse engineering, allowing defenders to analyze compiled malware and identify vulnerabilities without source code access&#8212;a major technical milestone for automated defense.</p></li><li><p><strong>Governance and Trusted Access: </strong>To balance capability with safety, OpenAI has deployed the Trusted Access for Cyber (TAC) program, requiring identity verification (KYC) to prevent misuse by malicious actors while empowering verified security experts.</p></li></ul><p></p><h3><strong>Model Release &amp; Availability</strong></h3><ul><li><p><strong>Rapid Iteration:</strong> GPT-5.5 arrives shortly after GPT-5.4 Cyber, signalling an accelerated release cycle.</p></li><li><p><strong>Access Tiers:</strong> Currently rolling out to Plus, Pro, Business, and Enterprise users via ChatGPT and Codex; API access is expected soon.</p></li><li><p><strong>Variants:</strong> GPT-5.5 Pro is available only on the Pro, Business, and Enterprise tiers.</p></li></ul><p></p><h3><strong>Key Performance Enhancements</strong></h3><ul><li><p><strong>Reasoning &amp; Autonomy:</strong> Tests show superior performance compared to GPT-5.4 and Claude Opus 4.7, particularly in identifying issues and anticipating needs without explicit prompting.</p></li><li><p><strong>Coding &amp; Tool Use:</strong> The model is characterized by greater persistence, more reliable tool integration, and higher token efficiency (using fewer tokens for the same coding tasks).</p></li><li><p><strong>Niche Expertise:</strong> In cybersecurity, the model can perform complex tasks that even many human experts lack the specialized knowledge to perform.</p></li></ul><p></p><h3><strong>Cybersecurity &amp; Safety Frameworks</strong></h3><ul><li><p><strong>Advanced Safeguards:</strong> OpenAI implemented its most rigorous safety suite to date, including refined controls for high-risk activities and authenticated access.</p></li><li><p><strong>Vulnerability Research:</strong> While the model streamlines workflows for vulnerability discovery and exploitation, especially for novice and mid-level operators, it remains limited in &#8220;real-world&#8221; operational security.</p></li><li><p><strong>Testing:</strong> Evaluated through internal and external red-teaming, biology-specific stress tests, and feedback from 200 early-access partners.</p><p></p></li></ul><p></p><h2><strong>The Three Pillars of OpenAI&#8217;s Latest Release Approach</strong></h2><p>OpenAI&#8217;s strategy focuses on balancing broad access with rigorous safety controls:</p><ul><li><p><strong>Democratic Access (KYC &amp; TAC):</strong> Utilizing Know Your Customer (KYC) validation and the Trusted Access for Cyber (TAC) automated system to ensure legitimate users get access without arbitrary gatekeeping.</p></li><li><p><strong>Iterative Deployment:</strong> A careful release process designed to gather real-world feedback on model resilience against jailbreaks and adversarial attacks.</p></li><li><p><strong>Defensive Investment:</strong> Direct support for software security through grants, open-source donations (e.g., to the Linux Foundation), and dedicated tools like the Codex Security agent.</p></li></ul><p></p><h2><strong>Philosophical Differences</strong></h2><p>While Anthropic suggests that advanced AI necessitates a fundamental cybersecurity reckoning, OpenAI maintains that current safeguards are sufficient for now. However, OpenAI acknowledges that as AI capabilities eventually exceed purpose-built models, more expansive defences will be required in the long term.</p><p></p><h2>OpenAI 5.4-Cyber Released in Response to Anthropic Mythos</h2><p><strong>GPT-5.4-Cyber</strong>, a specialized variant of its flagship model designed to empower cybersecurity defenders. Released in April 2026, this move follows shortly after Anthropic&#8217;s rollout of Mythos and marks a significant shift toward AI-driven defensive security. SACR believes GPT-5.4&#8217;s release was partially driven by competitive pressure as users reportedly explored alternatives like Anthropic&#8217;s Claude. Below, we review specific differences between the two organization&#8217;s releases.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!B8Sz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc44b6f29-1e49-414e-8fd9-ac6a7abfb099_1080x1350.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!B8Sz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc44b6f29-1e49-414e-8fd9-ac6a7abfb099_1080x1350.png 424w, https://substackcdn.com/image/fetch/$s_!B8Sz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc44b6f29-1e49-414e-8fd9-ac6a7abfb099_1080x1350.png 848w, https://substackcdn.com/image/fetch/$s_!B8Sz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc44b6f29-1e49-414e-8fd9-ac6a7abfb099_1080x1350.png 1272w, https://substackcdn.com/image/fetch/$s_!B8Sz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc44b6f29-1e49-414e-8fd9-ac6a7abfb099_1080x1350.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!B8Sz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc44b6f29-1e49-414e-8fd9-ac6a7abfb099_1080x1350.png" width="1080" height="1350" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c44b6f29-1e49-414e-8fd9-ac6a7abfb099_1080x1350.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1350,&quot;width&quot;:1080,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:121295,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://softwareanalyst.substack.com/i/195066990?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc44b6f29-1e49-414e-8fd9-ac6a7abfb099_1080x1350.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!B8Sz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc44b6f29-1e49-414e-8fd9-ac6a7abfb099_1080x1350.png 424w, https://substackcdn.com/image/fetch/$s_!B8Sz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc44b6f29-1e49-414e-8fd9-ac6a7abfb099_1080x1350.png 848w, https://substackcdn.com/image/fetch/$s_!B8Sz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc44b6f29-1e49-414e-8fd9-ac6a7abfb099_1080x1350.png 1272w, https://substackcdn.com/image/fetch/$s_!B8Sz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc44b6f29-1e49-414e-8fd9-ac6a7abfb099_1080x1350.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>GPT 5.4 Cyber Core Features &amp; Capabilities</strong></h3><ul><li><p><strong>GPT&#8209;5.4&#8209;Cyber:</strong> Is a fine&#8209;tuned defensive cybersecurity model built on GPT&#8209;5.4, optimized for real&#8209;world threat analysis, secure coding, and adversarial testing.</p></li><li><p><strong>Binary Reverse Engineering:</strong> A major technical milestone allowing security experts to analyze compiled software for malware and vulnerabilities without requiring access to source code.</p></li><li><p><strong>Reduced Refusal Boundaries:</strong> The model is fine-tuned to be more permissive guardrails for legitimate security tasks, bypassing standard AI restrictions that might otherwise hinder defensive research.</p></li><li><p><strong>Codex Security Integration:</strong> Leverages a tool that has already identified and patched over 3,000 critical vulnerabilities during its research preview phase. Supports vulnerability scanning, exploit&#8209;chain reasoning, and deep inspection of software components.</p></li></ul><p></p><h3><strong>GPT 5.4 Cyber Access &amp; Verification (TAC Program)</strong></h3><p>To prevent misuse by threat actors, OpenAI is utilizing its <strong>Trusted Access for Cyber (TAC)</strong> program:</p><ul><li><p><strong>Tiered Availability:</strong> Claims that it&#8217;s the most advanced Cyber model reserved for customers in the highest service tiers.</p></li><li><p><strong>Target Audience:</strong> Open to thousands of individual defenders and hundreds of teams securing critical infrastructure.</p></li><li><p><strong>Authenticated and Trusted Access: </strong>Use of advanced features requires identity verification via <a href="http://chatgpt.com/cyber">chatgpt.com/cyber</a>. OpenAI expanded its Trusted Access for Cyber; the program is available to thousands of verified experts to give defensive researchers prioritized access to frontier models.</p></li></ul><p></p><h2><strong>GPT 5.4 Cyber Industry Context</strong></h2><p>Debate continues on both foundation model providers, and the ramifications they espouse highlight a rift among security experts where skeptics argue that catastrophic rhetoric may lead to power consolidation among tech giants and fuel anti-hacker sentiment, while alarmists warn that agentic AI could allow a broader range of bad actors to exploit known vulnerabilities with unprecedented speed. SACR&#8217;s position is that this is an obvious extension of where vulnerability research was already headed in AI; it continues to be impactful, but it is only a key accelerant at this time. This occurs against the backdrop of CVE (Common Vulnerability and Exploitation) reduction by NIST for NVD enrichment (see <a href="https://www.nist.gov/news-events/news/2026/04/nist-updates-nvd-operations-address-record-cve-growth">NIST Updates NVD Operations to Address Record CVE Growth</a>), which seems to confirm the inadequacy of multiple parties to deal with the rising AI-based reporting of net-new vulnerabilities.</p><p></p><p></p><h2><strong>Economic and Regulatory Consequences</strong></h2><p>The collapse of the time-to-exploit window introduces profound financial and compliance pressures on organizations:</p><ul><li><p><strong>Cyber Insurance Impact:</strong> The sudden shift to sub-hour vulnerabilities will force underwriters to re-evaluate policy coverage, significantly raise premiums, and alter risk models due to the increased frequency and speed of high-impact breaches.</p></li><li><p><strong>Liability and Fines:</strong> Regulatory bodies are expected to increase pressure on organizations, particularly those in critical infrastructure, to maintain a zero-vulnerability backlog. Non-compliance, where a sub-hour vulnerability leads to a breach due to slow patching, will carry higher financial penalties and fines.</p></li><li><p><strong>Vendor Ecosystem Disruption:</strong> Traditional vulnerability management and security service vendors must rapidly adapt their offerings to incorporate AI-driven remediation and prevention tools, or face obsolescence as human-speed solutions become inadequate.</p></li></ul><div><hr></div><p></p><h3>Recommendations for CISO</h3><p>Based on our extensive discussions with all the security leaders, we got the following perspectives that we are sharing with the community:   </p><ol><li><p><strong>Shift security left by turning developers into the first-line control:</strong> Treat &#8220;Mythos-speed&#8221; exploitation as a development-time problem, not just a SOC problem: every engineering team should own secure-by-default configuration, dependency hygiene, and patch discipline as part of normal delivery. Operationally, mandate AI-assisted code review and vulnerability triage in the IDE/CI pipeline, with clear SLAs for fixing internet-exposed issues and guardrails that block risky changes from shipping without explicit approval. This is the only scalable way to reduce the amount of exploitable surface area that reaches production when attackers can move from disclosure to exploit in minutes.</p></li><li><p><strong>Run continuous, adversary-style testing:</strong> Move from &#8220;scan and prioritize by CVSS&#8221; to continuous security testing that validates exploitability and observes real attack paths across apps, identity, cloud config, and data access. Put automated pen testing and attack simulation on a cadence aligned to deploy frequency, and ensure findings produce developer-ready fixes, not just tickets. The goal is to detect and eliminate the 80% of vulnerabilities that can be automated before they become mass-exploitable, while reserving expert time for the higher-value 20% that still need human creativity.</p></li><li><p><strong>Harden runtime with distributed enforcement and higher-fidelity detection:</strong> Assume prevention will fail sometimes and build runtime controls that reduce blast radius: stronger identity controls (least privilege, continuous authorization), rapid anomaly detection, and containment that can execute quickly. Where feasible, distribute enforcement closer to users/endpoints (e.g., browser/endpoint policy, step-up confirmation prompts for sensitive actions) so the system can slow attacker automation without crushing productivity. Pair this with detection logic that correlates across identity, endpoint, cloud, and application telemetry to reduce false positives and surface the few signals that matter under time compression.</p></li><li><p><strong>Adopt &#8220;safe auto-remediation&#8221; as a board-level risk decision, not a tooling experiment:</strong> The discussion pointed to a reality: the traditional fear of regression can&#8217;t be the gating constraint when the threat can weaponize faster than humans can respond. Make auto-patching/auto-rollback an explicit program with engineering-owned testing harnesses, canarying, and rapid recovery playbooks, so the organization can remediate at machine speed while limiting outage risk. Success looks like high-confidence automatic fixes for well-scoped classes of issues (e.g., known-bad configs, vulnerable dependencies, exposed services) and tightly controlled human-in-the-loop for edge cases.</p></li><li><p><strong>Treat supply chain and open-source exposure as a standing incident, with immediate blast-radius mapping:</strong> When high-leverage capabilities like Mythos appear, the first question becomes: &#8220;What do we and our critical vendors run that could be hit next week?&#8221; Build and continuously maintain an inventory that ties critical business services to software components, cloud services, and third-party dependencies, so you can answer exposure questions in hours, not days. Operationalize this into a repeatable &#8220;emerging threat drill&#8221; that triggers rapid assessment, prioritized mitigation, and vendor verification; the objective is to cut the window where you&#8217;re vulnerable but unaware, especially across open-source and inherited risk paths.</p></li></ol><p></p><div><hr></div><p></p><h1>Tactical Response Recommendations</h1><p>The SACR team shared detailed recommendations below for rapid response recommendations for CISOs </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!krJG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09042db9-884a-4a93-a1d1-d93fa8c22a4e_1600x900.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!krJG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09042db9-884a-4a93-a1d1-d93fa8c22a4e_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!krJG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09042db9-884a-4a93-a1d1-d93fa8c22a4e_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!krJG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09042db9-884a-4a93-a1d1-d93fa8c22a4e_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!krJG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09042db9-884a-4a93-a1d1-d93fa8c22a4e_1600x900.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!krJG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09042db9-884a-4a93-a1d1-d93fa8c22a4e_1600x900.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/09042db9-884a-4a93-a1d1-d93fa8c22a4e_1600x900.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!krJG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09042db9-884a-4a93-a1d1-d93fa8c22a4e_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!krJG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09042db9-884a-4a93-a1d1-d93fa8c22a4e_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!krJG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09042db9-884a-4a93-a1d1-d93fa8c22a4e_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!krJG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09042db9-884a-4a93-a1d1-d93fa8c22a4e_1600x900.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Security Strategy</h2><ul><li><p><strong>Modernize Defence:</strong> Implement AI agents across the workforce to automate vulnerability discovery and remediation.</p></li><li><p><strong>Strengthen Basics:</strong> Focus on hardening fundamentals like segmentation, egress filtering, and multifactor authentication (MFA).</p></li><li><p><strong>Operational Shifts:</strong> * Prioritize robust dependency management for third-party and open-source components.</p><ul><li><p>Re-evaluate risk tolerance regarding operational downtime for emergency patching.</p></li></ul></li><li><p><strong>Resource Allocation:</strong> Request additional budget and headcount to provide reserve capacity and prevent staff burnout.</p></li></ul><h4><strong>0&#8211;30 days: Assume exploit synthesis will become cheap</strong></h4><ul><li><p><strong>Prioritize attack surface reduction</strong>: exposed management planes, legacy protocols, internet-facing auth flows, forgotten services.</p></li><li><p><strong>Tighten compensating controls where patching lags</strong>: WAF/WAAP virtual patching, egress control, service-to-service auth hardening, segmentation.</p></li><li><p><strong>Exploit-chain monitoring</strong>: instrument the steps attackers must still do (access, credential abuse, lateral movement, data staging).</p></li></ul><h4><strong>31&#8211;60 days: Make patching safe, resilient, recoverable and fast</strong></h4><ul><li><p>Build a <strong>prevention engineering focus</strong> to surgically counter AI-generated exploits: Secure defaults, dependency governance,</p></li><li><p><strong>Mandate memory-safe roadmaps</strong> where applicable to defeat complex ROP chains and buffer overflows that Mythos excels at generating.</p></li><li><p><strong>Prioritize secure language adoption</strong> as the most durable control against exploits in autonomous code generation. SAST/DAST modernization, fuzzing at scale.</p></li><li><p>Stand up a <strong>crisis patch governance program</strong>: Ask your Security Team and IT: Can you safely ship emergency fixes in hours without breaking prod?</p></li></ul><h4><strong>61&#8211;90 days: Prepare for semi-autonomous remediation</strong></h4><ul><li><p>Start designing a trusted remediation pipeline with resilience and rapid patching as a key goal:</p><ul><li><p>Design and deploy a repository for production controls, signed artifacts, policy gates, canarying, rapid backups, and instant rollback for resilience.</p></li><li><p>Formalize verification where feasible for critical components, for example, SBOM validation</p></li><li><p>Prioritize Live Patching for operating systems and tools that support this capability.</p></li></ul></li><li><p>Agentic remediation vendors become a key priority</p><ul><li><p>Ask vendors: Can your agentic remediation produce patches you can trust and operationalize, not just findings?</p></li></ul></li></ul><p>This accelerates demand for:</p><ul><li><p><strong>Trusted agent runtimes/containment</strong> (agents that can&#8217;t freely exfiltrate or laterally move).</p></li><li><p><strong>Prevention engineering</strong> as a discipline (security as a built artifact, not a SOC event).</p></li><li><p><strong>Autonomous mitigation</strong> that goes beyond ticketing: configuration fixes, identity/session revocation, safe hotfix workflows.</p></li></ul><div><hr></div><p></p><h2>Vendor Ecosystem Case Study </h2><p>The market map above highlights the emergence of a new security layer for the Mythos era: <strong>continuous exploitability management</strong>. Mythos does not create an entirely new cybersecurity problem; it accelerates existing ones. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2kby!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F21a60d9d-ce90-4d0d-9c33-a03e1aceb4de_2208x1456.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2kby!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F21a60d9d-ce90-4d0d-9c33-a03e1aceb4de_2208x1456.png 424w, https://substackcdn.com/image/fetch/$s_!2kby!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F21a60d9d-ce90-4d0d-9c33-a03e1aceb4de_2208x1456.png 848w, https://substackcdn.com/image/fetch/$s_!2kby!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F21a60d9d-ce90-4d0d-9c33-a03e1aceb4de_2208x1456.png 1272w, https://substackcdn.com/image/fetch/$s_!2kby!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F21a60d9d-ce90-4d0d-9c33-a03e1aceb4de_2208x1456.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2kby!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F21a60d9d-ce90-4d0d-9c33-a03e1aceb4de_2208x1456.png" width="1456" height="960" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/21a60d9d-ce90-4d0d-9c33-a03e1aceb4de_2208x1456.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:960,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3180283,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://softwareanalyst.substack.com/i/195066990?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F21a60d9d-ce90-4d0d-9c33-a03e1aceb4de_2208x1456.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!2kby!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F21a60d9d-ce90-4d0d-9c33-a03e1aceb4de_2208x1456.png 424w, https://substackcdn.com/image/fetch/$s_!2kby!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F21a60d9d-ce90-4d0d-9c33-a03e1aceb4de_2208x1456.png 848w, https://substackcdn.com/image/fetch/$s_!2kby!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F21a60d9d-ce90-4d0d-9c33-a03e1aceb4de_2208x1456.png 1272w, https://substackcdn.com/image/fetch/$s_!2kby!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F21a60d9d-ce90-4d0d-9c33-a03e1aceb4de_2208x1456.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Mythos changes vulnerability management from a periodic prioritization problem into a real-time exposure and mitigation problem. As AI compresses the time from vulnerability discovery to exploitability, security teams can no longer rely on CVSS scoring, manual triage, or normal patch cycles alone; the key question becomes which vulnerabilities are actually exploitable in the organization&#8217;s environment, which assets are exposed, and what compensating controls can reduce risk before patches are safely deployed.  </p><p>The CSA/SANS/OWASP briefing frames this as a structural asymmetry: attackers gain speed faster than most defenders can patch, respond, or update risk models. This is why CISOs should view the vendors in this map as complementary parts of a Mythos-ready operating model. </p><ol><li><p><strong>Specialized offensive security</strong> vendors help organizations understand how real attackers would test their environments through penetration testing, bug bounty, red teaming, and breach-and-attack simulation. </p></li><li><p><strong>AI vulnerability and exploitability</strong> vendors extend that logic by using automation and AI to continuously identify which weaknesses are actually exploitable, not merely theoretically severe. </p></li><li><p><strong>RBVM</strong> platforms then help translate those findings into prioritization, ownership, and remediation workflows.</p></li></ol><p>The key shift is from asking, &#8220;What vulnerabilities do we have?&#8221; to asking, &#8220;Which weaknesses can be exploited, chained, and used to cause business impact?&#8221; Traditional vulnerability management produces too many findings and often relies on severity scores that do not reflect real-world attackability. </p><p>In a Mythos environment, that is insufficient. CISOs need evidence-based exploitability intelligence that combines technical severity, asset criticality, exposure, compensating controls, identity context, and realistic attack paths. The best tools will help prove exploitability, map attack paths, prioritize what matters, recommend compensating controls when patching is delayed, and integrate directly into engineering, IT, and security workflows. For example, companies like Zafran help organizations map vulnerabilities against real asset exposure, existing security controls, and business context so teams can prioritize the small subset of issues that create immediate operational risk. </p><p>This aligns with the broader Mythos-ready security model, which emphasizes attack surface reduction, continuous patching, compensating controls such as segmentation and egress filtering, and automated response capabilities rather than relying on detection alone. Companies that are good at identifying what is exploitable now, determining what is already protected, and accelerating the path to mitigation while the organization works through patch validation and deployment</p><p>For CISOs, the Mythos-ready market is not a replacement for existing security programs. It is a force multiplier across application security, exposure management, cloud security, identity, patching, and resilience. The organizations that benefit most will use these vendors to build a continuous loop: </p><ol><li><p>Discover exposure, </p></li><li><p>Validate exploitability,</p></li><li><p>Prioritize by business risk, </p></li><li><p>Remediate quickly, and </p></li><li><p>Verify that risk has actually been reduced. </p></li></ol><p>That is the path from reactive vulnerability management to proactive exploitability reduction.</p><p></p><div><hr></div><h2>Conclusion: Mythos Defines the Next Security Operating Model</h2><p>Mythos is not just another AI model or another cybersecurity headline. It is a preview of a new operating environment in which vulnerability discovery, exploit development, and attack execution increasingly operate at machine speed. The core implication is clear: security programs built around periodic scanning, manual triage, ticket-based remediation, and slow patch cycles were not designed for this reality.</p><p>The biggest shift is not simply that attackers get faster. It is that the entire defender operating model must change. In a Mythos world, detection alone is insufficient. Faster investigation does not matter if the organization cannot safely validate, patch, contain, and recover at comparable speed. The durable advantage moves to organizations that can reduce exploitable surface area, ship safe fixes quickly, constrain blast radius, and restore trust when prevention fails.</p><p>For CISOs and boards, the mandate is immediate. Update your risk models. Harden the basics. Accelerate attack surface reduction. Invest in AI-enabled defensive workflows. Build patch governance that can operate in hours, not weeks. Prepare security and engineering teams for a higher volume of vulnerabilities without burning them out. And treat resilience as a core security outcome. </p><p>Mythos does not mean the sky is falling. But it does mean <strong>human-based cybersecurity is becoming obsolete.</strong> The winners in the next era will be the organizations that can continuously find, validate, fix, contain, and recover at machine speed while preserving the governance and judgment enterprise security requires.</p><p></p><div><hr></div><h4><strong>Sources:</strong></h4><ul><li><p><em><a href="https://labs.cloudsecurityalliance.org/mythos-ciso/">Credits to the CSA &#8220;AI Vulnerability Storm&#8221;: Building a &#8220;Mythos-ready&#8221; Security Program</a>. <a href="https://cloudsecurityalliance.org/artifacts/the-ai-vulnerability-storm">(0) </a></em></p></li><li><p><em>Anthropic: Project Glasswing overview.<a href="https://www.anthropic.com/glasswing">[1]</a></em></p></li><li><p><em>Anthropic technical deep dive (red team/security testing write-up).<a href="https://red.anthropic.com/2026/mythos-preview/">[2]</a></em></p></li><li><p><em>Reuters on banking/legacy risk and policy attention.<a href="https://www.reuters.com/legal/litigation/ai-boosted-hacks-with-anthropics-mythos-could-have-dire-consequences-banks-2026-04-13/">[3]</a></em></p></li><li><p><em>WIRED take: &#8220;security reckoning&#8221; framing.<a href="https://www.wired.com/story/anthropics-mythos-will-force-a-cybersecurity-reckoning-just-not-the-one-you-think/">[4]</a></em></p></li><li><p><em>Fortune on leak &#8594; acknowledgment and &#8220;step change&#8221; characterization.<a href="https://fortune.com/2026/03/26/anthropic-says-testing-mythos-powerful-new-ai-model-after-data-leak-reveals-its-existence-step-change-in-capabilities/">[5]</a></em></p></li></ul><p></p><div><hr></div><p></p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Software Analyst Cyber Research! Subscribe for free to receive new cybersecurity research reports and analysis.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/p/the-cybersecurity-implications-of?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/p/the-cybersecurity-implications-of?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/p/the-cybersecurity-implications-of/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/p/the-cybersecurity-implications-of/comments"><span>Leave a comment</span></a></p><div class="directMessage button" data-attrs="{&quot;userId&quot;:6770950,&quot;userName&quot;:&quot;SACR&quot;,&quot;canDm&quot;:null,&quot;dmUpgradeOptions&quot;:null,&quot;isEditorNode&quot;:true}" data-component-name="DirectMessageToDOM"></div><p></p>]]></content:encoded></item><item><title><![CDATA[Introducing Social Engineering Identity Defense (SEID): A New Category for Securing Identity Workflows Beyond Authentication ]]></title><description><![CDATA[A New Workforce Identity Security Category for Protecting the Workflows Attackers Exploit As Authentication Gets Stronger]]></description><link>https://softwareanalyst.substack.com/p/introducing-social-engineering-identity</link><guid isPermaLink="false">https://softwareanalyst.substack.com/p/introducing-social-engineering-identity</guid><dc:creator><![CDATA[Sean Sosnowski]]></dc:creator><pubDate>Tue, 05 May 2026 17:01:10 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!FYyo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58debc75-3442-4345-bcd7-1a6b3d83c8b4_1968x1046.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>New Identity Security Category </h2><p>In this report, we are introducing a new category we call <strong>Social Engineering Identity Defense (SEID)</strong>. The premise is simple: as enterprises harden authentication with MFA, passkeys, and stronger identity controls, attackers are shifting toward the workflows that sit around identity: help desk resets, account recovery, onboarding, internal approvals, and collaboration channels. </p><p>SEID is our framework for understanding and securing this emerging attack surface, where trust is not broken at the login screen, but manipulated through the business processes that grant, restore, or change access. We hope you find this research note detailed! </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!FYyo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58debc75-3442-4345-bcd7-1a6b3d83c8b4_1968x1046.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!FYyo!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58debc75-3442-4345-bcd7-1a6b3d83c8b4_1968x1046.png 424w, https://substackcdn.com/image/fetch/$s_!FYyo!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58debc75-3442-4345-bcd7-1a6b3d83c8b4_1968x1046.png 848w, https://substackcdn.com/image/fetch/$s_!FYyo!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58debc75-3442-4345-bcd7-1a6b3d83c8b4_1968x1046.png 1272w, https://substackcdn.com/image/fetch/$s_!FYyo!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58debc75-3442-4345-bcd7-1a6b3d83c8b4_1968x1046.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!FYyo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58debc75-3442-4345-bcd7-1a6b3d83c8b4_1968x1046.png" width="1456" height="774" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/58debc75-3442-4345-bcd7-1a6b3d83c8b4_1968x1046.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:774,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:715161,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://softwareanalyst.substack.com/i/195893707?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58debc75-3442-4345-bcd7-1a6b3d83c8b4_1968x1046.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!FYyo!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58debc75-3442-4345-bcd7-1a6b3d83c8b4_1968x1046.png 424w, https://substackcdn.com/image/fetch/$s_!FYyo!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58debc75-3442-4345-bcd7-1a6b3d83c8b4_1968x1046.png 848w, https://substackcdn.com/image/fetch/$s_!FYyo!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58debc75-3442-4345-bcd7-1a6b3d83c8b4_1968x1046.png 1272w, https://substackcdn.com/image/fetch/$s_!FYyo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58debc75-3442-4345-bcd7-1a6b3d83c8b4_1968x1046.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Software Analyst Cyber Research! Subscribe for free to receive new research reports on cybersecurity.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><div><hr></div><h1>Author</h1><p><a href="https://www.linkedin.com/in/seansosnowski/">Sean Sosnowski</a> serves as the Research Director for Security Operations and Cloud Security at SACR, where he leads research on SOC strategy and operations, detection engineering, and the evolving role of automation and agentic AI in security workflows. Drawing on a decade of intelligence experience in the U.S. Marine Corps he has authored several analytic reports on emerging technologies and threats regarding sensitive national security and military operations.</p><div><hr></div><p></p><h1>Executive Summary</h1><p><strong>The next major identity breach may not start with a stolen password. </strong>It will likely take one of the following forms:</p><ul><li><p>It will start with a phone call to the help desk.</p></li><li><p>A fake candidate in the hiring process.</p></li><li><p>A Slack message that looks like it came from an executive.</p></li><li><p>A request to reset MFA.</p></li><li><p>A support ticket that feels urgent enough to bypass normal procedure.</p></li></ul><p>That is the uncomfortable reality facing enterprise security teams. The identity stack has become stronger at the login layer, but attackers have found a softer target: the workflows that can change identity without breaking authentication directly.</p><p>The center of gravity in identity security has shifted from the login prompt to the workflows around it. As enterprises deploy stronger, phishing-resistant authentication, attackers are moving toward the human systems they can still exploit. Account recovery, help desk operations, hiring and onboarding, and internal communications are increasingly targeted by attackers. These workflows were built for speed, continuity, and trust. They were not built to function as high-assurance security controls under adversarial pressure. That gap is now one of the most important blind spots in workforce identity security.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rKeL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f16713c-dcc8-48e5-a872-4fc8cb3ea9b9_2100x1176.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rKeL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f16713c-dcc8-48e5-a872-4fc8cb3ea9b9_2100x1176.png 424w, https://substackcdn.com/image/fetch/$s_!rKeL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f16713c-dcc8-48e5-a872-4fc8cb3ea9b9_2100x1176.png 848w, https://substackcdn.com/image/fetch/$s_!rKeL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f16713c-dcc8-48e5-a872-4fc8cb3ea9b9_2100x1176.png 1272w, https://substackcdn.com/image/fetch/$s_!rKeL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f16713c-dcc8-48e5-a872-4fc8cb3ea9b9_2100x1176.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rKeL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f16713c-dcc8-48e5-a872-4fc8cb3ea9b9_2100x1176.png" width="1456" height="815" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4f16713c-dcc8-48e5-a872-4fc8cb3ea9b9_2100x1176.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:815,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:955707,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://softwareanalyst.substack.com/i/195893707?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f16713c-dcc8-48e5-a872-4fc8cb3ea9b9_2100x1176.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!rKeL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f16713c-dcc8-48e5-a872-4fc8cb3ea9b9_2100x1176.png 424w, https://substackcdn.com/image/fetch/$s_!rKeL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f16713c-dcc8-48e5-a872-4fc8cb3ea9b9_2100x1176.png 848w, https://substackcdn.com/image/fetch/$s_!rKeL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f16713c-dcc8-48e5-a872-4fc8cb3ea9b9_2100x1176.png 1272w, https://substackcdn.com/image/fetch/$s_!rKeL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f16713c-dcc8-48e5-a872-4fc8cb3ea9b9_2100x1176.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Generative AI makes this problem more dangerous, but it does not create it. The underlying weakness is structural. Deepfake voice, synthetic video, AI-assisted scripting, and contextual impersonation give attackers better tools to exploit the same issue, where many sensitive identity actions are still treated as routine support tasks rather than security-critical transactions. In practice, attackers do not need to beat passkeys or MFA head-on. They need to persuade a help desk agent to reset an account, convince a recruiter to advance a synthetic candidate, manipulate an employee through a trusted collaboration channel, or exploit a recovery path that lacks the rigor of primary authentication.</p><p>This report argues that workforce identity security must be reframed accordingly. The right model is not simply stronger authentication or more awareness training. It is a workflow-centric approach that extends identity assurance into the moments where access is granted, changed, delegated, or restored. We describe this model <strong>as Social Engineering Identity Defense (SEID),</strong> where a control framework built around verification in workflow, governed human touchpoints, cross-channel identity trust, and auditable decisioning. The goal is to reduce attacker leverage where human judgment and business processes still determine access outcomes.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!K_TY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e3beea6-d8da-4f6a-b814-f126b6027b76_2048x1448.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!K_TY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e3beea6-d8da-4f6a-b814-f126b6027b76_2048x1448.png 424w, https://substackcdn.com/image/fetch/$s_!K_TY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e3beea6-d8da-4f6a-b814-f126b6027b76_2048x1448.png 848w, https://substackcdn.com/image/fetch/$s_!K_TY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e3beea6-d8da-4f6a-b814-f126b6027b76_2048x1448.png 1272w, https://substackcdn.com/image/fetch/$s_!K_TY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e3beea6-d8da-4f6a-b814-f126b6027b76_2048x1448.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!K_TY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e3beea6-d8da-4f6a-b814-f126b6027b76_2048x1448.png" width="1456" height="1029" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4e3beea6-d8da-4f6a-b814-f126b6027b76_2048x1448.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1029,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!K_TY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e3beea6-d8da-4f6a-b814-f126b6027b76_2048x1448.png 424w, https://substackcdn.com/image/fetch/$s_!K_TY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e3beea6-d8da-4f6a-b814-f126b6027b76_2048x1448.png 848w, https://substackcdn.com/image/fetch/$s_!K_TY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e3beea6-d8da-4f6a-b814-f126b6027b76_2048x1448.png 1272w, https://substackcdn.com/image/fetch/$s_!K_TY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e3beea6-d8da-4f6a-b814-f126b6027b76_2048x1448.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The implication for security leaders is straightforward. Identity programs centered only on sign-in protection will increasingly miss the transactions that matter most. The next phase of identity defense will be won by organizations that treat recovery, support, onboarding, and internal approvals as part of the identity plane itself; reduce discretionary decisions in high-risk flows; and build systems that can verify, govern, and explain sensitive identity actions in real time. This is not a marginal extension of IAM. It is the beginning of a broader workforce identity security market built for the era of social engineering, deepfakes, and human-layer compromise.</p><p></p><p></p><div><hr></div><h1>Problem</h1><p>This emerging market exists because the enterprise identity stack is still securing the wrong boundary. Most identity programs focus on sign-in, yet many of the highest-consequence identity decisions happen after the user leaves the login screen. The shift is not simply that social engineering has improved. Stronger authentication is pushing attackers into the workflow layer, where human judgment, fragmented context, and business urgency still determine outcomes. Passkeys and phishing-resistant MFA raise the cost of direct credential theft, but they do not eliminate recovery bypass, help desk manipulation, session abuse, or trusted-channel impersonation. In practice, attackers do not need to break the front door if they can persuade an operator to issue a reset, approve a device, advance a synthetic hire, or trust an internal message that triggers a legitimate-looking exception.</p><p>AI-assisted impersonation increases pressure on the people and systems already responsible for resolving edge cases quickly. The result is a workforce identity blind spot, where enterprises have hardened authentication, but the workflows that change identity remain easier to manipulate. The core problem is not a lack of awareness training or the arrival of one more phishing variant. It is that workforce identity security must extend beyond authentication into the human workflows, moving up the stack to applications where greater or increased trust is granted, exceptions are made, and access is ultimately decided.</p><h1>Social Engineering as Workflow Abuse</h1><p>For this report, social engineering in cybersecurity means the use of deception to cause a legitimate person to perform a security-relevant action on an attacker&#8217;s behalf. In enterprise identity environments, its most important form is workflow manipulation where the attacker targets decision points where access is reset, restored, approved, delegated, or trusted across channels.</p><p>This framing shifts the analysis from user awareness to operating control. The central question is how deceptive requests move through a business process, what evidence is evaluated, who has authority to approve the action, and whether the resulting decision can be explained after the fact.</p><p>What changed is not that attackers suddenly discovered new human weakness. It is that stronger authentication methods such as passkeys and phishing-resistant MFA have made direct compromise harder, pushing adversaries upwards in the stack toward the workflows beyond authentication instead of through it. Account recovery, help desk operations, hiring and onboarding, and internal communications have become prime attack surfaces because they can still authorize high-impact identity changes under conditions of urgency, ambiguity, and incomplete context.</p><p>The threat is compounded by Generative AI, which provides attackers with better tools like deepfake voice, synthetic video, AI-assisted scripting, and contextual impersonation. Attackers no longer need to beat MFA head-on, they seek to persuade a help desk agent to reset an account, convince a recruiter to advance a synthetic candidate, or manipulate an employee through a trusted channel.</p><p>Social engineering should therefore be treated as an operational security problem, not merely a training problem. Its enterprise form is now increasingly workflow-centric and identity-adjacent, focused on the abuse of authorized processes through impersonation, contextual pressure, and cross-channel coordination. The attacker&#8217;s goal is to convert trust into a legitimate action that grants access, changes identity state, or moves money and data.</p><h2>Real Life Examples of Social Engineering</h2><p>A strong real-world example of the SEID problem is Okta Threat Intelligence&#8217;s reporting on O-UNC-034. According to Okta, the group used social engineering of help desk staff to take over employee accounts and then manipulate data in payroll systems. The sequence is important because it shows that the attacker did not need to defeat phishing-resistant authentication directly. Instead, the attacker targeted the workflow that could reset access on the user&#8217;s behalf.</p><p>Okta reported that the actor impersonated legitimate employees and contacted the target company&#8217;s IT help desk to request password resets. After a successful reset, the actor established persistence by enrolling an attacker-controlled MFA method or manipulating recovery factors, including Okta Verify, voice call authentication, SMS, or security questions. From there, the actor pivoted into internal applications, including payroll platforms such as Workday, Dayforce HCM, and ADP, as well as CRM and IT service management systems such as Salesforce and ServiceNow. Okta also noted access to collaboration environments such as Office 365 and Google Workspace, which could support additional internal reconnaissance and follow-on abuse.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!CpN3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa012e4a9-2f40-48d3-be5b-1e966d3f9e81_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!CpN3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa012e4a9-2f40-48d3-be5b-1e966d3f9e81_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!CpN3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa012e4a9-2f40-48d3-be5b-1e966d3f9e81_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!CpN3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa012e4a9-2f40-48d3-be5b-1e966d3f9e81_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!CpN3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa012e4a9-2f40-48d3-be5b-1e966d3f9e81_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!CpN3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa012e4a9-2f40-48d3-be5b-1e966d3f9e81_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a012e4a9-2f40-48d3-be5b-1e966d3f9e81_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!CpN3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa012e4a9-2f40-48d3-be5b-1e966d3f9e81_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!CpN3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa012e4a9-2f40-48d3-be5b-1e966d3f9e81_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!CpN3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa012e4a9-2f40-48d3-be5b-1e966d3f9e81_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!CpN3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa012e4a9-2f40-48d3-be5b-1e966d3f9e81_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This is exactly the kind of identity attack path SEID is designed to address. The decisive failure did not occur at the login prompt. It occurred when a help desk workflow treated a sensitive identity change as a routine support action rather than a high-risk identity transaction. In SEID terms, O-UNC-034 illustrates a breakdown in Verification-in-Workflow, because a password reset and MFA change were approved without sufficiently strong identity proofing at the moment of change. It also illustrates the importance of Governed Human Interaction, because a front-line operator was placed in a position to make a high-impact identity decision under uncertainty and urgency.</p><p>The case also supports the need for Cross-Channel Identity Trust. Although the immediate action took place through the help desk, the actor&#8217;s objective extended beyond account recovery into payroll manipulation and broader access to enterprise systems. That is the core SEID insight where attackers increasingly exploit the workflows around identity rather than attacking authentication head-on. Once a support process can be manipulated into issuing a reset or accepting a new authenticator, the attacker can obtain legitimate-looking access through an apparently legitimate business process.</p><h1>Social Engineering Identity Defense</h1><p>SEID organizes this problem around the workflows where identity trust is created or changed. The framework has four linked requirements whereby we enhance verification of the requester inside the workflow, govern and inform workflow participants (through visible human indicators and scoring) inside the human touchpoints that can approve sensitive actions, carry trust signals across communication and identity channels, and preserve enough evidence to explain each decision after the fact. Together, these controls make identity-changing workflows more resistant to manipulation, because it informs human (or autonomous agents) of increased risk.</p><p>Each pillar owns a distinct decision problem. Verification-in-Workflow establishes whether the requester should be trusted at the moment of change. Governed Human Interaction defines how operators act when the request is sensitive or potentially ambiguous. Cross-Channel Identity Trust ensures that risk signals from one channel can inform decisions in another. Measurable Outcomes and Auditability preserve the evidence needed to reconstruct and improve the process.</p><p>Together, these pillars shift identity defense from authentication at the front door to trust enforcement across the workflows that actually govern workforce access.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!K_TY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e3beea6-d8da-4f6a-b814-f126b6027b76_2048x1448.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!K_TY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e3beea6-d8da-4f6a-b814-f126b6027b76_2048x1448.png 424w, https://substackcdn.com/image/fetch/$s_!K_TY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e3beea6-d8da-4f6a-b814-f126b6027b76_2048x1448.png 848w, https://substackcdn.com/image/fetch/$s_!K_TY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e3beea6-d8da-4f6a-b814-f126b6027b76_2048x1448.png 1272w, https://substackcdn.com/image/fetch/$s_!K_TY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e3beea6-d8da-4f6a-b814-f126b6027b76_2048x1448.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!K_TY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e3beea6-d8da-4f6a-b814-f126b6027b76_2048x1448.png" width="1456" height="1029" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4e3beea6-d8da-4f6a-b814-f126b6027b76_2048x1448.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1029,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!K_TY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e3beea6-d8da-4f6a-b814-f126b6027b76_2048x1448.png 424w, https://substackcdn.com/image/fetch/$s_!K_TY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e3beea6-d8da-4f6a-b814-f126b6027b76_2048x1448.png 848w, https://substackcdn.com/image/fetch/$s_!K_TY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e3beea6-d8da-4f6a-b814-f126b6027b76_2048x1448.png 1272w, https://substackcdn.com/image/fetch/$s_!K_TY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e3beea6-d8da-4f6a-b814-f126b6027b76_2048x1448.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>SEID&#8217;s core scope is identity-sensitive workflow control. It applies to account recovery, MFA reset, device enrollment, onboarding credential issuance, privileged support actions, and high-risk internal approvals. Adjacent areas such as email security, ITDR, identity governance, and security awareness matter when they feed evidence into these workflows or help govern the decision itself. This boundary keeps SEID focused on the moments where trust changes state.</p><h2>Verification-in-Workflow</h2><p>Verification-in-Workflow brings identity assurance to the point where a sensitive action is requested. Password resets, account unlocks, MFA changes, and onboarding credential issuance should be treated as identity transactions because they can alter trust as materially as a successful login. The control objective is to ensure that the requester is verified before the workflow executes the change.</p><p>Architecturally, the request should pass through a policy-controlled verification step before execution. That step can evaluate device, location, ticket, employment, and recent activity context, then apply adaptive proofing and inform workflow participants based on risk. Low-risk requests can move quickly, while higher-risk requests can require stronger evidence, additional approval, or in-person validation. The value of the model comes from placing verification directly inside the workflow, where the sensitive identity decision is made.</p><h2>Governed Human Interaction</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Mtzy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1671500d-3d69-41f3-bafd-7f59c00a0178_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Mtzy!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1671500d-3d69-41f3-bafd-7f59c00a0178_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!Mtzy!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1671500d-3d69-41f3-bafd-7f59c00a0178_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!Mtzy!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1671500d-3d69-41f3-bafd-7f59c00a0178_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!Mtzy!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1671500d-3d69-41f3-bafd-7f59c00a0178_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Mtzy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1671500d-3d69-41f3-bafd-7f59c00a0178_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1671500d-3d69-41f3-bafd-7f59c00a0178_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Mtzy!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1671500d-3d69-41f3-bafd-7f59c00a0178_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!Mtzy!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1671500d-3d69-41f3-bafd-7f59c00a0178_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!Mtzy!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1671500d-3d69-41f3-bafd-7f59c00a0178_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!Mtzy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1671500d-3d69-41f3-bafd-7f59c00a0178_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Many of the most exploitable identity decisions are made by human operators. Help desk agents, HR, and other user-facing staff are frequently required to resolve issues that are deemed urgent, making them high value targets for social engineering attacks. The core of this pillar is about reducing the number of critical decisions reliant on improvisation a human operator has to make. The current state of human interaction allows for a single operator to reset a password based on information that is easily collected through basic open source intelligence collection. Conceptually in SEID, operators initiate the Verification-in-Workflow process to validate the identity of the user without relying on easily collectable information. The process either automatically approves the request, or moves on to a tightly controlled exception workflow, requiring manager approval, or physical presence of the user to reset credentials.</p><p>Governed Human Interaction also presents some cultural shortfalls, legitimate users and support teams alike expect easy and consistent workflows that deliver results. Controls that increase the friction between a legitimate user and a help desk will often be disregarded and not used to their full potential. Governed Human Interaction therefore has to be structured as a model that improves capabilities of help desk operations, not as a restriction. Properly implemented governance should reduce ambiguity for operators and lower the likelihood of them becoming a weak link in the identity verification process. The target outcome is a support system that resolves ordinary issues efficiently while hardening the process to exploitation.</p><h2>Cross Channel Identity Trust</h2><p>Cross-Channel Identity Trust exists because effective social engineers don&#8217;t stay inside one workflow or tool. Attacks may start in email, then move to voice, and other platforms as they gain trust within an organization. They can then execute their goals, taking advantage of the cross-channel trust they established by using multiple platforms as vectors. A security model that evaluates email, collaboration tools, and identity systems in isolation will miss the contextual indicators of effective social engineering.</p><p>Through Cross-Channel Identity Trust, SEID extends from transactional security to contiguous protections across an organization. Architecturally, Cross-Channel Identity Trust is a shared layer across email, collaboration tools, and identity infrastructure. This communication stack shares a signal to help identify anomalous activity across an organization, such as thread hijacking, excessive authority/urgency language, and abnormal requests that do not fit prior norms of interaction. Adding identity telemetry gives access to signals about impossible travel, new devices, abnormal inbox rules, session anomalies, token misuse, or suspicious post-authentication behavior.</p><p>The goal is to preserve a sequence of contextual information that can inform an identity centric decision. A password reset request arriving at a help desk after anomalous activity from the same identity can now be treated differently than the same request from a trusted user. Cross Channel Identity Trust builds the temporal and behavioral context on identities within an organization to inform the Verification-in-Workflow process.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2-hY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83548c34-c565-44c0-b1b8-ce06ae564801_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2-hY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83548c34-c565-44c0-b1b8-ce06ae564801_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!2-hY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83548c34-c565-44c0-b1b8-ce06ae564801_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!2-hY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83548c34-c565-44c0-b1b8-ce06ae564801_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!2-hY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83548c34-c565-44c0-b1b8-ce06ae564801_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2-hY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83548c34-c565-44c0-b1b8-ce06ae564801_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/83548c34-c565-44c0-b1b8-ce06ae564801_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!2-hY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83548c34-c565-44c0-b1b8-ce06ae564801_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!2-hY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83548c34-c565-44c0-b1b8-ce06ae564801_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!2-hY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83548c34-c565-44c0-b1b8-ce06ae564801_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!2-hY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83548c34-c565-44c0-b1b8-ce06ae564801_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Measurable Outcomes &amp; Auditability</h2><p>The final pillar, Measurable Outcomes &amp; Auditability, turns sensitive identity actions into security events rather than vague support transactions. In many identity incidents, failure lies in post-incident ambiguity, no clear record of who initiated the request, what evidence was collected and considered, which policy was followed, and where human operators overrode system rules. SEID treats auditable metrics as a control surface, every action taken by human operators or autonomous systems is cataloged along with all of the contextual evidence used to justify the action.</p><p>Security teams should be able to reconstruct a complete workflow from request to decision with evidence as to why the decision was made. In practice, capturing data such as: requester, associated identities, communication method, risk score, verification methods, approvers involved, and final decisions. Integrating auditability into the workflow itself builds transparency and trust across an organization, enabling process improvement and increasing defensive capabilities against an attack.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!u8sh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a6618c1-f6cb-4ad2-a72e-0e3725c19d1f_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!u8sh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a6618c1-f6cb-4ad2-a72e-0e3725c19d1f_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!u8sh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a6618c1-f6cb-4ad2-a72e-0e3725c19d1f_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!u8sh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a6618c1-f6cb-4ad2-a72e-0e3725c19d1f_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!u8sh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a6618c1-f6cb-4ad2-a72e-0e3725c19d1f_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!u8sh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a6618c1-f6cb-4ad2-a72e-0e3725c19d1f_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7a6618c1-f6cb-4ad2-a72e-0e3725c19d1f_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!u8sh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a6618c1-f6cb-4ad2-a72e-0e3725c19d1f_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!u8sh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a6618c1-f6cb-4ad2-a72e-0e3725c19d1f_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!u8sh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a6618c1-f6cb-4ad2-a72e-0e3725c19d1f_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!u8sh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a6618c1-f6cb-4ad2-a72e-0e3725c19d1f_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1>Framework as a Market Category</h1><p>SEID should be understood as a category frame for controls that protect identity-changing workflows from social engineering. At first, this market will likely form through adjacent products, with a cleaner standalone category emerging as buyers demand controls that span recovery, support, onboarding, and high-risk approvals. Products count as SEID infrastructure when they improve at least one of the framework&#8217;s core requirements: point-of-change verification, governed human decisioning, cross-channel identity context, or durable decision evidence.</p><p>The strategic need is an integrated control pattern, because attackers exploit the handoffs between tools as much as they exploit any one tool. Buyers should evaluate SEID solutions by workflow coverage, evidence quality, policy control, operator usability, and audit completeness. The key question is whether the product reduces attacker leverage at the moment an identity-sensitive action is approved. SEID ownership will likely be cross-functional. IAM teams own several identity controls, SOC teams see account takeover and behavioral signals, IT service teams operate recovery workflows, and HR owns onboarding risk. A mature program needs a clear owner for identity-sensitive workflow decisions, even when the evidence and execution sit across multiple systems.</p><p>The business value of SEID comes from reducing the cost and frequency of compromised workflow decisions. Strong implementations should lower fraudulent reset risk, reduce unnecessary escalations, make help desk decisions more consistent, and give security teams cleaner evidence during incident response. These outcomes position the category as an operating model for safer identity service delivery.</p><h1>Vendor Strategy</h1><p>Constructing a complete SEID framework requires a multi-vendor approach, as no single solution can cover the full lifecycle of workforce identity workflows and the diverse attack surfaces. Successful security stacks must combine technologies that address both the verification-in-workflow layer and the cross-channel identity trust layer. For this reason, we examine a combined strategy with Imper AI and Abnormal AI, whose technologies map to how modern social engineering attacks often begin in communication channels and pivot to exploit core identity workflows.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Dkjq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F291ee77f-e0a3-478a-8855-15ee61ad64f0_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Dkjq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F291ee77f-e0a3-478a-8855-15ee61ad64f0_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!Dkjq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F291ee77f-e0a3-478a-8855-15ee61ad64f0_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!Dkjq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F291ee77f-e0a3-478a-8855-15ee61ad64f0_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!Dkjq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F291ee77f-e0a3-478a-8855-15ee61ad64f0_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Dkjq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F291ee77f-e0a3-478a-8855-15ee61ad64f0_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/291ee77f-e0a3-478a-8855-15ee61ad64f0_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Dkjq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F291ee77f-e0a3-478a-8855-15ee61ad64f0_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!Dkjq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F291ee77f-e0a3-478a-8855-15ee61ad64f0_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!Dkjq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F291ee77f-e0a3-478a-8855-15ee61ad64f0_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!Dkjq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F291ee77f-e0a3-478a-8855-15ee61ad64f0_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>imper.ai</h2><h3>Overview</h3><p>imper.ai is relevant to SEID because it is focused on the workflow layer where identity assurance is often weakest. It is aimed at help desk recovery, hiring, onboarding, and other moments when trust is granted through process rather than through a standard authentication event. imper.ai presents itself as a workforce identity security platform operating between enterprise IAM controls and the human workflows that sit outside routine sign-in. That framing aligns closely with the SEID view that stronger MFA shifts attacker pressure toward recovery and exception paths.</p><p>This profile is especially relevant to Verification-in-Workflow because the product is centered on the decision point itself. It is designed for the moment when a password is reset, a candidate is advanced, or credentials are issued. That matters because the security consequence becomes operationally real at that point.</p><h3>Product &amp; Architecture</h3><p>At the product level, imper.ai combines an impersonation detection engine with a contextual verification layer. The detection engine correlates network and location characteristics, endpoint and device attributes, and behavioral patterns into a real-time risk score. The contextual verification layer adds dynamic, work-based questions grounded in enterprise context rather than static knowledge checks, document uploads, or biometric enrollment. In practice, the model is trying to observe conditions an attacker has to manage while impersonating a real worker, then pair those signals with verification logic tied to the specific workflow.</p><p>That architecture maps cleanly to the SEID model because it operates inside high-consequence identity transactions. In the help desk recovery flow, a caller requesting a password reset or MFA change can be routed into a verification process that combines ticket context, device and network telemetry, and contextual questioning before the action is approved. The same logic extends into hiring and onboarding. Recruiters continue to work inside ATS or interview workflows while imper.ai adds risk scoring, contextual prompts, and a record across multiple stages. At onboarding, the platform can compare the credential-issuance session to an earlier hiring baseline where that baseline exists, or establish one at the point of first verification.</p><p>The outsourced help desk point is also analytically important. Third-party agents often have less organizational familiarity and less confidence about what normal behavior looks like for a given employee. A workflow-linked verification layer can reduce reliance on individual judgment by standardizing the decision around policy-backed evidence. That is why the product is relevant to recent attack patterns associated with contractor-mediated or help desk access paths, including public reporting around Caesars, MGM, and M&amp;S.</p><p>The AI layer also appears to have been designed with adversarial misuse in mind. System prompts are separated from user input, a secondary model evaluates responses for prompt-injection patterns, output length is constrained, and suspicious sessions can be marked as failed without providing the requester direct feedback. These signals are used for risk assessment without collecting session content such as typed responses, documents, or communications, which helps address privacy and deployment concerns.</p><p>imper.ai&#8217;s public DPRK research adds a useful example of how the model is intended to work. In an April 13, 2026 post, four candidates were identified out of 600 pre-employment verifications whose device, network, and identity signals aligned with published DPRK IT worker tradecraft. The value of that case study extends beyond the attribution claim. It shows that the platform is attempting to detect risk in the network, device, and workflow layer during a live verification event, which is a layer that resume review, background checks, and one-time identity proofing often do not observe directly.</p><h3>Competition &amp; Positioning</h3><p>imper.ai overlaps with several adjacent categories, including identity proofing, help desk security, hiring fraud controls, step-up authentication, and deepfake or meeting security tools. Its practical distinction is that it appears to join infrastructure signals with enterprise context at the point where a high-impact identity decision is made. That gives it a different role from products that are strongest at sign-in, strongest during document or biometric checks, or strongest inside a single meeting or media interaction.</p><p>That position gives imper.ai a distinctive place in the SEID landscape. Identity providers and MFA vendors reduce straightforward credential abuse, but they are often less informative once a user enters a recovery or exception path. Identity proofing vendors are typically oriented to discrete verification events rather than continuing workflow assurance. Deepfake or meeting security tools can contribute evidence inside a video or audio interaction, but they usually do not govern the downstream workflow where access is restored, credentials are issued, or a candidate is advanced. imper.ai is interesting because it is trying to sit inside those operational systems and carry risk evaluation through the decision itself.</p><p>The strategic limit is also clear. imper.ai depends on surrounding systems such as identity providers, HR platforms, and ITSM tools for authoritative context and final execution. Its role is better understood as a control layer inside those workflows than as a full replacement for the systems around it.</p><h3>Implications for SEID</h3><p>imper.ai is a strong example of Verification-in-Workflow and Governed Human Interaction. The product is built around the premise that sensitive identity actions should be mediated by contextual verification and policy rather than by static knowledge questions or agent discretion alone. It also has a meaningful fit within Measurable Outcomes and Auditability through the investigation views, verification records, and workflow-linked results.</p><p>The practical importance of imper.ai in this report is that it treats social engineering as an identity workflow problem. If the platform executes well, it could become a meaningful control layer for organizations that have already strengthened MFA but still expose high-impact exceptions through recovery desks, recruiting teams, and onboarding functions. The main diligence questions therefore become operational: how much policy orchestration is handled directly in product, how consistent the system remains across varied enterprise roles and uneven data quality, and how broadly the current model extends beyond the flagship workflows.</p><h2>Abnormal AI</h2><h3>Overview</h3><p>Abnormal AI is relevant to SEID because it approaches identity abuse from the surrounding behavior layer rather than from the authentication control alone. The company began in email security, where it built behavioral baselines around employees, vendors, and communication patterns to detect phishing, business email compromise, vendor fraud, and account takeovers. It now presents the platform as a broader behavioral AI system for protecting people and data across cloud and SaaS environments. That matters for SEID because many workforce identity attacks begin as trust manipulation in email or collaboration tools before they surface as a reset request, privileged action, or workflow exception.</p><p>This profile is especially relevant to the Cross-Channel Identity Trust pillar. Abnormal is centered on whether the surrounding sequence of communications, account activity, and relationship signals still looks consistent with the real person behind the identity. In that sense, it occupies an important adjacent layer in the SEID model: the system that can make a later identity decision more informed and more defensible.</p><h3>Product &amp; Architecture</h3><p>At the platform layer, Abnormal&#8217;s differentiator is behavioral modeling across identities and relationships rather than static rule matching alone. Through API-based integrations into Microsoft 365, Google Workspace, and other connected SaaS applications, the platform ingests large volumes of contextual signals and builds per-identity and per-relationship baselines. In practice, that means it is not only evaluating whether an email or login looks suspicious in isolation, but whether a sequence of events deviates from how a user, vendor, or service normally behaves over time.</p><p>This model is visible in the company&#8217;s current product set. Its cloud email security offering focuses on phishing, vendor email compromise, and other socially engineered attacks that bypass traditional email defenses. Its account takeover products extend that behavioral approach into Microsoft 365, Google Workspace, and SaaS applications, where Abnormal correlates signs such as unusual sign-ins, mailbox-rule changes, abnormal location or device context, and suspicious downstream activity. Abnormal&#8217;s integrations with Crowdstrike are especially relevant to this report because they feed context from their in-depth behavioral analysis across multiple sources into identity and response workflows, reinforcing the verification-in-workflow pillar of SEID.</p><p>Abnormal describes its core advantage as cross-signal correlation over time. They argue that subtle events often do not cross a threshold on their own, but become high-confidence evidence when chained together across email, sign-ins, device context, vendor relationships, and subsequent SaaS behavior. That claim is analytically important for SEID because social engineering-driven identity abuse often appears benign when viewed as isolated steps. The problem becomes clearer only when communications context and post-authentication behavior are considered together.</p><p>From an SEID perspective, the key architectural point is that Abnormal treats communications and cloud activity as an evidence layer about identity trust. A suspicious reset or service request should be interpreted differently if it is preceded by thread hijacking, a compromised vendor relationship, impossible travel, mailbox-rule manipulation, or other behavior that diverges from the employee&#8217;s historical pattern. Abnormal&#8217;s value is in assembling that context earlier and more coherently than tools that only inspect a single channel or a single event type.</p><h3>Competition and Positioning</h3><p>For the purposes of this report, Abnormal overlaps with several adjacent categories. It overlaps with email security platforms, ITDR vendors, SaaS security tools, and a broader set of behavioral analytics vendors that claim to detect social engineering and account misuse. Its practical differentiator is the attempt to unify those surfaces around one behavioral model of people, relationships, and cloud activity rather than treating them as separate detection silos.</p><p>That position gives Abnormal a distinctive place in the SEID landscape. Vendors centered on authentication, MFA, or identity provider telemetry are often strongest at login and session controls but weaker at interpreting the communications and relationship context that frequently precedes compromise. Email-focused tools can identify phishing or impersonation but often stop short of building a broader identity-risk narrative across SaaS and service workflows. Abnormal is interesting because it is moving across that boundary. If the platform can reliably join communication behavior, account takeover evidence, and cloud activity into a coherent case, it starts to resemble a contextual trust layer for workforce identity decisions.</p><p>The strategic limit is also clear. Abnormal does not, by itself, solve the full Verification-in-Workflow problem. It does not replace authoritative identity systems, approval policy, or workflow orchestration. Its role is better understood as upstream context and autonomous detection that can improve the quality of identity decisions made elsewhere. In a mature SEID architecture, that may be valuable precisely because the system supplying context should remain distinct from the system granting final authority.</p><h3>Implications for SEID</h3><p>Abnormal is most relevant to the third SEID pillar, Cross-Channel Identity Trust, and secondarily to Measurable Outcomes and Auditability because it can generate contextual cases, risk signals, and audit data that other systems can consume. It also has emerging relevance to Verification-in-Workflow if its identity roadmap produces a stable way to feed behavioral attestation into help desk, reset, or recovery flows.</p><p>The practical importance of Abnormal in this report is not that it provides a complete SEID stack. It demonstrates where part of the market is heading: toward identity decisions informed by behavioral context drawn from email, collaboration, ticketing, and SaaS activity rather than by authentication status alone. That shift matters because many socially engineered identity incidents are decided in the period between the first trust signal and the final privileged action.</p><p>Key open questions to validate include how broadly and reliably Abnormal can correlate behavior across non-email systems at scale, how explainable its behavioral decisions remain during high-consequence identity workflows, and how well its account takeover and ticketing context can be operationalized by downstream workflow engines.</p><h1>Practitioner Takeaways</h1><p>Practitioners should begin by inventorying identity transactions that sit outside normal sign-in. Password resets, MFA changes, onboarding approvals, and other exception paths deserve the same review rigor as primary authentication because they can alter trust and access just as materially. In many environments, the most useful first move is not another front-door control. It is a stronger decision gate at the point of change, where a reset, recovery, or approval is about to be executed.</p><p>That shift also requires a different operating model for human-facing teams. Help desk agents, recruiters, and HR staff need bounded policy, clear escalation, and evidence-backed approvals so that high-risk decisions do not depend on improvisation. At the same time, organizations need context to travel across channels. Email, voice, collaboration, and service workflows should inform one another when a sensitive identity action is pending. If a team cannot explain who requested the action, what evidence was used, and why it was approved, the control is not yet mature enough. That is also why a layered vendor strategy matters. Workflow verification and cross-channel context may come from different tools, so architecture and data flow deserve as much attention as feature depth.</p><h1>Conclusion</h1><p>Adopting a SEID solution is critical because it gives security leaders a way to describe a problem that many organizations are already experiencing but often categorize in fragments. The help desk sees account recovery abuse. Recruiting sees synthetic candidates. Email security sees impersonation. Identity teams see pressure on MFA and exception flows. SEID connects those issues at the level where they share a common cause: sensitive identity decisions are still being made in workflows built for service delivery rather than adversarial trust enforcement.</p><p>As authentication continues to improve, the center of gravity in workforce identity security will keep moving toward those workflows. That does not reduce the importance of IAM or MFA. It expands what a complete identity defense program has to cover. Organizations that extend verification, governance, shared context, and auditability into recovery, onboarding, and other exception paths will be better positioned to reduce attacker leverage.</p><p>The practical next move is to treat identity-changing workflows as a core element and integrated capability of the future enterprise identity plane, then design controls accordingly. That is the core contribution of SEID and the reason the category is worth tracking.</p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Software Analyst Cyber Research! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/subscribe?"><span>Subscribe now</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/p/introducing-social-engineering-identity/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/p/introducing-social-engineering-identity/comments"><span>Leave a comment</span></a></p><div class="directMessage button" data-attrs="{&quot;userId&quot;:6770950,&quot;userName&quot;:&quot;SACR&quot;,&quot;canDm&quot;:null,&quot;dmUpgradeOptions&quot;:null,&quot;isEditorNode&quot;:true}" data-component-name="DirectMessageToDOM"></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/p/introducing-social-engineering-identity?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/p/introducing-social-engineering-identity?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[CyberMadness: Motion & Tailwinds Report 2025-2026]]></title><description><![CDATA[A Strategic Guide to the Key Shifts, Market Forces, and Tech Shifts from 2025 into 2026]]></description><link>https://softwareanalyst.substack.com/p/cybermadness-motion-and-tailwinds</link><guid isPermaLink="false">https://softwareanalyst.substack.com/p/cybermadness-motion-and-tailwinds</guid><dc:creator><![CDATA[SACR]]></dc:creator><pubDate>Tue, 28 Apr 2026 20:47:56 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!29hT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F43493bbb-ca1b-474f-9bbd-58cc71af22d0_1920x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p></p><div><hr></div><h2><strong>Executive Summary</strong></h2><p>This is a thought-leadership report based on the accumulated annual research work of the SACR and Deutsch &amp; Co research teams, which included 200+ CISO interactions and recorded interviews, 100+ founding team interviews, and internal reviews of 50+ teams backed by industry-defining VCs. It is meant to provide an overview of 2025&#8217;s motions and trends to help security professionals, founders, and investors navigate the tailwinds of 2026. We will have an upcoming report on our perspectives on Mythos tomorrow. </p><p>Please visit <strong><a href="https://www.cybermadness.io/">the official website</a></strong> to view detailed findings &gt; </p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybermadness.io/&quot;,&quot;text&quot;:&quot;State of Cyber&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cybermadness.io/"><span>State of Cyber</span></a></p><p></p><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;0ab67a98-ec06-45ef-9dde-7242efc628c5&quot;,&quot;duration&quot;:null}"></div><div><hr></div><h2><strong>Authors</strong></h2><ul><li><p><strong>Software Analyst Cybersecurity Research (SACR)</strong> is an independent research and advisory organization focused on helping CISOs, founders, investors, and security teams understand where cybersecurity is heading. Through in-depth industry reports, analyst research, vendor analysis, and shorter thought pieces, SACR analyzes emerging technologies, market shifts, and vendor strategies across key security domains. The firm was founded by <strong>Francis Odum</strong>, Founder and Chief Cybersecurity Analyst, who built SACR into one of the largest independent cybersecurity research platforms in the market. He is recognized for his work with over 60,000 security professionals worldwide and for establishing SACR as a trusted brand among CISOs and leading vendors. </p></li><li><p><strong>Deutsch &amp; Co</strong> is a private equity firm focused on investing in and building category leaders across cybersecurity and AI. The firm&#8217;s investment strategy is grounded in proprietary research, including hundreds of annual interviews with industry leaders, buyers, and practitioners, used to identify emerging market gaps and define new categories. By combining research-driven insights with strategy, positioning, and branding, Deutsch &amp; Co partners with companies to help shape and lead the categories they operate in. The firm was founded by <strong>Roei Deutsch</strong>, who serves as CEO.</p></li></ul><div><hr></div><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Software Analyst Cyber Research! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><div><hr></div><h2><strong>Actionable Summary</strong></h2><p>This report distills the key shifts, signals, and strategic implications shaping cybersecurity in 2026, based on extensive research across CISOs, operators, and leading vendors. It is designed to help security leaders, builders, and investors understand what fundamentally changed in 2025 and how to navigate what comes next.</p><p>Cybersecurity has entered a new phase defined by the operationalization of AI. Both attackers and defenders are now leveraging automation at scale, turning security into a competition of speed, execution, and feedback loops rather than static controls. In this environment, three foundational changes are reshaping the industry.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!29hT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F43493bbb-ca1b-474f-9bbd-58cc71af22d0_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!29hT!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F43493bbb-ca1b-474f-9bbd-58cc71af22d0_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!29hT!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F43493bbb-ca1b-474f-9bbd-58cc71af22d0_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!29hT!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F43493bbb-ca1b-474f-9bbd-58cc71af22d0_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!29hT!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F43493bbb-ca1b-474f-9bbd-58cc71af22d0_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!29hT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F43493bbb-ca1b-474f-9bbd-58cc71af22d0_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/43493bbb-ca1b-474f-9bbd-58cc71af22d0_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1452919,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://softwareanalyst.substack.com/i/195248866?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F43493bbb-ca1b-474f-9bbd-58cc71af22d0_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!29hT!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F43493bbb-ca1b-474f-9bbd-58cc71af22d0_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!29hT!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F43493bbb-ca1b-474f-9bbd-58cc71af22d0_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!29hT!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F43493bbb-ca1b-474f-9bbd-58cc71af22d0_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!29hT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F43493bbb-ca1b-474f-9bbd-58cc71af22d0_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>First, the market is consolidating toward platforms, as organizations move away from fragmented tools and demand measurable efficiency and outcomes. Second, context has become the core engine of security, with decisions increasingly driven by identity, behavior, and business relevance. Third, identity has emerged as the new perimeter, as non-human identities and autonomous agents rapidly expand the attack surface and force a shift toward continuous, just-in-time access control.</p><p>At the same time, risk is evolving from securing systems to governing autonomous agents, and from data theft to operational disruption. These dynamics are driving major changes across the stack, including AI-augmented SOCs, LLM security and governance, data-layer decoupling, and upstream application security.</p><p>The direction is clear: cybersecurity is converging toward a unified, context-aware, identity-driven control plane designed to secure autonomous systems at scale.</p><div><hr></div><p></p><h2><strong>A Year in Review </strong></h2><p>AI stopped being an experiment in 2025 and became operational. Across the security stack - in SOC workflows, developer environments, and adversary toolkits - AI moved from pilot projects into everyday use. So, as attackers and defenders suddenly could iterate more quickly and test more ideas, traditional security processes were clearly outpaced.</p><p>That shift forced real changes in how teams operate. Agentic triage began cutting through alert noise, and federated detections improved the signal across fragmented environments. Just-in-time privilege models started shrinking blast radius, and continuous red teaming replaced assumptions with constant validation. At the same time, resilience and recovery stopped being aspirational goals and became measurable expectations for boards and leadership teams.</p><p>This report relies on three signal types: direct feedback from CISOs, observable vendor roadmap shifts, and the operational lessons of major incidents throughout 2025. It focuses on what truly changed - and what those changes mean for 2026. The report is organized in three parts: the trends that defined 2025, five technology pivots grounded in clear signals and measurable KPIs, and practical recommendations for the year ahead.</p><p></p><h3><strong>Top Tailwinds</strong></h3><ul><li><p><strong>AI vs. AI Warfare:</strong> The accelerated operationalization of AI by adversaries, which forces defenders to adopt AI-Native solutions and automation cycles to keep up.</p></li><li><p><strong>Shadow AI Management:</strong> The rapid, unmanaged spread of employee use of AI tools, which is becoming a top operational risk by bypassing security and data controls.</p></li><li><p><strong>LLM Marketing Fatigue:</strong> Deep market skepticism towards generic AI claims, leading to a strong demand for transparency, measurable KPIs, and auditability in all AI-driven products.</p></li></ul><p></p><h3><strong>Top Motions</strong></h3><ul><li><p><strong>Consolidation:</strong> A strong market shift demanding fewer tools with broader platform capabilities, driving vendors to focus on measurable cost-efficiency like &#8220;Cost Per Investigated Alert.&#8221;</p></li><li><p><strong>Contextualization:</strong> Vendors are actively making business, behavioral, and operational context the primary engine for security tools, underpinning decisions like alert triage and privilege grants.</p></li><li><p><strong>The Rise of Agents:</strong> The focus has moved from securing AI models to governing autonomous agents operating across enterprise systems. Security now centers on behavior, access, and execution.</p></li></ul><p></p><h3><strong>Disrupted Categories</strong></h3><ul><li><p><strong>Identity, Privilege and Access Risk:</strong> Non-human identities are rapidly outnumbering human users across cloud and SaaS environments. This expanded the attack surface and accelerated the shift toward just-in-time access and zero-standing privilege models. Now vendors are beginning to build identity and access control layers specifically for autonomous agents.</p></li><li><p><strong>AI-Native SecOps Platforms:</strong> A new class of platforms integrating AI and autonomous agents to perform Tier-1 work in Security Operations Centers.</p></li><li><p><strong>LLM Security and Governance:</strong> Tools and solutions focused on managing the specific security and safety risks of Large Language Models, including measuring Hallucination Rate and Guardrail Accuracy.</p></li><li><p><strong>Security Data Pipeline and Platform Consolidation:</strong> The new architecture of vendor-agnostic security data pipelines, decoupling storage and compute to allow detections to run wherever the data resides. </p></li><li><p><strong>AI Coding and Application Security:</strong> The AppSec domain is shifting to move critical controls upstream into the developer workflow and secure code that is written or assisted by AI.</p><p></p></li></ul><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Software Analyst Cyber Research! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><div><hr></div><h2><strong>What Dominated 2025: Overall Trends </strong></h2><p>Throughout 2025, recurring themes emerged from private CISO forums, executive briefings, and peer discussions, revealing both the risks that dominated security leaders&#8217; attention and the priorities shaping their outlook for 2026. Here are the highlights.</p><h3><strong>The Rise of Agents</strong></h3><p>In 2025, the industry conversation shifted from &#8220;security for AI/LLMs&#8221; to securing agentic platforms themselves. Early discussions focused on model risks such as prompt injection, hallucinations, and data leakage. But as enterprises moved beyond experimentation and began embedding AI into real workflows, the conversation rapidly shifted. LLMs stopped being static assistants or chatbots and began evolving into agents, capable of taking actions across systems, chaining tools together, and operating with increasing autonomy.</p><p>This shift reframed the security challenge: the problem was no longer just securing models, but governing the behavior, access, and execution of autonomous systems interacting with enterprise infrastructure. <strong>By the end of 2025, it became clear that the next phase of cybersecurity will center not simply on AI safety, but on securing agentic systems operating inside real enterprise environments.</strong></p><p>As organizations began operationalizing agentic systems inside real enterprise environments, a deeper challenge quickly emerged: governing the identities and actions of machines operating at scale. Traditional IAM and SSO architectures, designed for predictable human logins, struggle to manage agents that execute high-frequency, non-deterministic tasks using long-lived credentials across multiple systems. As a result, 2026 will see the emergence of Agentic Identity Access Platforms (AIAP): a new identity control layer that acts as an &#8220;SSO for Agents,&#8221; brokering task-scoped, ephemeral identities based on agent intent. <strong>In the agentic era, identity security will shift from verifying who is acting to continuously governing why an action is occurring and how long access should exist.</strong></p><h4><strong>Key Industry Moves and Company Launches in 2025</strong></h4><ul><li><p><strong>Companies evolved in the past year: </strong>Keycard (Access Governance), Fabrix (Access Governance), AgentField (Access Governance), Scalekit, ONYX, Token Security, Straiker, Singulr AI, EVE, Geordie, Manifold, Virtue AI, Aiceberg, Aurascape, Capsule Security, AuthMind, Pillar Security, Hush Security, Zenity, Noma Security, Mint Security (in stealth), Judgment Labs.</p></li><li><p><strong>Moves by legacy companies (M&amp;A/launches): </strong>Okta (Launched &#8220;Okta for AI Agents&#8221;), CrowdStrike (Launched visibility and control of AI agents and acquired Pangea and SGNL), Palo Alto Networks (Launched a module for real-time monitoring of agentic AI endpoints and acquired Protect AI), Microsoft (Launched Entra Agent ID), GitGuardian, SailPoint, Saviynt.</p></li><li><p><strong>Companies acquired in the past year: </strong>Pangea, Protect AI, Prompt Security, Lakera, AIM security, Calypso AI, Invariantlabs, Cyata, CyberArk.</p></li></ul><blockquote><p><em>&#8220;Amid the excitement of embracing the next wave of generative AI, companies are moving quickly to deploy agentic use cases, often overlooking the critical need to secure these systems and control the sprawl of non-human identities.&#8221;</em></p><p><strong>- Arnab Bose</strong>, Former Chief Product Officer, Okta</p><p><em>&#8220;AI agents are quickly becoming a new class of workforce in the enterprise, but they require more complex identity lifecycle management than human users.&#8221;</em></p><p><strong>- Itamar Apelblat</strong>, CEO &amp; Co-Founder</p><p><em>&#8220;AI agents don&#8217;t just authenticate, they take action, call APIs, chain workflows, and make decisions. Securing them requires treating identity as a runtime control plane, not a one-time configuration.&#8221;</em></p><p><strong>- Ido Shlomo</strong>, CTO &amp; Co-Founder, token</p><p><em>&#8220;Enterprises are moving beyond simple AI chatbots to fully autonomous agents -but with this evolution comes an exponential rise in security and safety risks. The threat vector has escalated from basic prompt injection attacks to mass data exfiltration, supply chain attacks, and even autonomous chaos.&#8221;</em></p><p><strong>- Ankur Shah</strong>, CEO &amp; Co-Founder, Straiker</p></blockquote><h3><strong>Shadow AI Was The most Consistent CISO Concern Of 2025</strong></h3><p>Across CISO dinners, closed-door forums, and year-end briefings, Shadow AI<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a> emerged as the most cited operational risk. <strong>AI tools proved useful enough that adoption quickly outpaced security&#8217;s ability to inventory and govern them. </strong>Employees uploaded sensitive data into copilots, browser extensions, and SaaS AI features with little visibility into data flow or retention.</p><p>This wasn&#8217;t reckless behavior - AI was becoming embedded in everyday workflows, making its use inevitable. Blocking it outright didn&#8217;t work; it simply pushed activity into unmonitored channels. The real concern was the absence of control, logging, and policy enforcement. Shadow AI became a symptom of a deeper issue: security teams losing visibility into how work actually happens.</p><p><strong>By 2025, the conclusion was unavoidable: AI is here. Security teams must navigate it - without losing control.</strong></p><p>Security leaders described a tension between innovation and risk. Development teams moved quickly, leadership encouraged experimentation, and security teams were asked to approve systems they barely understood yet.</p><p><strong>The most effective organizations responded by narrowing scope.</strong> They permitted AI in defined domains, such as SOC triage, documentation, and internal tooling, while enforcing guardrails on data access, actions, and auditability. The lesson for 2026 is not to slow AI, but to effectively constrain the boundaries in which it operates.</p><h3><strong>Autonomous Offense vs. Defense: AI-Driven Cyber Warfare</strong></h3><p>2025 was a transition year: security programs began a slow pivot away from non-AI-native stacks, just as adversaries operationalized AI tooling at scale. The resulting shift in attack patterns - faster iteration, lower-cost experimentation, and compressed time-to-breach - made legacy approaches objectively insufficient. For CISOs, this became an additional, concrete driver for modernization: when both sides are automated, advantage accrues to the party that closes the loop first. <strong>In practice, &#8220;AI vs. AI&#8221; is simply competing automation cycles: faster learning, tighter feedback, and broader execution.</strong></p><p>That acceleration also shifted the core risk from data theft to operational paralysis. Incidents like the Jaguar Land Rover attack (estimated $2.5B impact),<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a> SaaS-jacking campaigns targeting major SaaS platforms,<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-3" href="#footnote-3" target="_self">3</a> and the Salt Typhoon espionage<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-4" href="#footnote-4" target="_self">4</a> activity showed attackers increasingly optimizing for continuity disruption and deep infrastructure access - not just exfiltration. The implication is blunt: security failures are now business-stopping events, not merely confidentiality breaches.</p><p>This reality resulted in two new priorities for security teams: <strong>resilience and recovery</strong>.</p><h4><strong>Resilience</strong></h4><p>Organizations moved away from periodic assurance toward continuous validation, treating security posture as something you prove, not assume. Continuous red teaming and autonomous attack simulation began shifting from &#8220;advanced program&#8221; to an operating baseline, <strong>continuously exercising real attacker paths and measuring whether controls still prevent, detect, and contain under evolving tactics.</strong> Just as importantly, teams started validating execution, not just documentation: playbooks were drilled through repeatable technical exercises to surface latency, ownership gaps, and brittle dependencies - turning response into a practiced capability rather than a binder on a shelf.</p><h4><strong>Recovery</strong></h4><p>In 2025, cyber resilience increasingly became the board&#8217;s yardstick for security performance: assume incidents will occur, and measure how quickly the business can restore critical operations. That reframed investment toward verified, attack-resistant recovery - <strong>tiered RTO/RPO commitments, dependency-aware restoration sequencing, and routine proof that backups are recoverable and operationally usable.</strong> Teams also reduced human latency by operationalizing response and recovery workflows through orchestration and automation, turning playbooks into executable procedures rather than documentation. Mature programs now manage recovery readiness like an SLO: restoration time for Tier-0 services, recovery success rate, and time-to-restore under realistic conditions - continuously validated and extended across critical third- and fourth-party dependencies.</p><h4><strong>Key Industry Moves and Company Launches in 2025</strong></h4><ul><li><p><strong>Companies launched in the past year: </strong>Armadin, Novee, Gambit, Terra, RunSybil, Bold Security, Cuantro Security, Cogent, Tenzai, XBOW.</p></li><li><p><strong>Moves by legacy companies (M&amp;A/launches): </strong>Microsoft (Expanded security Copilot agents), Pentera (Acquired E.V.A Information Security), SentinelOne (Upgraded Purple AI &#8220;Athena&#8221; - agentic auto-triage and auto-investigation), Palo Alto Networks (Launched Prisma AIRS 2.0).</p></li><li><p><strong>Companies acquired in the past year: </strong>E.V.A Information Security</p></li></ul><blockquote><p><em><a href="https://venturebeat.com/security/crowdstrike-bets-on-agentic-workforces-to-outpace-ai-driven-adversaries">&#8220;We&#8217;re moving from the analyst&#8217;s hands on the steering wheel to autonomous actions that are effective, safe, and reliable. We need full autonomy, it&#8217;s not optional, it&#8217;s foundational.&#8221;</a></em></p><p><strong>- George Kurtz</strong>, CEO, CrowdStrike</p><p><em><a href="https://www.securityweek.com/kevin-mandias-armadin-launches-with-189-9-million-in-funding/">&#8220;I believe within the next few years virtually all cyberattacks will be AI-based - swarming, tailored, and relentless. They will be untethered to human limitations and capable to execute on a scale we have never witnessed before.&#8221;</a></em></p><p><strong>- Kevin Mandia</strong>, CEO &amp; Founder, Armadin</p><p><em><a href="https://fintech.global/2026/01/16/ai-cyber-defence-firm-novee-bags-51-5m-to-counter-attacks/">&#8220;Attackers don&#8217;t wait for your annual pentest. Neither should your defense. What security teams actually need are high-signal findings they can trust: novel vulnerabilities that are proven exploitable.&#8221;</a></em></p><p><strong>- Ido Geffen</strong>, CEO &amp; Co-Founder, Novee</p><p><em><a href="https://qa-financial.com/terra-security-ceo-future-of-pentesting-is-about-giving-humans-leverage/">&#8220;Fully autonomous testing tools promise efficiency but introduce security risks and inaccuracies in production environments. Traditional pentesting tools force testers into manual workflows, limiting scalability. Resolve this tension by enabling autonomous pentesting to scale through human-governed AI execution.&#8221;</a></em></p><p><strong>- Shahar Peled</strong>, CEO &amp; Co-Founder, Terra</p></blockquote><h3><strong>Contextualization Is Everywhere</strong></h3><p>Across virtually all sectors, vendors, customers, and domain experts are signaling the shift toward contextual security. <strong>Alert triage and enrichment are increasingly executed through the lens of business-critical context</strong>; just-in-time privileges are being issued and revoked based on usage context and behavioral pattern recognition; and secure coding is shifting toward context-aware guidance - surfacing prescriptive fixes directly from pull requests and code reviews. <strong>Context is no longer merely an input to security decisions; it now underpins them</strong>. Its influence is pervasive today and is poised to become even more dominant over the coming year.</p><h3><strong>The Great Security Platform Convergence</strong></h3><p>By 2025, security tooling fragmentation was becoming harder to justify: <strong>many teams were running broad stacks of overlapping tools across endpoint, identity, cloud, network, and detection</strong>. That sprawl added unnecessary costs and operational burden (more integrations, more policy surfaces, more triage), yet left teams with hard-to-trace visibility gaps.</p><p>At the same time, we started seeing clearer consolidation signals. Among others, Google&#8217;s acquisition of Wiz suggests that leading point solutions are increasingly being treated as &#8220;platform-grade&#8221; capabilities. Despite ongoing concerns around vendor lock-in, we expect 2026 to extend this direction: <strong>more stack rationalization and more vendor consolidation, with a stronger emphasis on fewer tools that drive prioritized remediation over noisy detection</strong>.</p><p>This trend is amplified by the previous topic-contextualization, as the trend of putting AI &amp; organizational context in the core of each security product, brings the different tools - and traditionally-defined cybersecurity quadrantable categories - even closer together.</p><h4><strong>Select Industry Moves and Company Launches in 2025</strong></h4><ul><li><p><strong>Moves by legacy companies (M&amp;A/launches): </strong>Google (Acquired Wiz), CrowdStrike (Acquired Onum), SentinelOne (Acquired Observo AI, Prompt Security), Palo Alto Networks (Acquired CyberArk, Chronosphere and Koi), ServiceNow (Acquired Armis, Moveworks and Veza)</p></li><li><p><strong>Companies acquired in the past year: </strong>Wiz, Onum, Observo AI, Chronosphere, Koi, Armis, Moveworks, CyberArk, Veza, Prompt Security.</p></li></ul><blockquote><p><em><a href="https://www.calcalistech.com/ctechnews/article/hy1qvx7dzx">&#8220;We&#8217;re seeing a trend towards more consolidation, more platformization. You cannot respond fast if you&#8217;ve got 70 different vendors who have different data, different logs, different APIs running.&#8221;</a></em></p><p><strong>- Nikesh Arora</strong>, Chairman &amp; CEO, Palo Alto Networks</p><p><em><a href="https://www.sdxcentral.com/news/crowdstrike-eyes-market-share-gains-as-sentinelone-and-blackberry-in-potential-sale-talks/">&#8220;What was a market littered with dozens of companies is quickly consolidating to several vendors.&#8221;</a></em></p><p><strong>- George Kurtz</strong>, CEO, CrowdStrike</p></blockquote><h3><strong>LLM Marketing Fatigue Set In Quickly</strong></h3><p><strong>By mid-2025, CISOs were openly dismissive of generic AI and LLM claims</strong>. Many vendors added &#8220;AI&#8221; to their messaging without fundamentally changing their products, and hype alone no longer inspired trust. CISOs demanded both proof of the advantages of the LLM through clear KPIs and a measurable way to audit, understand, and control its behavior. Vendors that couldn&#8217;t provide precise answers, validation, or evidence quickly lost credibility. Adoption would no longer be driven by marketing claims - security leaders wanted results, not buzzwords.</p><p><strong>During 2026, the term &#8220;AI agent&#8221; or &#8220;agentic LLM&#8221; is prone to suffer the same fate, as CISOs now see past the AI hype, demanding demonstrable value and explainability.</strong></p><h2><strong>Distinguished Tech Pivots</strong></h2><p>The following five areas capture the main structural changes that defined 2025 and now shape 2026 planning and execution.</p><h3><strong>The Autonomous SOC: The Emergence of AI SOC</strong></h3><h4><strong>What happened in 2025</strong></h4><p>2025 was the year AI stopped being a toy in the SOC and started carrying real Tier-1 load.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-5" href="#footnote-5" target="_self">5</a> Leading vendors and early adopters put agentic systems in the alert path: they triage and cluster alerts, crush duplicate noise, enrich incidents from security data lakes using retrieval-augmented reasoning, and auto-draft response playbooks for analysts to review and approve. The conversation at the front of the market shifted from &#8220;should we add a copilot?&#8221; to &#8220;how far are we willing to let agents act on their own?&#8221;. Fear of fully autonomous response, from hallucinated actions, missed or downgraded real attacks, to uncontrolled blast radius and opaque decision trails, remained a hard constraint, reinforced by new AI and cyber regulations<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-6" href="#footnote-6" target="_self">6</a> that insist on human oversight and accountability for high-impact security actions. <strong>Exactly where the line for true autonomy should sit is still very much unresolved, and the category will only become non-optional once there is hard evidence that SOC performance improves dramatically, without increasing the probability or impact of false negatives at scale</strong>.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-7" href="#footnote-7" target="_self">7</a></p><p>At the same time, it is hard to point to any single KPI that will unambiguously improve, as every gain in SecOps will be met by corresponding adaptations along the attackers&#8217; kill chain, including adversaries&#8217; own use of agentic AI to probe, evade, and poison automated defenses.</p><h4><strong>Vendor signals</strong></h4><p>Vendors turned autonomy into a dial. The same agents can run in &#8220;recommend only&#8221;, &#8220;human approval&#8221;, or &#8220;auto-execute within guardrails&#8221; modes, effectively moving SOC operators into an oversight role over policy and risk. In parallel, products started to expose more AI plumbing - model choices, lineage, and audit trails - to give security and compliance teams real visibility into what the agents do and to make their behavior auditable.</p><h4><strong>Security leader signals</strong></h4><p>Leaders adopted AI &#8220;inside the fence&#8221; first: alert triage, incident writeups, control mapping, and compliance documentation - areas where agents could be wrong without taking production down. The real question quietly shifted from &#8216;will AI replace analysts?&#8217; to &#8216;will AI finally let analysts do analyst work?&#8217; They also insisted on guardrails: SOC change control, red-teaming of agents, sandboxed and scoped execution, as well as actions that are signed, logged, and rollback-capable.</p><h4><strong>Why it matters</strong></h4><p>Measurable productivity gains in SOCs depend on pushing more work to AI while keeping core metrics: time to detect, time to respond, dwell time, and error rates - flat or improving, and without raising the risk of bad changes. Trust rests on grounded outputs and strict guardrails on what agents can touch, but above all on uncompromising auditability: every recommendation and action is logged, explainable, and traceable back to data, model, and approver.</p><h4><strong>KPIs to watch</strong></h4><ul><li><p>Share of alerts triaged by agents, and the analyst approval/override rate on those decisions</p></li><li><p>Time-to-first-draft for incidents (from alert to usable writeup) and the associated human-rated quality scores</p></li><li><p>Agent-initiated actions with full audit trail and successful rollback rate (including tested and actual rollbacks)</p></li></ul><h4><strong>2026 outlook - Motions &amp; Tailwinds</strong></h4><p><strong>We&#8217;ll see a shift from assistive workflows to semi-autonomous response for low-risk changes</strong>, governed by policy and confidence thresholds. For example, automatically disabling a non-privileged account following a high-confidence login anomaly, with full auditability and rollback. The rising efficiency of attackers using AI, combined with the productivity boost from AI-powered SOCs, will drive widespread adoption, commoditization, and a shift in differentiation toward user experience and vertical flavors (e.g., &#8220;AI SOC for X industry&#8221;). In parallel, the traditional boundary between detection and cloud/ops will erode as SOC teams will gain the tooling and permissions to execute a larger share of routine operational actions.</p><h4><strong>Key Industry Moves and Company Launches in 2025</strong></h4><ul><li><p><strong>Companies launched in the past year: </strong>Mate, 7AI, Legion, Conifers, Prophet Security, Zenyard, Exaforce, Cotool, Tenex AI, Kenzo Security, Bricklayer AI, Fig Security, Anomali, Surf AI.</p></li><li><p><strong>Moves by legacy companies (M&amp;A/launches): </strong>Microsoft (Embedded agentic triage directly into M365 E5), SentinelOne (Upgraded to &#8220;Athena&#8221; with agentic auto-triage and auto-investigation), CrowdStrike (Launched 7 autonomous SOC agents), Palo Alto Networks (Launched AgentiX autonomous investigation and response framework), Google (Launched Agentic SOC agents within Google SecOps).</p></li><li><p><strong>Companies acquired in the past year: </strong>Wirespeed</p></li></ul><blockquote><p><em><a href="https://www.linkedin.com/posts/liordiv_rsac2026-share-7434340866581757952-JpF2?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAGEm9LMBi9xuMrkuI1UkyaY2YUYf14Odq0I">&#8220;A year ago, every meeting started with: &#8216;Does AI actually work in security?&#8217; Today, it&#8217;s: &#8216;How do I operationalize AI agents in my SOC?&#8217;&#8220;</a></em></p><p><strong>- Lior Div</strong>, CEO and Co-Founder, 7AI</p><p><em><a href="https://www.securityweek.com/mate-emerges-from-stealth-mode-with-15-5-million-in-seed-funding/">&#8220;The old approach of configuring and maintaining endless playbooks doesn&#8217;t scale. Attackers are already using AI to launch bigger and faster campaigns. Security teams need tools that don&#8217;t just keep up but actually learn and improve continuously.&#8221;</a></em></p><p><strong>- Asaf Wiener</strong>, CEO &amp; Co-Founder, Mate</p><p><em><a href="https://venturebeat.com/ai/ai-vs-ai-prophet-security-raises-30m-to-replace-human-analysts-with-autonomous-defenders">&#8220;This is not about eliminating jobs. It&#8217;s about ensuring an analyst doesn&#8217;t have to spend time triaging and investigating alerts, because who wants to do that all day, every day? Instead, they can focus on the 4% of issues that truly matter to an organization.&#8221;</a></em></p><p><strong>- Kamal Shah</strong>, CEO, Prophet Security</p><p><em><a href="https://www.linkedin.com/posts/ely-abramovitch-a3a912bb_some-thoughts-and-rants-about-ai-soc-metrics-share-7422020732093816832-aXtK?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAGEm9LMBi9xuMrkuI1UkyaY2YUYf14Odq0I">&#8220;What we actually want to measure is that the AI is accurate, comprehensive, and that it takes on work that is actually valuable. If it is, measuring how many equivalent analyst hours are done by the AI is a great metric to start with.&#8221;</a></em></p><p><strong>- Ely Abramovitch</strong>, CEO &amp; Co-Founder, Legion</p></blockquote><h3><strong>LLM Security and Governance</strong></h3><h4><strong>What happened in 2025</strong></h4><p>By 2025, LLMs were running at scale inside enterprises - dev tools, productivity suites, and SOC consoles - so security, risk, and compliance had to lock in. LLM risk management became concrete: control frameworks and checklists scored model safety, hallucination risk, and data exposure for high-impact use. Regulators raised the bar with AI and privacy rules that expect human oversight, logging, and strong data controls around high-risk workloads. Guardrails carried a double mandate: security (no PII spills, no prompt-injected SQL against production) and safety (keeping models inside acceptable behavior and policy in high-stakes workflows). Psychological jailbreaks, socially engineered prompts and other forms of manipulation emerged as a visible attack surface. Model and security vendors answered with hard controls - behavioral policies, input/output filtering, policy-based access, continuous red-teaming, and even AI-driven red-teaming in production to iteratively strengthen guardrails - to keep prompt injection, data leakage, and other LLM failure modes inside a visible, auditable fence, with some programs also experimenting with behavioral red-teaming to probe manipulative, multi-turn attacks.</p><h4><strong>Vendor signals</strong></h4><p><strong>Platforms now ship with guardrails that enforce security and safety policies, backed by explainability, observability, and real-time monitoring dashboards</strong>. Compliance reporting increasingly maps directly to ISO/IEC 42001 controls rather than ad-hoc &#8220;responsible AI&#8221; checklists. Model risk management is no longer a parallel track; it is wired into mainstream MLOps pipelines as a first-class stage for validation, approvals, and ongoing monitoring. Psychological maneuvering has become a problem, and behavioral red-teaming started showing up.</p><h4><strong>Security leader signals</strong></h4><p>By 2025, many organizations effectively ran two AI policies: the formal one in the handbook, and the shadow policy that actually lived in Slack. Security leaders refused to accept that reality: they now demand governed LLM behavior with hard guardrails against toxic, biased and hallucinated outputs, plus audit trails and human review on high-impact decisions. At the same time, they expect LLMs to snap into their existing Zero Trust and data security stack, with strict data leakage controls, purpose-based and least-privilege access, continuous monitoring for adversarial misuse, and formal AI governance over both sanctioned and shadow AI.</p><h4><strong>Why it matters</strong></h4><p>LLMs introduce risks - hallucinations, bias, prompt injection - that traditional security controls miss. Visibility, Monitoring, Governance, and Auditability must be first-class concerns across the entire AI lifecycle, from data collection and training through deployment, inference, and eventual retirement.</p><h4><strong>KPIs to watch</strong></h4><ul><li><p>Hallucination rate in production</p></li><li><p>Guardrail intervention frequency and accuracy</p></li><li><p>Time to detect and remediate adversarial inputs</p></li></ul><h4><strong>2026 outlook - Motions &amp; Tailwinds</strong></h4><p>LLM security and safety will be pulled into mainstream AppSec: teams will bake in guardrails by default, treat model attestations as compliance evidence, and push behavioral monitoring earlier into the SDLC.</p><h4><strong>Key Industry Moves and Company Launches in 2025</strong></h4><ul><li><p><strong>Companies launched in the past year: </strong>Virtue AI, Aiceberg, Aurascape, SolidCore, Runlayer, Meibel, Pillar Security.</p></li><li><p><strong>Moves by legacy companies (M&amp;A/launches): </strong>Palo Alto Networks (Acquired Protect AI), Snyk (Launched AI Trust Platform, acquired Invariant Labs), Microsoft (Announced Prompt Shields, updates of Azure Foundery), F5 (Acquired Calypso AI), AWS (Launched Amazon Bedrock Guardrails and Automated Reasoning checks), Alice (Launched AI safety and security platform), Netskope (Launched GenAI DLP and Shadow AI visibility), CrowdStrike (Acquired Pangea)</p></li><li><p><strong>Companies acquired in the past year: </strong>Protect AI, Pangea, Lakera, Splx AI, Calypso AI, Prompt Security, AIM Security, Invariantlabs</p></li></ul><blockquote><p><em><a href="https://www.lakera.ai/news/lakera-raises-20m-series-a-to-secure-generative-ai-applications">&#8220;Enterprises now operate in a world where anyone who knows how to talk knows how to hack.&#8221;</a></em></p><p><strong>- David Haber</strong>, Founder and CEO, Lakera</p><p><em><a href="https://www.businesswire.com/news/home/20250408315878/en/Aurascape-Launches-from-Stealth-with-%2450M-in-Funding-and-an-AI-Native-Security-Platform-to-Enable-Businesses-to-Innovate-Fearlessly-in-the-Age-of-AI">&#8220;AI is here to stay, and enterprises must implement strategies to monitor and protect AI use. Traditional security offerings were not designed for the ways AI applications operate.&#8221;</a></em></p><p><strong>- Moinul Khan</strong>, Co-Founder &amp; CEO, Aurascape</p><p><em><a href="https://techcrunch.com/2025/11/17/mcp-ai-agent-security-startup-runlayer-launches-with-8-unicorns-11m-from-khoslas-keith-rabois-and-felicis/">&#8220;Everyone talks about AI, but AI is really only as useful as the tools and the resources it has access to.&#8221;</a></em></p><p><strong>- Andrew Berman</strong>, CEO, Runlayer</p><p><em><a href="https://www.linkedin.com/posts/ericchiu_some-recent-headlines-pose-this-question-share-7381706346477563905-U933?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAGEm9LMBi9xuMrkuI1UkyaY2YUYf14Odq0I">&#8220;Enterprises we&#8217;re working with have 50 to 200 LLM applications today. That number could double, and then quadruple, in just the next few years.&#8221;</a></em></p><p><strong>- Eric Chiu</strong>, CO-Founder and CEO, SolidCore</p></blockquote><h3><strong>Decoupling Data from SIEM: The Security Data Layer</strong></h3><h4><strong>What happened in 2025</strong></h4><p><strong>Security data finally started breaking out of the SIEM jail</strong>: Organisations implemented vendor-agnostic pipelines as a control plane, then pointed them at SIEM, XDR and open lakehouses so detections could run wherever the data actually lives. Procurement stopped buying &#8220;platforms by logo&#8221; and started buying &#8220;signals by dollar,&#8221; with cost per event and cost per investigated alert becoming hard gates in renewals.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-8" href="#footnote-8" target="_self">8</a></p><h4><strong>Vendor signals</strong></h4><p>Vendors promoted bring-your-own-lake ingestion, late-binding schemas, replay on cheap storage and tiered economics. They pushed source-agnostic, federated detections over a shared telemetry fabric, offering cross-product correlation and summarisation that run directly on whatever lake or SIEM holds the data.</p><h4><strong>Security leader signals</strong></h4><p>Platform teams rationalised duplicate ingestion, normalised data ownership and demanded transparent price performance and workload portability.</p><h4><strong>Why it matters</strong></h4><p>Signal density per dollar is increasingly the measure of detection sustainability. <strong>Decoupling storage, compute, and analytics unlocks choice, flexibility and optimization</strong>.</p><h4><strong>KPIs to watch</strong></h4><ul><li><p>Cost per investigated alert and cost per retained terabyte</p></li><li><p>Coverage of priority telemetry sources and replay SLA</p></li></ul><h4><strong>2026 outlook - Motions &amp; Tailwinds</strong></h4><p>&#8220;Query once, detect anywhere&#8221; will solidify into the default pattern: a single detection definition fanning out across SIEM, XDR and lake engines, running as close as possible to where the data already sits. Data retention will be policy-driven and explicitly tied to business risk, with hot, high-value telemetry kept close and expensive, and long-tail data pushed to cheap tiers but still replayable on demand.</p><h4><strong>Key Industry Moves and Company Launches in 2025</strong></h4><ul><li><p><strong>Companies launched in the past year: </strong>Vega, Artemis, Databahn, Cribl, Beacon Security, Sawmills, Ziggiz.</p></li><li><p><strong>Moves by legacy companies (M&amp;A/launches): </strong>Palo Alto Networks (Acquired Chronosphere), Cisco (Launched Cisco Data Fabric), SentinelOne (Acquired Observo AI), CrowdStrike (Acquired Onum), Google (Added Bindplane-powered data processing pipelines)</p></li><li><p><strong>Companies acquired in the past year: </strong>Onum, Observo AI, Datable, Chronosphere</p></li></ul><blockquote><p><em><a href="https://www.databahn.ai/press-releases/databahn-ai-raises-17m-series-a-to-redefine-enterprise-data-pipelines-for-security-observability-and-ai">&#8220;Enterprises aren&#8217;t just overwhelmed by data volume; they&#8217;re being outpaced by its complexity&#8221;</a></em></p><p><strong>- Nanda Santhana</strong>, Co-Founder and CEO, Databahn</p><p><em><a href="https://www.sentinelone.com/press/sentinelone-to-acquire-observo-ai-to-revolutionize-siem-and-security-operations/">&#8220;Security is, at its heart, a data problem, and legacy, rules-based data pipeline platforms simply weren&#8217;t built for today&#8217;s ever-growing attack surface and data-rich security operations.&#8221;</a></em></p><p><strong>- Tomer Weingarten</strong>, Co-Founder and CEO, SentinelOne</p><p><em><a href="https://techcrunch.com/2026/02/10/vega-raises-120m-series-b-to-rethink-how-enterprises-detect-cyber-threats/">&#8220;The current operating model of the SIEM - the dominant technology in this domain for the last two decades - is not only &#8216;crazy expensive, but is also increasingly causing AI-native security operations to fail.&#8221;</a></em></p><p><strong>- Shay Sandler</strong>, Co-Founder and CEO, Vega</p><p><em><a href="https://www.insightpartners.com/ideas/onum-leadership-story/">&#8220;I think we are discussing AI too much and losing the context. AI is changing our lives, but perhaps not yet. We want to show the market that data is the only place where all tools, all attacks, and everything are together.&#8221;</a></em></p><p><strong>- Pedro Castillo</strong>, Co-Founder &amp; former CEO, Onum</p><p><em><a href="https://www.linkedin.com/posts/galhochberg_ive-noticed-a-small-shift-in-how-security-activity-7420231944141144066-kHTu?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAGEm9LMBi9xuMrkuI1UkyaY2YUYf14Odq0I">&#8220;I hear fewer questions about &#8216;what platform should we choose?&#8217; and more about &#8216;how do we manage our data so each tool gets what it needs to do its job well?&#8217;&#8220;</a></em></p><p><strong>- Gal Tal-Hochberg</strong>, Co-Founder &amp; CEO, Beacon Security</p></blockquote><h3><strong>Identity as the New Perimeter Attack Surface: From Users to NHIs &amp; Agents</strong></h3><h4><strong>What happened in 2025</strong></h4><p>Identity became the first perimeter of security across cloud and SaaS - who or what you are mattered more than which network you sat on. Non-human identities exploded - API keys, service accounts, tokens and agents outnumber human users, often with tens of non-human identities per human user, turning poorly kept secrets into one of the steepest, fastest-growing risk curves in the stack.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-9" href="#footnote-9" target="_self">9</a> At the same time, heavy-friction IAM and PAM workflows are still pushing developers to bypass controls, fuelling shadow access and unmanaged NHIs that quietly escaped central governance. Just-in-time and just-enough privilege finally moved from slideware into mainstream programs, as Zero Standing Privileges are slowly becoming the expected pattern for admins, developers and high-risk NHIs.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-10" href="#footnote-10" target="_self">10</a></p><h4><strong>Vendor signals</strong></h4><p>Vendors combined identity threat detection, entitlement visibility and automated access brokering. They enhanced the graph-based context (HR, device, workload) to score access risk.</p><h4><strong>Security leader signals</strong></h4><p>Leaders focused on toxic privilege combinations and orphaned rights that drive blast radius in a breach. Adoption was guided by measurable reductions in excessive entitlements and high-risk access paths.</p><h4><strong>Why it matters</strong></h4><p>When breach impact correlates with privilege sprawl, identity must serve as the perimeter, but only if entitlement right sizing and machine identity lifecycle control are continuous.</p><h4><strong>KPIs to watch</strong></h4><ul><li><p>Reduction in standing admin privileges and high-risk paths</p></li><li><p>Mean time to deprovision machine identities</p></li><li><p>Percentage of access granted via JIT (with time bounds)</p></li></ul><h4><strong>2026 outlook - Motions &amp; Tailwinds</strong></h4><p><strong>Identity is steadily consolidating onto unified platforms that cover workforce, customer, partner, and machine identities across on-prem and cloud, instead of living in separate stacks</strong>. At the same time, IGA and PAM will converge into a single control plane, so the same policies that govern joiners/movers/leavers also drive just-in-time privilege and approvals on production changes. Identity risk scores will plug directly into CI/CD, deployment, and change-control gates, turning &#8220;who is this, and how risky are they?&#8221; into a non-negotiable release criterion.</p><h4><strong>Key Industry Moves and Company Launches in 2025</strong></h4><ul><li><p><strong>Companies evolved in the past year: </strong>Venice, Opti, Fabrix, Orchid Security, Aizome, Silverfort, Linx, Oasis Security, Outtake, Astrix, Abnormal AI, Imper AI, AuthMind, Hush Security, C1 (Formerly ConductorOne), Token Security.</p></li><li><p><strong>Moves by legacy companies (M&amp;A/launches): </strong>Okta (Acquired Axiom), Palo Alto Networks(Acquired CyberArk), Microsoft (Launched Entra Agent ID), CrowdStrike (Launched Falcon Privileged Access), IBM (Acquired HashiCorp), GitGuardian (Launched its NHI Governance product), SailPoint (Launched NHI governance features), Saviynt (Expanded its platform to cover NHI + AI agents)</p></li><li><p><strong>Companies acquired in the past year: </strong>Axiom, CyberArk, Otterize, Zilla, 1Password, Veza, Sgnl, Stack Identity, StrongDM, and HashiCorp.</p></li></ul><blockquote><p><em><a href="https://www.crowdstrike.com/en-us/press-releases/crowdstrike-debuts-falcon-privileged-access-unified-hybrid-identity-security/?utm_source=chatgpt.com">&#8220;Identity is under relentless attack, and adversaries are going straight for the keys to the kingdom - privileged access. From social engineering to sophisticated insider abuse, they&#8217;re escalating privileges to access the most sensitive systems and data.&#8221;</a></em></p><p><strong>- Michael Sentonas</strong>, President, CrowdStrike</p><p><em><a href="https://www.orchid.security/blog/crn-2025-stellar-startup">&#8220;We&#8217;re at a pivotal moment in identity security. The unseen dark matter of identity is overtaking what organizations can manage or even see. It&#8217;s no longer about control - it&#8217;s about context.&#8221;</a></em></p><p><strong>- Roy Katmor</strong>, CEO &amp; Co-Founder, Orchid Security</p><p><em><a href="https://www.calcalistech.com/ctechnews/article/sk5qcux00we">&#8220;For years, companies assumed the root of identity security was making access as convenient as possible. But what has changed is the scale and dynamism of modern environments. Humans can manage things manually, but organizations operating at today&#8217;s speed, especially with AI agents, need systems that can handle constant change.&#8221;</a></em></p><p><strong>- Rotem Lurie</strong>, CEO &amp; Co-Founder, Venice</p></blockquote><h3><strong>AI coding and Application Security</strong></h3><h4><strong>What happened in 2025</strong></h4><p><strong>Application security continued to move upstream, as adversaries increasingly targeted the environments where software is made, not just where it runs</strong>. Developer endpoints, IDEs, CI runners, package ecosystems, and build credentials became the soft underbelly of otherwise well-hardened production stacks. Campaigns like NX<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-11" href="#footnote-11" target="_self">11</a> and Shai Hulud<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-12" href="#footnote-12" target="_self">12</a> reflected a broader shift in adversary strategy: <strong>rather than attacking hardened production systems directly, attackers targeted the systems that created them</strong>.</p><p>In parallel, AI-written code became the default operating mode for many engineering teams, expanding the developer plane. The volume of AI-generated code paths and dependency decisions now outpaces already-stretched security checks. As a result, teams tuned out generic &#8220;AI security&#8221; messaging and demanded auditable evidence at decision time: what was generated, what shaped it, what data it touched, and whether it cleared a defensible ship bar.</p><p><strong>This points to a new generation of AppSec: continuous, context-rich, policy-driven tooling for AI-assisted delivery, with automated provenance and verification across the creation layer.</strong></p><h4><strong>Vendor signals</strong></h4><p>Vendors started bundling developer security into a single story across AppSec, code scanning, secrets scanning, and supply chain controls. Key patterns included:</p><ul><li><p>Security checks earlier in the workflow, inside IDEs and pull requests</p></li><li><p>Guardrails for AI coding, like policy checks, safe prompts, and blocked risky patterns</p></li><li><p>Better visibility into open source and build dependencies, including provenance and signing</p></li><li><p>Contextualised tooling - for posture and remediation alike</p></li><li><p>Detection for repo access abuse, token misuse, and suspicious CI activity</p></li></ul><h4><strong>Security leader signals</strong></h4><p>Security leaders wanted to keep developer velocity high while making AI-driven changes reviewable and enforceable. Priorities included clear ownership and defined scope of AI coding tools used across repos and environments, hard controls on secrets and tokens in repos and CI, mandatory security gates embedded throughout the SDLC, and evidence that AI use does not bypass review, testing, or approval standards.</p><h4><strong>Why it matters</strong></h4><p>If AI can write more code, teams will ship more code. That raises the odds of vulnerabilities, insecure defaults, and dependency risk, unless controls scale with output. <strong>The builder is now part of the perimeter. If developer identities, endpoints, repos, and pipelines are compromised, production will fall downstream</strong>.</p><h4><strong>KPIs to watch</strong></h4><ul><li><p>Mean time to rotate or revoke exposed secrets and tokens found in code or CI logs</p></li><li><p>Percentage of critical repos covered by branch protection, signed commits, and required reviews. Mean time to patch vulnerable dependencies after disclosure</p></li><li><p>Percentage of PRs that pass security gates before merge (and how often gates are bypassed). Rate of high severity findings introduced per release (not just total findings)</p></li></ul><h4><strong>2026 outlook - Motions &amp; Tailwinds</strong></h4><p>AppSec will move from &#8220;scan and report&#8221; to &#8220;gate and verify.&#8221; AI coding will push policy into authoring, building, and merging before code is built and merged -not after the fact. Expect security controls to plug directly into IDEs, PRs, CI/CD, and change management so teams can answer, in real time:</p><ul><li><p>Who wrote or generated this change?</p></li><li><p>What was the source of the code and dependencies?</p></li><li><p>What risk do we accept, and why?</p></li></ul><p>In 2026, the goal is not to stop AI-written code. The goal is to secure the builder. Secure developer identities, endpoints, and secrets, and you reduce downstream production risk.</p><h4><strong>Key Industry Moves and Company Launches in 2025</strong></h4><ul><li><p><strong>Companies evolved in the past year: </strong>Archipelo, Clover Security, Symbiotic, Dam Secure, Echo, Sola Security</p></li><li><p><strong>Moves by legacy companies (M&amp;A/launches): </strong>Checkmarx (Acquired Tromzo), Anthropic (Claude Code Security), Cyera (Acquired Trail Security), Snyk (Rebranded its platform as the &#8220;AI Security Fabric&#8221;), Google (Wiz launched Wiz Code), GitHub (Launched Copilot coding agent with built-in security validation)</p></li><li><p><strong>Companies acquired in the past year: </strong>Tromzo, Mayhem Security, Trag, XEOL, Trail Security, Dazz</p></li></ul><blockquote><p><em><a href="https://www.globenewswire.com/news-release/2025/02/28/3034691/0/en/Archipelo-Emerges-from-Stealth-with-12M-in-Funding-to-Tackle-the-Next-Frontier-in-Cybersecurity-Developer-Security-Posture-Management.html">&#8220;In a world where AI is transforming software development, the biggest security risk isn&#8217;t just in the code - it&#8217;s in how the code is written.&#8221;</a></em></p><p><strong>- Matthew Wise</strong>, Co-Founder and CEO, Archipelo</p><p><em><a href="https://www.linkedin.com/posts/alonkol_excited-to-finally-share-clover-security-activity-7399109137810255872-QTXU?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAGEm9LMBi9xuMrkuI1UkyaY2YUYf14Odq0I">&#8220;The problem is clear: AI has pushed engineering velocity far beyond what reactive security tools were built to handle.&#8221;</a></em></p><p><strong>- Alon Kollmann</strong>, Co-Founder and CEO, Clover Security</p><p><em><a href="https://finance.yahoo.com/news/symbiotic-security-version-1-enables-130000668.html?guccounter=1&amp;guce_referrer=aHR0cHM6Ly9jbGF1ZGUuYWkv&amp;guce_referrer_sig=AQAAAEGkVdJ8GzkzrloVuYWsMUZJ6ciRcvJWbB_F54x7w9eiZB1Bp3LTVySCw2Ugeh6buYxdaW7ggIStNRwcPmfu0kANRYnkP_VfKg1M2DFMoEqvBpABLTf5koLX2UJ4d5ViGaiTLgSS7DYyn9aARP_KKXFMDcNSn8ATqi0MrrreM5ob">&#8220;Making security a positive experience for developers is key to growing their cyber judgement and knowledge. By integrating AI-powered training into their workflow and using their current work as the reference point, developers learn in a way that&#8217;s impactful, helping them better understand and resolve security vulnerabilities without disrupting productivity.&#8221;</a></em></p><p><strong>- Edouard Viot</strong>, CTO and co-founder, Symbiotic</p></blockquote><h2><strong>Newly emerging tailwinds</strong></h2><p>While there were no meaningful public motions to reference in these categories, having seen many teams working in stealth on solutions to these and given the strong technological shift that enables / require them - we make an educated guess that these categories would be prominent in next year&#8217;s report:</p><h3><strong>AI DLP</strong></h3><p>It is the next generation of DLP: instead of relying mostly on fixed rules like &#8220;block credit card numbers&#8221; or &#8220;detect files labeled confidential,&#8221; it uses AI models plus business context to understand what sensitive data is, where it is going, why the user is sending it, and whether the action is risky.</p><h3><strong>Agentic Runtime Security</strong></h3><p>Given the inability to pre-define guardrails for agents, new tools will &#8220;run&#8221; next to agents and logically &amp; contextually make sure they do as intended and reported, stopping them when they don&#8217;t. These dynamic guardrails - which we call in this report (coining a phrase!) &#8220;runners&#8221; - are an inevitable development in cybersecurity.</p><h3><strong>Unified Agentic Defense Platforms (UADPs)</strong></h3><p>As autonomous AI agents scale, the traditional, siloed security stack is beginning to break down. In 2026, we will see the emergence of Unified Agentic Defense Platforms (UADPs): This is a new architecture that converges data security, identity governance, and AI security into a single control plane. Rather than managing DSPM, DLP, AI security, and identity as separate tools. UADPs address the core challenge of the agentic era: governing the intersection of who or what is acting, what data is being accessed, and why the action is occurring. Static security rules will increasingly give way to real-time, behavior-driven defenses that evaluate agent intent and intervene at machine speed. The result will be significant consolidation across the security stack, as standalone tools collapse into a unified platform designed to secure autonomous systems operating across enterprise environments.</p><ul><li><p>Coining a new phrase: &#8220;Runners&#8221; also referred to as Agentic Runtime Security, are a new class of tools designed to provide dynamic security for autonomous AI agents. They operate alongside agents in real-time, functioning as dynamic guardrails. Their purpose is to logically and contextually verify that an agent is operating as intended, auditing all actions for compliance and traceability in realtime, and immediately stopping or containing the agent if its behavior deviates from its designated purpose.</p></li></ul><h2><strong>Cross Cutting Recommendations For CISOs</strong></h2><p>These recommendations reflect lessons from 2025 as AI adoption accelerated across security and engineering environments. As AI capabilities expand, organizations must adopt them in ways that remain measurable, controllable, and auditable. Risk is reduced when clear operational boundaries are defined, when the full lifecycle from development through production is hardened, and when real incidents are systematically converted into stronger preventive controls. Sustained executive support depends on translating resilience into business-relevant outcomes that leadership can track and fund.</p><h3><strong>DON&#8217;T: </strong></h3><ul><li><p><strong>Roll out AI everywhere all at once:</strong> Start with a narrow, high-frequency security use case where outcomes are measurable, and the blast radius is controlled (e.g., phishing triage, alert summarization, investigation drafts). Running AI in a contained domain allows teams to validate reliability, measure productivity gains, and understand operational risks before expanding its role. Once the system consistently improves triage speed, investigation quality, or analyst workload, the scope can gradually expand to additional workflows with higher operational impact.</p></li><li><p><strong>Collect security data you can&#8217;t afford to investigate:</strong> Don&#8217;t treat telemetry ingestion as a free resource. Uncontrolled data pipelines create noise and drive up cost without improving detection quality. Instead, treat each telemetry source as a measurable investment: track the ingestion, storage, and compute costs alongside the detections and investigations it enables.</p></li><li><p><strong>Ignore non-human identities:</strong> Don&#8217;t assume API tokens, service accounts, and machine identities are low-risk or temporary. In modern cloud and SaaS environments, these identities often hold persistent privileges and can create powerful attack paths if left unmanaged. CISOs should ensure that non-human identities are governed with the same rigor as human credentials, including automated discovery, rotation policies, and lifecycle controls across the SaaS and API ecosystem.</p></li><li><p><strong>Try to fight Shadow AI:</strong> Employees will adopt AI tools whether security teams approve them or not. Instead of attempting to block usage entirely, CISOs should focus on discovering, monitoring, and governing AI adoption before it evolves into unmanaged risk.</p></li></ul><h3><strong>DO: </strong></h3><ul><li><p><strong>Build guardrails before you build autonomy:</strong> Require guardrails across the entire AI lifecycle, from development to production, including strict data policies, versioned prompts and tools, approval workflows for sensitive actions, and full logging of AI decisions and evidence. AI systems operating in security environments must function under controlled autonomy, where their behavior can be audited, explained, and constrained.</p></li><li><p><strong>Make identity risk visible where work happens:</strong> Ensure that identity risk is visible inside the operational environments where access decisions are actually made, not only within security dashboards. Instead of relying solely on centralized IAM or governance tools, make sure there is an integration of identity risk signals into developer and platform workflows. This allows engineers and platform teams to see the security implications of privileges, tokens, and access paths at the moment they create or modify them.</p></li><li><p><strong>Quantify cyber resilience in business terms:</strong> Translate cyber resilience into clear, measurable outcomes that leadership and the board can understand and track over time. While no universally accepted KPI exists for resilience, CISOs should prioritize indicators that demonstrate tangible improvements in operational performance and risk reduction. The specific metric matters less than its transparency, repeatability, and connection to business impact. Frame progress through trend lines and measurable changes in exposure, rather than relying solely on abstract technical metrics.</p></li></ul><h2><strong>Conclusion</strong></h2><p><strong>Security improvements did not come from adding more tools this year, it came from making them work together</strong>. The programs that improved fastest were those that connected signals, shared context across controls, and enabled teams to act quickly on what they saw.</p><p>AI did not change that principle. It accelerated everything - attacker experimentation, alert volume, and response timelines - but the difference between strong programs and weak ones remained coordination. Systems that share context and support decisive action outperform stacks that simply accumulate tools and signals. With the goal being to reduce time between risk appearing and controls taking effect, faster detection and containment, quicker restoration of services, and a smaller exposure window for revenue-critical systems became both the method, and the metric.</p><p><em><strong>Please note: All information herein is provided for general informational purposes only, may be subjective, and is based on sources believed to be reliable. No representation or warranty, express or implied, is made as to its accuracy or completeness. The information herein may be incomplete, outdated, or subject to change without notice. Nothing contained herein constitutes professional, legal, or investment advice, and it should not be relied upon for any decision-making or other purpose. Disclosure: Some of the companies mentioned in this report are Deutsch&amp;Co - Portfolio Companies.</strong></em></p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Software Analyst Cyber Research! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/p/cybermadness-motion-and-tailwinds/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/p/cybermadness-motion-and-tailwinds/comments"><span>Leave a comment</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&quot;,&quot;text&quot;:&quot;Share Software Analyst Cyber Research&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share Software Analyst Cyber Research</span></a></p><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p><em><strong>Shadow AI</strong> is the unauthorized or unsanctioned use of AI tools within an organization without formal oversight from IT or security teams.</em></p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-2" href="#footnote-anchor-2" class="footnote-number" contenteditable="false" target="_self">2</a><div class="footnote-content"><p><em>A 2025 <a href="https://www.cybersecuritydive.com/news/jaguar-land-rover-attack-british-economy-25-billion/803491/?utm_source=chatgpt.com">cyberattack</a> that forced Jaguar Land Rover to halt production for several weeks, disrupting global supply chains and causing an estimated <strong>$2.5B economic impact</strong>.</em></p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-3" href="#footnote-anchor-3" class="footnote-number" contenteditable="false" target="_self">3</a><div class="footnote-content"><p><em>A Cyberattack in which attackers hijack <strong>SaaS accounts or cloud applications</strong> through stolen credentials, tokens, or misconfigured integrations, allowing persistent access to organizational system.</em></p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-4" href="#footnote-anchor-4" class="footnote-number" contenteditable="false" target="_self">4</a><div class="footnote-content"><p><em>The cyber-espionage <a href="https://www.cybersecuritydive.com/news/salt-typhoon-telecom-hacks-one-of-the-most-consequential-campaigns-against/746870/?utm_source">campaign</a> linked to the <strong>Chinese state-backed group &#8220;Salt Typhoon&#8221;</strong>.</em></p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-5" href="#footnote-anchor-5" class="footnote-number" contenteditable="false" target="_self">5</a><div class="footnote-content"><p><em>Recent SOC studies show AI assistance reducing investigation time and increasing Tier&#8209;1 accuracy when embedded directly in analyst workflows. See: <a href="https://omdia.tech.informa.com/blogs/2025/nov/the-agentic-soc-secops-evolution-into-agentic-platforms">The agentic SOC: SecOps evolution into agentic platforms</a>, Omdia Tech, 2025.</em></p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-6" href="#footnote-anchor-6" class="footnote-number" contenteditable="false" target="_self">6</a><div class="footnote-content"><p><em>AI regulations (<a href="https://artificialintelligenceact.eu/article/14/">EU</a> AI Act; <a href="https://www.nist.gov/itl/ai-risk-management-framework">NIST</a> AI RMF) that require meaningful human oversight for high-impact AI decisions.</em></p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-7" href="#footnote-anchor-7" class="footnote-number" contenteditable="false" target="_self">7</a><div class="footnote-content"><p><em>Research on agentic security systems stresses that even a small increase in missed true attacks can outweigh large productivity gains. See: <a href="https://arxiv.org/abs/2508.18947">LLMs in the SOC: An Empirical Study of Human-AI Collaboration in Security Operations Centres</a>, 2025.</em></p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-8" href="#footnote-anchor-8" class="footnote-number" contenteditable="false" target="_self">8</a><div class="footnote-content"><p><em>Analysts note a shift toward cost-per-event and cost-per-investigation economies in modern cloud and security programs. See: <a href="https://www.returnonsecurity.com/p/the-state-of-the-cybersecurity-market-in-2024">2024 State of the Cybersecurity Market: $14B, Key Trends &amp; Data</a>. Returnonsecurity, 2025.</em></p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-9" href="#footnote-anchor-9" class="footnote-number" contenteditable="false" target="_self">9</a><div class="footnote-content"><p><em>See: <a href="https://www.infosecurity-magazine.com/news/machine-identities-outnumber/">Machine Identities Outnumber Humans Increasing Risk Seven-Fold</a>, infosecurity magazine, 2025.</em></p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-10" href="#footnote-anchor-10" class="footnote-number" contenteditable="false" target="_self">10</a><div class="footnote-content"><p><em>Consulting guidance Increasingly treats just-in-time access and zero standing privileges as the default for admins and high-risk workloads. See: <a href="https://www.deloitte.com/us/en/insights/topics/technology-management/tech-trends/2026/agentic-ai-strategy.html">The agentic reality check: Preparing for a silicon-based workforce</a>. Deloitte Insights, 2025.</em></p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-11" href="#footnote-anchor-11" class="footnote-number" contenteditable="false" target="_self">11</a><div class="footnote-content"><p><em>A supply chain <a href="https://www.kaspersky.co.uk/blog/nx-build-s1ngularity-supply-chain-attack/29435/?utm_source=chatgpt.com">attack</a> (August 2025) in which attackers hijacked the NX build platform, a developer tool with 5M+ weekly downloads, to steal developer credentials, tokens, and keys at scale.</em></p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-12" href="#footnote-anchor-12" class="footnote-number" contenteditable="false" target="_self">12</a><div class="footnote-content"><p><em>A self-replicating npm supply chain <a href="https://www.cisa.gov/news-events/alerts/2025/09/23/widespread-supply-chain-compromise-impacting-npm-ecosystem">worm</a> that compromised 500 packages</em></p></div></div>]]></content:encoded></item><item><title><![CDATA[The Great DLP Reset: Securing Data in the Age of SaaS, Cloud, and AI]]></title><description><![CDATA[DLP is being rebuilt for new runtimes in SaaS, cloud data, AI and agentic workflows.]]></description><link>https://softwareanalyst.substack.com/p/the-great-dlp-reset-securing-data</link><guid isPermaLink="false">https://softwareanalyst.substack.com/p/the-great-dlp-reset-securing-data</guid><dc:creator><![CDATA[SACR]]></dc:creator><pubDate>Thu, 23 Apr 2026 17:54:02 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!K5Li!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff4d9f8a-0402-4f43-8d42-38a440d1849f_1920x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h1><strong>Executive Summary</strong></h1><div><hr></div><p><strong>Data Loss Prevention (DLP) is undergoing a structural reset. </strong></p><p>What was once a fragmented set of point controls anchored to endpoints, networks, and email gateways is being rebuilt into a unified, discovery-led data control plane designed for a world where data no longer sits still, users no longer operate within defined perimeters, and AI systems now participate in how data is created, transformed, and exfiltrated.</p><p>The legacy DLP model is breaking, not because detection has failed, but because the underlying assumptions no longer hold. Traditional DLP relied on stable data patterns, centralized enforcement points, and human-driven tuning. Modern environments defined by SaaS sprawl, cloud data gravity, and GenAI workflows have invalidated each of these assumptions.  </p><p>Our report argues that the next era of DLP will not be defined by better pattern matching or broader coverage, but by a fundamental architectural shift. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!K5Li!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff4d9f8a-0402-4f43-8d42-38a440d1849f_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!K5Li!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff4d9f8a-0402-4f43-8d42-38a440d1849f_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!K5Li!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff4d9f8a-0402-4f43-8d42-38a440d1849f_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!K5Li!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff4d9f8a-0402-4f43-8d42-38a440d1849f_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!K5Li!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff4d9f8a-0402-4f43-8d42-38a440d1849f_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!K5Li!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff4d9f8a-0402-4f43-8d42-38a440d1849f_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ff4d9f8a-0402-4f43-8d42-38a440d1849f_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1380646,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://softwareanalyst.substack.com/i/194969072?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff4d9f8a-0402-4f43-8d42-38a440d1849f_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!K5Li!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff4d9f8a-0402-4f43-8d42-38a440d1849f_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!K5Li!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff4d9f8a-0402-4f43-8d42-38a440d1849f_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!K5Li!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff4d9f8a-0402-4f43-8d42-38a440d1849f_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!K5Li!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff4d9f8a-0402-4f43-8d42-38a440d1849f_1920x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><ol><li><p><strong>Our thesis for this research is that Data Loss Prevention (DLP)</strong> is being rebuilt into a discovery-led control plane for modern runtimes (SaaS, cloud data, and AI/agent workflows). Traditional Enterprise DLP, Integrated DLP, and Cloud-Native DLP categories are an insufficient way of delineating DLP at the program level. A DLP reset is needed. In the DLP reset, the winners are not the platforms that generate the most alerts, but those that reduce operational burden while delivering measurable risk reduction through automated remediation, real-time prevention where feasible, and audit-grade evidence (and lineage where possible).</p></li><li><p><strong>DLP is being rebuilt into a discovery-led control plane:</strong> This includes continuous classification, which becomes the truth layer where identity/entitlements provide decision context, and enforcement shifts from a few chokepoints to a set of distributed enforcement planes (SaaS APIs, inline SSE/SASE/GW, browser/session, endpoint, and AI prompt/agent surfaces).</p></li><li><p><strong>The Winners:</strong> The winners won&#8217;t be the platforms that generate the most alerts. Rather, they&#8217;ll be the ones that measurably reduce risk, improve visibility and control of data with AI and agents and offer lower operational burden, automated remediation, and audit-grade evidence.</p><p></p></li></ol><h2><strong>Key Insights On How DLP Is Changing </strong></h2><p>DLP is undergoing a reset and moving from deterministic, enforcement-point-centric controls to a discovery-led data control plane model that combines continuous classification, identity, context, data labeling, and automated remediation across SaaS, cloud data, endpoints, browsers, user driven and agentic AI workflows. AI adoption has reached 73% of enterprises in 2026, while real time security governance is just beginning to emerge at 7%. Browsers are emerging as a key defense mechanism for AI and Data loss as users spend  ~75% of their work day either working in a web browser or attending virtual meetings.</p><p>Based on discussions with SACR clients, briefings by vendors, emerging vendors, and public information:</p><ul><li><p>The center of gravity is shifting toward faster time-to-first-signal (TTFS), faster time to prevention and much more focused on lower tuning burden to avoid false positives, and improve classification.</p></li><li><p>API, SaaS-first and DSPM-led control planes generally offer lower burden, while classic endpoints and network suites remain high-burden even when their breadth is strong.</p></li><li><p>Inline SSE and SASE DLP (e.g., Prisma Access, Netskope, Zscaler, etc) remains a high-value path for broad enforcement, but it carries structural burden, for example requiring traffic steering or custom reverse proxying, policy pattern and profile management, and dependency on traffic flowing through enforcement points.</p></li><li><p>M365-native DLP (for example Microsoft Purview) can deliver high value quickly inside Microsoft environments, but the operational tax includes activities such as endpoint onboarding, policy complexity, and false positive or custom data classification tuning which remains non-trivial.</p></li><li><p>Expanding Agentic Platforms and AI interaction and enforcement points is complicating the future of DLP especially for emerging agentic platforms and their workflows.</p></li></ul><div><hr></div><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Software Analyst Cyber Research! Subscribe for free to receive new cybersecurity reports and analys</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><div><hr></div><h2><strong>Actionable Summary</strong></h2><ul><li><p><strong>Establish a truth layer for the data security program (discovery/classification):</strong>&nbsp;If you cannot answer where sensitive data is and who can access it, enforcement will be noisy and politically hard to sustain and preventive remediation efforts will not be easily achievable.</p></li><li><p><strong>Add in essential context (identity, entitlements, sharing posture):</strong> Combine a truth layer (DSPM and discovery) with context (identity and entitlements) to inform enforcement and direct remediation efforts or automations (for example data owner guidance or automated approvals).</p></li><li><p><strong>Choose enforcement points intentionally (SaaS API first where possible; inline and endpoints where justified):</strong> Utilize a targeted enforcement point layer (for example, by using SaaS APIs, Inline SSE/SASE/GW where needed, and focus on endpoints only where necessary - e.g. users leveraging traditional protocols and data sharing infrastructures like SMB/SAMBA Drive Shares or sync-share file solutions).</p></li><li><p><strong>Operationalize GenAI runtime controls, ideally using browser controls (prompt/session + agent tool-call logging):</strong> Define controls for users for example prompt pasting, Copilot access scope, and agent tool-call auditing and logging and don&#8217;t assume classic DLP policies will translate to the new emerging areas.</p></li><li><p><strong>Measure data loss prevention outcomes (automation, risk reduction and adequate evidence):</strong> The reset winners are those that can revoke sharing, redact, delete or even mask and encrypt content in SaaS, and produce evidence trails with less analyst labour and without increasing burden or creating a ticket factory outcome for your human participants.</p></li><li><p><strong>Focus on Audit-grade evidence and end-to-end data lineage (what counts):</strong> The key components are the event logs, the actors involved, the object impacted, the action taken, the precise timestamp, data lineage trace and proof of the remediation if applied.</p></li></ul><div><hr></div><p></p><h1>Introduction, Market and Industry Context</h1><h1><strong>The Great DLP Reset</strong></h1><p>The Great DLP Reset signifies a major transformation in architecture, detailing several essential shifts in how data security initiatives must evaluate DLP tools. This movement is steering the development of new vendor strategies to resolve longstanding challenges within data loss prevention programs. DLP is transitioning from conventional, static perimeter security toward a discovery-driven data control plane, tailored for the rapid pace of Cloud, SaaS, AI, and autonomous agent interactions.</p><h1>Market Definition: Modern DLP</h1><p>Modern DLP (as used in this report) is defined as solutions that, when combined, deliver a set of capabilities that: </p><p>Data Loss Prevention (DLP) is a security strategy and set of technologies designed to detect, monitor, and safeguard sensitive information from unauthorized access, accidental exposure, or malicious exfiltration. It governs sensitive data at rest, in motion, and in use across endpoints, networks, and cloud services. This definition intentionally expands beyond content inspection at fixed enforcement points and reflects the market&#8217;s convergence with DSPM, SaaS security and governance, browser security, and AI governance. </p><h3><strong>Definitional Technology, Feature(s), and Service Lines</strong></h3><p>DLP tools perform automated data discovery and classification with deep content inspection, and contextual policy enforcement (block, quarantine, encrypt) focused on the enforcement of real-time data prevention on real-time user interactions. Integrations commonly include CASB/SSE/SASE, network gateways and endpoint agents to govern data flows. Emerging patterns include browser extensions and agentic platforms with limited data control and visibility. Modern DLP tools prevent sensitive data exfiltration across endpoints, SaaS, web/email, and cloud via classification and policy enforcement. </p><p><em><strong>Exclusion criteria: Vendors that deliver products and services of AI prompt inspection and API based application proxies</strong> that focus primarily on prompt threat inspection and context (these solutions are more focused on agentic and workflows: See <a href="https://softwareanalyst.substack.com/p/the-convergence-of-ai-and-data-security">Unified Agentic Defence Platforms (UADP</a>).</em></p><h2><strong>What It Is This Reset In DLP?</strong></h2><p>The architecture of the DLP reset defines a new truth layer combined with context and distributed, establishes continuous discovery and classification to determine what the data is and where it is, and reinforcement that includes remediation and substantive evidence.</p><ul><li><p><strong>Truth Layer:</strong> Edes across premises, SaaS, cloud, AI services and endpoints.</p></li><li><p><strong>Context:</strong> Integrates identity, entitlements, sharing posture, and behavioral analytics to provide decision intelligence and reduce false positives.</p></li><li><p><strong>Distributed Enforcement:</strong> Shifts control from fixed chokepoints to multiple planes including SaaS APIs, inline SSE/SASE/GW, browser sessions, and AI prompt surfaces.</p></li><li><p><strong>Remediation:</strong> Emphasizes automated actions such as revoking links, redacting sensitive data fragments, engaging data owners through autonomous workflows and chat applications (Slack/Teams) and can perform quarantining of assets at machine speed.</p></li><li><p><strong>Evidence:</strong> Produces audit-grade logs and data lineage traces that provide proof of remediation and a forensic chain of custody for investigations in the case of an intentional data exfiltration by a user.</p></li></ul><h2><strong>What it Isn&#8217;t</strong></h2><p>Rather than a traditional solution defined by pervasive regex, the DLP reset moves away from models that necessitate constant manual adjustment and result in a ticket factory style SOC environment. Such legacy approaches impose a heavy operational burden on personnel at every stage, from policy refinement and alert triage to the execution of enforcement actions.</p><ul><li><p><strong>Regex Everywhere:</strong> Traditional DLP relies on deterministic pattern matching and static signatures (e.g., RegEx for Social Security Numbers) which fail to understand content depth or context in modern, unstructured data flows.</p></li><li><p><strong>Manual Tuning:</strong> Legacy systems require constant human intervention to manage exception sprawl and adjust rules for stable data schemas that no longer exist in ephemeral cloud workloads.</p></li><li><p><strong>Ticket Factory:</strong> Without identity or behavioral context, classic tools generate massive volumes of false positives, turning security operations into ticket factories focused on bulk-closing alerts rather than active risk mitigation.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!47V1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78f11e30-b6df-4657-a28d-0ad90c1ccc62_1600x900.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!47V1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78f11e30-b6df-4657-a28d-0ad90c1ccc62_1600x900.jpeg 424w, https://substackcdn.com/image/fetch/$s_!47V1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78f11e30-b6df-4657-a28d-0ad90c1ccc62_1600x900.jpeg 848w, https://substackcdn.com/image/fetch/$s_!47V1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78f11e30-b6df-4657-a28d-0ad90c1ccc62_1600x900.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!47V1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78f11e30-b6df-4657-a28d-0ad90c1ccc62_1600x900.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!47V1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78f11e30-b6df-4657-a28d-0ad90c1ccc62_1600x900.jpeg" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/78f11e30-b6df-4657-a28d-0ad90c1ccc62_1600x900.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!47V1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78f11e30-b6df-4657-a28d-0ad90c1ccc62_1600x900.jpeg 424w, https://substackcdn.com/image/fetch/$s_!47V1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78f11e30-b6df-4657-a28d-0ad90c1ccc62_1600x900.jpeg 848w, https://substackcdn.com/image/fetch/$s_!47V1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78f11e30-b6df-4657-a28d-0ad90c1ccc62_1600x900.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!47V1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78f11e30-b6df-4657-a28d-0ad90c1ccc62_1600x900.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1>The DLP Control Plane (Discovery and labelling-led)</h1><p>Modern DLP is best understood as a control-plane model which includes decisioning and orchestration that drives actions across multiple enforcement planes. It breaks the regex everywhere plus manual tuning era and ticket factory pattern by separating the intelligence plane that determines what matters, from the enforcement planes that execute data security control. Put simply, data discovery, a core aspect of DSPM technology, DSPM is great at discovery and classification of data, determining location and various use cases, the DSPM tools and the data they discover and classify helps inform enforcement points, placement of key inspection and control layer functions across an enterprise, its users and any AI agents it is operating. It can be used to fine tune data loss programs for actual data loss prevention, vs only being used like they are in most DLP programs, as data monitoring solutions, or focused on limited data classifications such as PII or well known structured data types.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!icrO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bc90395-bb10-469c-ab4d-318efc6380f6_1600x900.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!icrO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bc90395-bb10-469c-ab4d-318efc6380f6_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!icrO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bc90395-bb10-469c-ab4d-318efc6380f6_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!icrO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bc90395-bb10-469c-ab4d-318efc6380f6_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!icrO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bc90395-bb10-469c-ab4d-318efc6380f6_1600x900.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!icrO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bc90395-bb10-469c-ab4d-318efc6380f6_1600x900.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4bc90395-bb10-469c-ab4d-318efc6380f6_1600x900.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!icrO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bc90395-bb10-469c-ab4d-318efc6380f6_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!icrO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bc90395-bb10-469c-ab4d-318efc6380f6_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!icrO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bc90395-bb10-469c-ab4d-318efc6380f6_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!icrO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bc90395-bb10-469c-ab4d-318efc6380f6_1600x900.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>The Intelligence Plane (truth, context and orchestration)</h2><p>Modern DLP Control plane architecture is fundamentally sub-divided into two major components: <strong>the Intelligence Plane and the Enforcement Plane</strong>. This structural division acts as the core machinery of the reset, effectively separating the centralized intelligence required to determine data significance from the distributed planes required to execute precise controls.</p><ul><li><p><strong>Truth layer (continuous discovery and classification):</strong> Establishes what the data is, where it lives, and how it is moving.  Where vendors offering Data Security Posture Management (DSPM),  handle data discovery across premise and cloud, properly classify and label, and synchronize data sensitivity labeling across Microsoft (Purview/MIP) and Google Workspaces. These labels serve as critical truth layer context for the enforcement planes.</p></li><li><p><strong>Context layer (identity, entitlements, sharing posture and behavior):</strong> Determine who can access it, how it&#8217;s exposed, and what the risk scenario is to apply the best controls to match the scenario.</p></li><li><p><strong>Decisioning and prioritization:</strong> Reduces noise by ranking what is materially risky (not merely what matches a simple pattern), augmented with AI and LLM content analysis and labeling.</p></li><li><p><strong>Automation and orchestration:</strong> Translates policy intent into repeatable orchestrated actions (for example warn, block, redact, revoke sharing, quarantine, label, encrypt) ideally with guardrails, contextual policy control and rollback capabilities.</p></li><li><p><strong>Evidence and auditability:</strong> Produces investigation-ready data lineage and timelines with actor, object, action, timestamp, and remediation proof (plus end to end data lineage where possible).</p></li></ul><h2>The Enforcement Plane (aka distributed control points)</h2><p>The Enforcement Plane represents the distributed control points where security policies are actively applied to data across various environments. These planes are responsible for executing specific actions, such as blocking, redacting, or quarantining, at the precise moment a violation occurs, moving beyond simple detection to active data risk mitigation. By shifting enforcement from a few centralized chokepoints to distributed surfaces like SaaS services, APIs, inline SSE/SASE/GW, and the enterprise browser, organizations can achieve more precise control over modern data movement and usage patterns. SACR believes that enterprises must look at their data security architecture through this lens to achieve better data loss prevention outcomes.</p><p>The <strong>Enforcement Plane</strong> includes:</p><ul><li><p><strong>SaaS/API enforcement:</strong> Out-of-band controls and remediation inside collaboration and business apps and in AI workflows and agentic platforms.</p></li><li><p><strong>Inline SSE/SASE/GW enforcement:</strong> Real-time inspection/control for web and SaaS traffic where steering and SSL/TLS decryption is justified.</p></li><li><p><strong>Browser and session enforcement (last-mile runtime):</strong> In-session controls over the dominant leakage verbs (copy/paste, upload/download, printing, screen capture), including browser based GenAI interactions.</p></li><li><p><strong>Endpoint enforcement:</strong> Device-level controls for local exfil paths (USB, local copies, unmanaged sync, print, clipboard, screen capture), especially for regulated or high-risk endpoints and end user workspaces.</p></li></ul><h3><strong>Emerging Problems in Data Security and Data Loss Prevention</strong></h3><p>Classic DLP approaches struggle because they assume clear architectural or isolated choke-points, stable data schemas and patterns, and that there are human resources available for manageable tuning and remediation. Modern environments violate those assumptions dramatically, leading to failed deployments and fragmented enforcement with no clear unification of policy.</p><p>Organizations are facing a modern data exposure problem characterized by:</p><ul><li><p>SaaS sprawl and collaboration-first workflows for example sensitive data moves through Slack, Microsoft Teams, Google Drive, One Drive, Microsoft GitHub or various SaaS applications like Salesforce, marketplaces and similar SaaS surfaces.</p></li><li><p>Cloud data gravity has shifted towards sensitive data in warehouses, data lakes and object stores with complex access paths and various data sharing integrations (even between SaaS applications).</p></li><li><p>User controlled GenAI chat applications and agentic workflows, prompt-based exposures, copilots with broad reach and data moving data between data stores, file systems, applications or other AI agents and users.</p></li><li><p>Expanding SaaS-based agentic platform services and no-code providers (Salesforce Agents, Claude Cowork, OpenClaw hosting, Eigent(open source), Zapier, Airtable etc)</p></li></ul><h1><strong>Modern DLP Reset Storyline: Market Phases</strong></h1><h2><strong>Why Classic DLP Became High-Burden</strong></h2><p>Classic Data Loss Prevention (DLP) approaches have become a high-burden due to several core problems that fundamentally require a reset. These issues include a significant operational tax from noise and tuning burden caused by high false-positive rates and exception and enforcement gap sprawl. Classic DLP suffers from weak visibility into where sensitive data exists and which users have the entitlement(s) to reach it. Often various DLP tools were deployed in silo&#8217;s and not properly configured to unify enforcement or consistent policies and utilized various editions of data labeling and classification techniques. Architecturally, it has a poor fit for modern environments characterized by SaaS-native sharing and API-driven data movement that bypass intermediary choke points. Classic DLP is proving to be even a weaker fit for AI usage, struggling to govern probabilistic AI workflows, prompt-based exposures, and agentic tool calls.</p><p>While these foundational mechanics still have a place for performance-heavy compliance tasks, they are insufficient for modern runtimes and emerging architectures which are requiring greater granularity and data-in-use understanding. This legacy framework was effective only as long as the enterprise controlled the infrastructure, the network, application deployment architectures and the devices. However, the shift toward Software-as-a-Service (SaaS), Cloud-native infrastructures, and now Artificial Intelligence (AI) has fundamentally disrupted this paradigm.</p><h3><strong>The Core Problems and Operational Tax</strong></h3><ul><li><p><strong>Noise and Tuning Burden:</strong> High false-positive rates and exception sprawl leading to DLP-as-a-ticket-factory style outcomes, overwhelming data security teams and causing alert fatigue for security operations.</p></li><li><p><strong>Weak Visibility and Graph Visualizations for Analysis:</strong> Traditional tools lacked insight into what sensitive data exists at rest and who has the entitlement to reach it across fragmented environments. They lacked significant visualizations and graph databases to properly articulate vast interconnected data flows between various entities and connect it with data in-use visualizations.</p></li><li><p><strong>Architectural Fragility:</strong> Dependence on network interception makes steering traffic and rearchitecting for DLP fragile and politically difficult as data moved directly between SaaS apps via APIs (for example N8N and Zapier style no-code and workflow automation tooling).</p></li><li><p><strong>Weak AI Fit:</strong> Static rules cannot govern emerging probabilistic AI workflows, prompt-based exposures, or agentic tool calls and need additional enhancements to deliver that functionality through integrated APIs.</p></li></ul><h1><strong>Market Shift Timeline: Data Loss Prevention Challenges 2000s-Present</strong></h1><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tRec!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb3e6055-a8fb-4a70-9d42-b8171f41bae8_1600x900.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tRec!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb3e6055-a8fb-4a70-9d42-b8171f41bae8_1600x900.jpeg 424w, https://substackcdn.com/image/fetch/$s_!tRec!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb3e6055-a8fb-4a70-9d42-b8171f41bae8_1600x900.jpeg 848w, https://substackcdn.com/image/fetch/$s_!tRec!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb3e6055-a8fb-4a70-9d42-b8171f41bae8_1600x900.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!tRec!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb3e6055-a8fb-4a70-9d42-b8171f41bae8_1600x900.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tRec!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb3e6055-a8fb-4a70-9d42-b8171f41bae8_1600x900.jpeg" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/eb3e6055-a8fb-4a70-9d42-b8171f41bae8_1600x900.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tRec!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb3e6055-a8fb-4a70-9d42-b8171f41bae8_1600x900.jpeg 424w, https://substackcdn.com/image/fetch/$s_!tRec!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb3e6055-a8fb-4a70-9d42-b8171f41bae8_1600x900.jpeg 848w, https://substackcdn.com/image/fetch/$s_!tRec!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb3e6055-a8fb-4a70-9d42-b8171f41bae8_1600x900.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!tRec!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb3e6055-a8fb-4a70-9d42-b8171f41bae8_1600x900.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>Late 2000s to early 2010s: DLP becomes a Mainstream Enterprise Control</strong></h3><ul><li><p><strong>High policy authoring and tuning burden</strong> (regex, Exact data matching/hashing (EDM), fingerprinting) and large operational overhead</p></li><li><p><strong>High false positives without strong context</strong>, leading to alert fatigue and DLP-as-a-ticket-factory</p></li><li><p><strong>Cultural and adoption friction:</strong> DLP often perceived as blocking business productivity without clear outcomes</p></li></ul><h3><strong>Mid 2010s: Cloud migration begins to erode chokepoints</strong></h3><ul><li><p><strong>Architectural dependency</strong> on interception of network traffic, steering became fragile and politically difficult.</p></li><li><p><strong>Visibility gaps for data-at-rest across hybrid</strong> environments and in SaaS and cloud storage (not just data-in-motion).</p></li><li><p><strong>Identity use and entitlements</strong> started to dominate outcomes, but classic DLP has weak native entitlement context and is mostly limited in scope to traditional endpoint or network traffic choke-points, file and data storage systems and sharing protocols.</p></li></ul><h3><strong>Late 2010s to early 2020s: SaaS sprawl and collaboration-first work explode the policy burden</strong></h3><ul><li><p><strong>Proliferation of enforcement</strong> surfaces (too many places to write and maintain consistent policies)</p></li><li><p><strong>Weak evidence and investigation context</strong> (who shared what, with whom, and why)</p></li><li><p><strong>Remediation becomes workflow-heavy</strong> (revoking shares, cleaning repos, fixing permissions) and doesn&#8217;t scale well via manual tickets</p></li></ul><h3><strong>Early to mid 2020s: DSPM and discovery-led approaches reshape expectations</strong></h3><ul><li><p><strong>Classification Accuracy limitations:</strong> Classification accuracy and explainability at scale (trust becomes the gating factor) for adoption to be viable.</p></li><li><p><strong>Shadow SaaS (also called Shadow IT) and SaaS data Sprawl:</strong> Connector and data sprawl and integration reality (coverage of data in storage and motion becomes dependent on APIs, audit logs, and action depth) often requiring knowledge of SaaS adoption to integrate DLP functions.</p></li><li><p><strong>Control-plane complexity:</strong> Orchestrating consistent actions across heterogeneous tools without breaking business workflows meant that end to end visibility and discovery challenges became rampant.</p></li><li><p><strong>Centers of gravity emerge for data classification labeling:</strong> Microsoft Information Protection/Purview, Google Workspace become centers of gravity for key data labeling hierarchies, enabling greater federation of enforcement across the enforcement layers</p></li></ul><h3><strong>2023 to present: GenAI and agentic workflows create a new DLP runtime</strong></h3><ul><li><p><strong>Governance:</strong> Governance of non-file data flows (prompts, outputs, tool calls) where content inspection at gateways is insufficient.</p></li><li><p><strong>New UX and policy questions:</strong> Warn user vs block or data redaction require deep user and use case understanding, and what constitutes sensitive in a prompt context is required for proper enforcement and policies.</p></li><li><p><strong>Evidence and audit requirements:</strong> Logging agent actions and maintaining chain-of-custody for investigations and having a forensically sound chain of custody and data lineage become a new requirement.</p></li><li><p><strong>Model and AI agent uncertainty:</strong> Controlling stochastic systems and verifying efficacy claims in production become very challenging and introduce uncertainty.</p></li></ul><div><hr></div><p></p><h1>The Great Reset: Why DLP is Back</h1><p>We think DLP programs need to reframe their deployment architectures around our new framework. Today, DLP deployments span a variety of enforcement plane capabilities and fragmented abilities to control data (also called actions), some using older or more basic methods of data identification, classification and enforcement. Meanwhile, more modern classification tooling such as that of machine learning, semantic classifiers and the broader variety of data security actions can be embedded across enforcement points in a more unified manner. The old frameworks were moderately effective because the enterprise controlled the infrastructure, the network, the communication channels, and the computing devices that made data residency and transit patterns static and manageable.</p><p>Though the basics of traditional DLP still have a place in modern DLP systems (for example using Exact data match or regular expressions, for delivering higher performance or speed), they are not the capabilities that offer the best detection accuracy, classification depth and deep semantic understanding of content and context that is needed for future data loss prevention, especially agentics. Today&#8217;s disparately deployed DLP solutions also need a better grounding in truth, a new defining truth-layer to align various enforcement points and their policies. Modern DLP implementations are plagued by severe architectural instability and have various nuanced limitations. Security departments are frequently trapped in a cycle of managing inconsistent, siloed controls that span across endpoints, network gateways, collaboration platforms, and browser environments. This disconnected approach necessitates a comprehensive structural overhaul, shifting toward a unified control plane anchored by a discovery-driven data strategy. Failure to implement this transition prevents organizations from maintaining uniform policy enforcement across the decentralized points needed to regulate real-time data interactions by modern users and emerging AI agents.</p><h3><strong>Emergence of the Ticket Factory Overload</strong></h3><p>In traditional DLP solutions, this phenomenon is usually referred to as alert fatigue, or false positive overload, or as the swivel-chair security problem - where practitioners need to stitch various events and data security contexts across multiple silo&#8217;s of tools. But generally, this is why traditional DLP tends to turn security teams into ticket factories, and in the new world of DLP the core idea is to avoid it. Traditional DLP solutions rely on static rules, regular expressions (regex), and exact data matching (EDM). For example, if a user tries to move a file under the old classification schemes where it looks like it has 16 digits, the regex based DLP flags it as a credit card number, even if it&#8217;s not, simply because the data is formatted similarly. This is predominately because these older tools lacked context and depth of understanding of semantics and consideration of other data content context, they often generate massive volumes of false positives. For example, a 2024 Security Boulevard SOC Efficiency Study noted that nearly one-third of all security alerts are false positives, and legacy DLP classification approaches were a primary offender.</p><h3><strong>The Old Paradigm Created a Tremendous Toll on the SOC</strong></h3><p>In the old ticket factory paradigm, analysts with DLP tooling and enforcement points without solid context often spend their entire day bulk-closing tickets just to keep their heads above water, investigating business-as-usual activities rather than actual data exfiltration events. The SOC or data security teams become a ticket factory focused on closing IT service desk requests rather than hunting threats. As data classification, context and semantic understanding has increased, so too has accuracy of alerting, and a great reduction in false positives.</p><h3><strong>Challenges in Modern Day Environments</strong></h3><ul><li><p><strong>SaaS Sprawl:</strong> Sensitive data now moves from both managed and unmanaged endpoints, through communications tools like Slack, Microsoft Teams, and GitHub and are also often outside the view of traditional DLP style gateways and choke points.</p></li><li><p><strong>Unified Data Labeling Strategy and Synchronizing Across the stack:</strong> Google data labeling or Microsoft Purview, tend to be gold standards. Using modern DSPM tools like Cyera, Palo Alto Networks, Varonis and others, they can properly translate labeling as files or data move between different environments.</p></li><li><p><strong>Cloud Data Gravity:</strong> The emergence of Data lakes and object stores has created new complex access paths that violate the assumptions of legacy choke-point models.</p></li><li><p><strong>The AI runtime increasingly routes through the browser:</strong> Most SaaS work and many GenAI interactions happen in-browser, which makes browser and session control a first-class last-mile enforcement-plane. Endpoint and network DLP are not obsolete, but they are often insufficient alone for browser-mediated leakage (copy/paste, upload/download, printing, screen capture) and for prompt and agent workflows.</p></li></ul><div><hr></div><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Subscribe to Software Analyst Cyber Research for in-depth research, market insights, and early signals on the next wave of security innovation.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><p></p><div><hr></div><h2><strong>Trends driving the change</strong></h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!dx8W!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb52e9e4a-03e2-44a5-bce2-9773c85cc662_1600x900.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!dx8W!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb52e9e4a-03e2-44a5-bce2-9773c85cc662_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!dx8W!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb52e9e4a-03e2-44a5-bce2-9773c85cc662_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!dx8W!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb52e9e4a-03e2-44a5-bce2-9773c85cc662_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!dx8W!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb52e9e4a-03e2-44a5-bce2-9773c85cc662_1600x900.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!dx8W!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb52e9e4a-03e2-44a5-bce2-9773c85cc662_1600x900.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b52e9e4a-03e2-44a5-bce2-9773c85cc662_1600x900.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!dx8W!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb52e9e4a-03e2-44a5-bce2-9773c85cc662_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!dx8W!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb52e9e4a-03e2-44a5-bce2-9773c85cc662_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!dx8W!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb52e9e4a-03e2-44a5-bce2-9773c85cc662_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!dx8W!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb52e9e4a-03e2-44a5-bce2-9773c85cc662_1600x900.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>These shifts are necessary to address modern environmental challenges, including <strong>SaaS Sprawl</strong>, where sensitive data moves through tools like Slack and GitHub outside traditional gateways, and <strong>Cloud Data Gravity</strong>, which involves complex access paths in data lakes and object stores and labeling problems. As the <strong>AI runtime</strong> increasingly routes through the browser, traditional endpoint and network DLP are often insufficient to control browser-mediated user actions like copy/paste and AI prompt interactions. It&#8217;s notable that not all enforcement points have orchestrated data control, nor do they all share classification and labeling, an industry standardization problem that some vendors are addressing. To address this, vendors focused on data loss have been centralizing policy enforcement based on document and file labeling within data classification functions (for example, labels provided by Microsoft Purview or Google Workspace) in the enforcement layer, most providers now offer label based enforcement, helping to unify enforcement actions across the enforcement layer. To address the data relabeling issue, some enforcement providers offer relabeling capability for documents that pass through their inspection points and help with freshness of that unified enforcement. Some vendors in the great reset DLP enforcement layer are also leveraging the Microsoft Security graph for risk signals to enhance threat prevention context coupled with visibility and control of user activities with sensitive data type policies for example conditional access signals like geolocation, endpoint, fingerprints, historical risk scoring,etc.</p><h2>Why the browser has become a new enforcement plane</h2><p>The shift toward web-based user workspaces and the rise of AI chat interfaces have transformed the browser into a vital enforcement plane for data security. As organizations move almost entirely to SaaS applications, new browser-based solutions and extensions are emerging as essential complementary tools to address visibility gaps. While GenAI chat is driving the initial demand for integrated Data Loss Prevention (DLP), the market is rapidly expanding toward agentic platforms that require sophisticated API-integrated services for comprehensive data control. Standard network and endpoint security often fail to capture granular, in-session activities. Consequently, the browser, combined with integrated APIs for agentic services, provides critical last-mile governance over how users and AI agents manipulate sensitive information. Modern browser-oriented security now leverages capabilities like DOM inspection, fingerprinting, and WebAssembly containers to function as a primary enforcement mechanism, offering robust detection, classification, and control at the edge.</p><p>Benefits include:</p><ul><li><p><strong>SaaS work that happens in-browser:</strong> In today&#8217;s modern SaaS applications, the most common collaboration and administrative actions occur in web apps.</p></li><li><p><strong>GenAI interactions that happen in-browser:</strong> Chat oriented prompts, copilots, and embedded assistants often run in a browser session even when backed by enterprise models.</p></li><li><p><strong>Copy/paste/upload/download and application context dominate leakage methods in browsers: </strong> This means that last-mile user actions are frequently the decisive exfil path, and they can bypass network or API-only controls without browser and session level enforcement. This capability is achieved either through browser extensions, injections of javascript to monitor dom-tree and execution elements, or enterprise browser replacements.</p></li></ul><h3><strong>The DLP Technology and Deployment Evolution</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!aJEt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2252e7b2-4a20-43ff-ae2e-8a694ed2486c_1600x900.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!aJEt!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2252e7b2-4a20-43ff-ae2e-8a694ed2486c_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!aJEt!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2252e7b2-4a20-43ff-ae2e-8a694ed2486c_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!aJEt!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2252e7b2-4a20-43ff-ae2e-8a694ed2486c_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!aJEt!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2252e7b2-4a20-43ff-ae2e-8a694ed2486c_1600x900.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!aJEt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2252e7b2-4a20-43ff-ae2e-8a694ed2486c_1600x900.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2252e7b2-4a20-43ff-ae2e-8a694ed2486c_1600x900.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!aJEt!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2252e7b2-4a20-43ff-ae2e-8a694ed2486c_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!aJEt!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2252e7b2-4a20-43ff-ae2e-8a694ed2486c_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!aJEt!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2252e7b2-4a20-43ff-ae2e-8a694ed2486c_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!aJEt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2252e7b2-4a20-43ff-ae2e-8a694ed2486c_1600x900.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>Modern DLP Outcome Imperatives</strong></h3><ol><li><p><strong>Establish a Discovery-led truth layer</strong> by shifting from Regex to AI Classification, Context Enrichment, and Semantic Understanding to classify data based on actual sensitivity and user intent, eliminating the need for thousands of static regex rules.</p></li><li><p><strong>Implement Automated Triage and Streamlined Incident Response</strong> by utilizing Agentic AI to autonomously triage alerts, auto-close false positives, and only escalate validated threats, preventing the SOC from becoming a data loss ticket factory.</p></li><li><p><strong>Empower the End-User with Real-Time Just-in-Time Coaching</strong> by leveraging automated workflows and browser-based alerts via platforms like Slack or Microsoft Teams to prompt users for justification or self-correction during policy violations, effectively decentralizing enforcement and reducing low-risk tickets.</p></li><li><p><strong>Drive Proactive Remediation and Prevention through Agentic Campaigns</strong> where modern DSPM and DLP solutions evolve toward autonomous, real-time remediation across the truth layer and prevention at the enforcement layer, enabling enterprises to launch agentic communication campaigns or continuous evaluation for prevention and engagement with data owners to address potential risks preemptively.</p></li><li><p><strong>Deploy Distributed Automated Enforcement</strong> with machine-speed interventions, including real-time blocking, contextualized DSPM, runtime encryption, and asset quarantine, by deploying uniform protections across endpoints and cloud gateways to effectively halt exfiltration and secure intellectual property.</p></li></ol><h2>When Selecting Data Loss Prevention Controls, Consider the Data Loss Prevention Trade-Off</h2><p>This infographic illustrates The Data Loss Prevention Value Trade-Off using a four-quadrant matrix that evaluates cybersecurity strategies based on their Value versus their Operational Burden. The chart highlights an Optimal Zone in the upper-left quadrant, where modern solutions like DSPM-DLP convergence, AI-era controls for prompts, and automated remediation and prevention workflows provide high security value with relatively low maintenance effort.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!jgb7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10870aee-8623-44b3-8a91-aa68fa7ad4ba_1600x900.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!jgb7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10870aee-8623-44b3-8a91-aa68fa7ad4ba_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!jgb7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10870aee-8623-44b3-8a91-aa68fa7ad4ba_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!jgb7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10870aee-8623-44b3-8a91-aa68fa7ad4ba_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!jgb7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10870aee-8623-44b3-8a91-aa68fa7ad4ba_1600x900.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!jgb7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10870aee-8623-44b3-8a91-aa68fa7ad4ba_1600x900.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/10870aee-8623-44b3-8a91-aa68fa7ad4ba_1600x900.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!jgb7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10870aee-8623-44b3-8a91-aa68fa7ad4ba_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!jgb7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10870aee-8623-44b3-8a91-aa68fa7ad4ba_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!jgb7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10870aee-8623-44b3-8a91-aa68fa7ad4ba_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!jgb7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10870aee-8623-44b3-8a91-aa68fa7ad4ba_1600x900.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In stark contrast, the Danger Zone in the lower-right quadrant contains legacy methods, such as classic network controls and deterministic pattern matching, which are depicted as having low value and high operational complexity. Ultimately, the visual serves as a strategic roadmap, encouraging organizations to shift away from labor-intensive, rule-based systems toward adaptive, SaaS-first enforcement and automated workflows to maximize efficiency and protection.</p><p></p><div><hr></div><p></p><h1><strong>Market Evolution in DLP</strong></h1><h2><strong>New Building Block Layers Emerge</strong></h2><p>Modern DLP stacks are increasingly assembled from interoperable component layers rather than a single monolith. This modular approach allows enterprises to move beyond legacy perimeter-based security toward a discovery-led data control plane. The landscape of Data Loss Prevention (DLP) is evolving from static, rule-based systems to highly intelligent, context-aware and AI/agentic enabled platforms designed to secure modern, AI-driven workspaces. Emerging features in this space focus on understanding intent, tracking data throughout its lifecycle, and governing both human and machine identities.</p><p><strong>Here is a look at the emerging concepts and capabilities in modern DLP:</strong></p><h2><strong>Autonomous AI Investigation</strong></h2><blockquote><p>Instead of relying on rigid keyword matching or regular expressions that generate massive alert fatigue, modern DLP platforms deploy AI to autonomously investigate potential data loss events. These intelligent systems analyze incidents across multiple dimensions&#8212;such as the data itself, the systems involved, human behavior, and the surrounding business processes. By interpreting the context and intent behind a data transaction, the system can distinguish between legitimate business workflows and genuine risks, effectively automating alert triage and response.</p></blockquote><h2><strong>Governance of AI Agents and MCPs</strong></h2><blockquote><p>As enterprises increasingly deploy autonomous AI agents to execute tasks, DLP must expand to secure these non-human actors. Emerging platforms provide continuous discovery and governance by enforcing action policies on autonomous behavior. This includes inline inspection of interactions, such as monitoring Model Context Protocol (MCP) calls, to prevent prompt injections, jailbreaks, and unintended data leakage across the AI supply chain. See Agentic Platform examples below.</p></blockquote><h2><strong>Graph-Based Data Lineage</strong></h2><blockquote><p>Rather than inspecting files in isolation, modern DLP tracks the entire lifecycle and provenance of data. By capturing a continuous record of where data originated (e.g., a secured internal database), how it has been modified, and who has interacted with it, systems can accurately assess risk. For instance, if sensitive data is copied, reformatted, and pasted into an unauthorized generative AI prompt, the DLP system recognizes the data&#8217;s sensitive origin and enforces protection policies, drastically reducing false positives.</p></blockquote><h2><strong>In-Line Browser Guardrails</strong></h2><blockquote><p>With the web browser becoming the primary interface for SaaS and Generative AI applications, emerging DLP solutions apply granular, last-mile controls directly within web sessions. Instead of simply blocking entire websites, these capabilities monitor text inputs, drag-and-drop actions, and file uploads in real time. They can dynamically disable copy/paste functions for specific fields or automatically redact sensitive information before it is submitted to public AI models, allowing organizations to adopt AI productivity tools safely.</p></blockquote><h2><strong>Dynamic, Risk-Adaptive Controls</strong></h2><blockquote><p>Modern DLP is moving away from static allow or block rules toward dynamic enforcement based on continuous behavioral and intent analysis. By calculating real-time risk scores based on user activity, the system can baseline normal behavior and automatically adjust its posture. If an employee exhibits anomalous or high-risk behavior, such as a sudden spike in downloads or accessing unusual repositories, the DLP controls automatically tighten to intervene. Once the behavior returns to normal, the restrictions are relaxed, minimizing friction for legitimate work.</p></blockquote><h3><strong>Emerging Agentic Platforms in 2026</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!c5lY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F965f799e-47ee-4631-99a8-d524c43c3a18_1080x1350.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!c5lY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F965f799e-47ee-4631-99a8-d524c43c3a18_1080x1350.png 424w, https://substackcdn.com/image/fetch/$s_!c5lY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F965f799e-47ee-4631-99a8-d524c43c3a18_1080x1350.png 848w, https://substackcdn.com/image/fetch/$s_!c5lY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F965f799e-47ee-4631-99a8-d524c43c3a18_1080x1350.png 1272w, https://substackcdn.com/image/fetch/$s_!c5lY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F965f799e-47ee-4631-99a8-d524c43c3a18_1080x1350.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!c5lY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F965f799e-47ee-4631-99a8-d524c43c3a18_1080x1350.png" width="1080" height="1350" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/965f799e-47ee-4631-99a8-d524c43c3a18_1080x1350.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1350,&quot;width&quot;:1080,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:116102,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://softwareanalyst.substack.com/i/194969072?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F965f799e-47ee-4631-99a8-d524c43c3a18_1080x1350.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!c5lY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F965f799e-47ee-4631-99a8-d524c43c3a18_1080x1350.png 424w, https://substackcdn.com/image/fetch/$s_!c5lY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F965f799e-47ee-4631-99a8-d524c43c3a18_1080x1350.png 848w, https://substackcdn.com/image/fetch/$s_!c5lY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F965f799e-47ee-4631-99a8-d524c43c3a18_1080x1350.png 1272w, https://substackcdn.com/image/fetch/$s_!c5lY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F965f799e-47ee-4631-99a8-d524c43c3a18_1080x1350.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>*Consideration List - not exhaustive</p><h1><strong>Defining the Unified Data Loss Control Plane (DLCP) for the Modern Enterprise</strong></h1><h2><strong>Converged Concept 1: The Convergence of DSPM and Discovery-Led Truth Layers</strong></h2><ul><li><p><strong>System of Record:</strong> Discovery-led classification (and label translation and synchronization between Google and Microsoft environments) establishes the definitive truth layer, where Data Security Posture Management (DSPM) acts as the system of record to position DLP as a measurable outcome.</p></li><li><p><strong>New Architectural Model:</strong> <em>DSPM (inventory + classification + risk) &#8594; data control plane (orchestration) &#8594; distributed enforcement points.</em></p></li></ul><h2><strong>Converged Concept 2: Adaptive and Contextual Data Control Planes</strong></h2><ul><li><p><strong>Operational Goal:</strong> Reducing the operational tax and eliminating ticket factory outcomes through high-fidelity signal prioritization and automated triage.</p></li><li><p><strong>Contextual Governance:</strong> Policies must integrate identity, access entitlements, and sharing posture to inform automated remediation and prevention across the full data lifecycle.</p></li></ul><h2><strong>Converged Concept 3: Securing the AI Runtime: Prompts, Copilots, and Agents</strong></h2><ul><li><p><strong>Leakage Modes:</strong> Addressing emerging exposure paths, including prompt-based exfiltration, Copilot access scope, and agentic tool-call actions across cloud and SaaS surfaces.</p></li><li><p><strong>Runtime Controls:</strong> Implementing session-based interventions&#8212;such as redaction, masking, and policy-driven warnings&#8212;tailored to specific data sensitivity and user behavior.</p></li><li><p><strong>Auditability:</strong> Establishing governance through audit-grade evidence, capturing data lineage and event provenance to support forensic investigations and remediation or prevention proof.</p></li></ul><h3><strong>The AI-era Example Scenario</strong></h3><blockquote><p><strong>The New Scenario:</strong> An employee pastes proprietary code into a public GenAI chatbot</p><p><strong>Modern DLCP response:</strong> Move towards warning users or redacting sensitive fragments and log an event with audit-grade detail</p></blockquote><ol><li><p><strong>Technical description:</strong> Prompt inspection, redaction, policy-driven warnings and blocking, Copilot governance, agent tool-call control and logging.</p></li><li><p><strong>How it addresses the problem:</strong> Covers exposure modes that do not resemble classic file and email exfiltrations.</p></li><li><p><strong>Integration considerations:</strong> Needs enhanced integrations into GenAI surfaces including but not limited to AI chat interfaces, Developer API Surfaces, Integrated AI services and AI Agent platforms and providers with strong logging and evidence as a differentiator.</p></li></ol><h2><strong>A Deep Dive of the Stack: Modern DLP Layers 0 through 6</strong></h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xUGb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9242576-5fc8-40a6-b5e6-688f81e925b5_1600x900.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xUGb!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9242576-5fc8-40a6-b5e6-688f81e925b5_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!xUGb!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9242576-5fc8-40a6-b5e6-688f81e925b5_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!xUGb!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9242576-5fc8-40a6-b5e6-688f81e925b5_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!xUGb!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9242576-5fc8-40a6-b5e6-688f81e925b5_1600x900.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xUGb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9242576-5fc8-40a6-b5e6-688f81e925b5_1600x900.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c9242576-5fc8-40a6-b5e6-688f81e925b5_1600x900.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!xUGb!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9242576-5fc8-40a6-b5e6-688f81e925b5_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!xUGb!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9242576-5fc8-40a6-b5e6-688f81e925b5_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!xUGb!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9242576-5fc8-40a6-b5e6-688f81e925b5_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!xUGb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9242576-5fc8-40a6-b5e6-688f81e925b5_1600x900.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Intelligence Plane</h2><h3><strong>Layer 1: Continuous discovery &amp; classification (the truth layer)</strong></h3><ul><li><p><strong>Technical description:</strong> API-based scanning of SaaS repositories and cloud data stores and performs classification using advanced patterns and machine learning (ML) algorithms with continuous posture updates to reflect real-time changes.</p></li><li><p><strong>How it addresses the problem:</strong> This layer reduces the unknown-unknowns that typically drive the noisy enforcement environments of the past, sporting high false-positive rates, and drawing political pushback from business units. By establishing a definitive truth layer through Data Security Posture Management (DSPM), organizations can position DLP as a measurable outcome of discovery and business enabler or at least an optimizing function.</p></li><li><p><strong>Integration considerations:</strong> Coverage breadth is heavily dependent on the quality of vendor connectors across SaaS, IaaS, and on-premises environments. High-fidelity classification and robust evidence trails are critical for supporting forensic investigations and establishing stakeholder trust in automated actions.</p></li><li><p><strong>Scanning Performance, Cloud Costs and Speed to Discovery:</strong> Various styles of deployment and sampling rates dictate the speed of discovery and scanning. For example, with file scanning using centralized methods, this can impact performance. Scan speed can be enhanced based on localized cloud based scanners and sampling of data stores (especially for structured data types) can be essential for speed (for example, identifying a credit card bin or social security number by sampling a few rows in a database table vs examining all data). Any DLP scanning interactions from Cloud to Cloud or Cloud to Premise can expand cloud costs.</p></li></ul><h3><strong>Layer 2: Access and usage context (identity, entitlement, posture and behavior)</strong></h3><ul><li><p><strong>Technical description:</strong> Modern DLP can augment content findings with who-accessed and who-shared, privilege and entitlement context, sharing posture, and sometimes lineage.</p></li><li><p><strong>How it addresses the problem:</strong> Applying these contextual elements, especially through federated context facilities such as model context protocol (MCP) reduces false positives and can enhance speed due to reduced re-classification need and enables prioritization or data security controls and enforcement mechanisms (what matters, to whom, and why).</p></li><li><p><strong>Integration considerations:</strong> This layer requires identity and SSO signals, SaaS audit logs, and in some cases endpoint or network gateway/SASE/SSE telemetry.</p></li></ul><h3><strong>Layer 3: Policy orchestration across tools (the data control plane)</strong></h3><ul><li><p><strong>Technical description:</strong> Ideal deployments will offer the ability to centralize data security policy definitions that map to distributed enforcement points and enforcement templates and apply these suggested policies to reduce manual burden.</p></li><li><p><strong>How it addresses the problem:</strong> Can help prevent policy sprawl across tools and aligns controls to business context and data labeling.</p></li><li><p><strong>Integration considerations:</strong> Orchestration depth varies, many vendors still are reliant on single vendor selection, but some products push policy into SSE and SASE or endpoint, others focus on SaaS actions.</p></li></ul><h2>Enforcement Plane</h2><h3><strong>Layer 4: Enforcement planes (API, inline, browser/session, endpoint)</strong></h3><ul><li><p><strong>Technical description:</strong></p><ul><li><p><strong>API/SaaS-first:</strong> Out-of-band detection + actions (quarantine, redact, revoke links)</p></li><li><p><strong>Inline SSE/SASE/GW:</strong> Offers real-time inspection/control for web and SaaS traffic (often requires steering and SSL/TLS decryption)</p></li><li><p><strong>Browser/session (last-mile runtime):</strong> In-session control over copy/paste, upload/download, printing, screen capture, and GenAI interactions</p></li><li><p><strong>Endpoint:</strong> device-level controls for local exfil paths (removable media, local copies, unmanaged sync clients, print, clipboard)</p></li></ul></li><li><p><strong>How it addresses the problem:</strong> Provides practical control coverage across the actual runtime surfaces where data moves.</p></li><li><p><strong>Integration considerations:</strong> Inline requires steering, endpoint requires rollout and tuning, browsers may require extension or browser replacement.</p></li></ul><h3><strong>Layer 5: Automated remediation and prevention workflows</strong></h3><ul><li><p><strong>Technical description:</strong> Automated responses (warn, redact, delete, revoke sharing, label) plus audit trails and investigation context.</p></li><li><p><strong>How it addresses the problem:</strong> Shifts DLP from alert factory to measurable risk reduction and autonomous prevention.</p></li><li><p><strong>Integration considerations:</strong> Action depth is vendor- and connector-dependent, evidence quality is crucial for stakeholder trust.</p></li></ul><h3><strong>Layer 6: AI runtime DLP (prompts, copilots, agents)</strong></h3><h4><strong>Capability taxonomy: AI runtime DLP</strong></h4><p>Emerging capability often delivered via API surface or inline proxy runtime) see also SACR <a href="https://softwareanalyst.substack.com/p/the-convergence-of-ai-and-data-security">Unified Agentic Defense Platforms</a> publication (UADP).</p><ul><li><p><strong>Prompt input controls:</strong> Offers paste/upload inspection, warnings, redaction/masking, and policy-driven blocking for sensitive inputs.</p></li><li><p><strong>Output controls:</strong> Offer redaction/masking/watermarking of generated outputs and safe copy or data export controls.</p></li><li><p><strong>Tool-call governance :</strong> Can constrain what tools can access/send, enforce least-privilege data access, and log tool inputs and outputs where appropriate, controls data residency and trust.</p></li><li><p><strong>Residency and compliance guardrails: </strong>Residency of data and compliance guardrails must exist for the data they inspect and log. This is critical for regulated environments where PII/PHI/PCI data cannot cross geopolitical or operational boundaries, even when processed by an agent or a cloud-hosted tool.</p></li><li><p><strong>Evidence and forensics for agent actions:</strong> Chain-of-custody events for agent activity (who/what/when), provenance, and investigation-ready timelines.</p></li><li><p><strong>Technical description:</strong> Prompt inspection,redaction, policy-driven warnings/blocks, Copilot governance, agent tool-call logging.</p></li><li><p><strong>How it addresses the problem:</strong> Covers exposure modes that do not resemble classic file/email exfiltration.</p></li><li><p><strong>Integration considerations:</strong> Needs integration into GenAI surfaces, strong logging and evidence is a differentiator.</p></li></ul><h1>Enterprise Data Loss Prevention Great DLP Reset Deployment Framework (Ideal Scenario)</h1><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wDE7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50f79d45-7bc8-4ad7-9ee0-20a69d79133a_1600x900.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wDE7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50f79d45-7bc8-4ad7-9ee0-20a69d79133a_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!wDE7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50f79d45-7bc8-4ad7-9ee0-20a69d79133a_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!wDE7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50f79d45-7bc8-4ad7-9ee0-20a69d79133a_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!wDE7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50f79d45-7bc8-4ad7-9ee0-20a69d79133a_1600x900.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wDE7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50f79d45-7bc8-4ad7-9ee0-20a69d79133a_1600x900.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/50f79d45-7bc8-4ad7-9ee0-20a69d79133a_1600x900.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wDE7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50f79d45-7bc8-4ad7-9ee0-20a69d79133a_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!wDE7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50f79d45-7bc8-4ad7-9ee0-20a69d79133a_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!wDE7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50f79d45-7bc8-4ad7-9ee0-20a69d79133a_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!wDE7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50f79d45-7bc8-4ad7-9ee0-20a69d79133a_1600x900.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Market landscape: DLP layers (archetypes)</strong></h2><p>This section maps common product layer archetypes to the control-plane model. Many platforms span multiple layers, but most have a primary center of gravity.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!IUhd!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F584f7529-34bd-4b6c-87fd-509a65608ad0_1080x1350.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!IUhd!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F584f7529-34bd-4b6c-87fd-509a65608ad0_1080x1350.png 424w, https://substackcdn.com/image/fetch/$s_!IUhd!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F584f7529-34bd-4b6c-87fd-509a65608ad0_1080x1350.png 848w, https://substackcdn.com/image/fetch/$s_!IUhd!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F584f7529-34bd-4b6c-87fd-509a65608ad0_1080x1350.png 1272w, https://substackcdn.com/image/fetch/$s_!IUhd!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F584f7529-34bd-4b6c-87fd-509a65608ad0_1080x1350.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!IUhd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F584f7529-34bd-4b6c-87fd-509a65608ad0_1080x1350.png" width="1080" height="1350" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/584f7529-34bd-4b6c-87fd-509a65608ad0_1080x1350.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1350,&quot;width&quot;:1080,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:197644,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://softwareanalyst.substack.com/i/194969072?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F584f7529-34bd-4b6c-87fd-509a65608ad0_1080x1350.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!IUhd!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F584f7529-34bd-4b6c-87fd-509a65608ad0_1080x1350.png 424w, https://substackcdn.com/image/fetch/$s_!IUhd!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F584f7529-34bd-4b6c-87fd-509a65608ad0_1080x1350.png 848w, https://substackcdn.com/image/fetch/$s_!IUhd!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F584f7529-34bd-4b6c-87fd-509a65608ad0_1080x1350.png 1272w, https://substackcdn.com/image/fetch/$s_!IUhd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F584f7529-34bd-4b6c-87fd-509a65608ad0_1080x1350.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>Adoption path (maturity model)</strong></h3><ol><li><p><strong>Start with the truth layer:</strong> Can establish discovery and classification and basic evidence.</p></li><li><p><strong>Prove remediation and prevention in one high-noise channel:</strong> Pick a SaaS surface and close the loop with reversible actions.</p></li><li><p><strong>Add context to reduce noise:</strong> Add context from sources such as identity,entitlements and sharing posture to prioritize what matters most for preventive enforcement actions or remediation.</p></li><li><p><strong>Add heavier enforcement intentionally:</strong> Inline SSE/SASE/GW (and SSL/TLS decryption) and endpoint where required by risk scenarios.</p></li><li><p><strong>Make AI runtime governance explicit:</strong> Emerging prompt,output, tool-call controls offer enforcement of DLP policy plus may add AI agent evidence through MCP monitoring or API integrations. Treat browser and sessions as a primary runtime where applicable. Also see SACR publication (<a href="https://softwareanalyst.substack.com/p/the-convergence-of-ai-and-data-security">Unified Agentic Defense Platforms</a> (UADP))</p></li><li><p><strong>To help Unify Enforcement Policies:</strong> Develop and use Normalized Data Sensitivity Labeling across Enforcement Points. Data sensitivity labeling from DSPM serves as a ground truth layer, derived from Microsoft Purview and Google Workspace classification label schemes.</p></li></ol><h3><strong>Data Sensitivity Labeling: Normalized for Enforcement Layer Policies</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!WwFF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faad1c415-23d8-4f95-b43a-ccda1802cdf6_1080x1350.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!WwFF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faad1c415-23d8-4f95-b43a-ccda1802cdf6_1080x1350.png 424w, https://substackcdn.com/image/fetch/$s_!WwFF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faad1c415-23d8-4f95-b43a-ccda1802cdf6_1080x1350.png 848w, https://substackcdn.com/image/fetch/$s_!WwFF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faad1c415-23d8-4f95-b43a-ccda1802cdf6_1080x1350.png 1272w, https://substackcdn.com/image/fetch/$s_!WwFF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faad1c415-23d8-4f95-b43a-ccda1802cdf6_1080x1350.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!WwFF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faad1c415-23d8-4f95-b43a-ccda1802cdf6_1080x1350.png" width="1080" height="1350" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/aad1c415-23d8-4f95-b43a-ccda1802cdf6_1080x1350.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1350,&quot;width&quot;:1080,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:162760,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://softwareanalyst.substack.com/i/194969072?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faad1c415-23d8-4f95-b43a-ccda1802cdf6_1080x1350.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!WwFF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faad1c415-23d8-4f95-b43a-ccda1802cdf6_1080x1350.png 424w, https://substackcdn.com/image/fetch/$s_!WwFF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faad1c415-23d8-4f95-b43a-ccda1802cdf6_1080x1350.png 848w, https://substackcdn.com/image/fetch/$s_!WwFF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faad1c415-23d8-4f95-b43a-ccda1802cdf6_1080x1350.png 1272w, https://substackcdn.com/image/fetch/$s_!WwFF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faad1c415-23d8-4f95-b43a-ccda1802cdf6_1080x1350.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1>What DLP Vendors Should do to Win in the Great DLP Reset</h1><p>The DLP market is being re-oriented by buyers against a new baseline: measurable risk reduction with lower operational burden, across modern runtimes (SaaS, cloud data platforms, and GenAI). Vendors that continue to lead with more detections without proving enforceable outcomes will increasingly be treated as noise generators rather than control-plane platforms.</p><h2><strong>1) Make operational burden a first-class product outcome</strong></h2><p>Buyers now treat deployment complexity, policy sprawl, and false-positive triage as existential program risks. Vendors should:</p><ul><li><p>Ship opinionated defaults (starter policies, templates, and tuning guardrails) rather than assuming every customer will build a program from scratch.</p></li><li><p>Provide staged rollout and rollback mechanics that are predictable and safe (preflight checks, safe modes, clear blast-radius controls).</p></li><li><p>Instrument and report burden: time-to-deploy, time-to-first-signal, false-positive rate, triage hours/week, and disruption rate (how often enforcement breaks legitimate work).</p></li></ul><h2><strong>2) Prove time-to-first-signal and prevention in days or hours, not quarters</strong></h2><p>A major separation in the market is how fast a platform can surface &#8220;material risk&#8221; (not just matches). Vendors should design onboarding around a 1&#8211;2 week proof window, sooner if at all possible:</p><ul><li><p>Fast connectors to core data gravity (M365/Google, Slack, Salesforce, GitHub, key cloud stores).</p></li><li><p>Immediate prioritization (what&#8217;s sensitive, who can access it, what&#8217;s externally exposed).</p></li><li><p>At least one closed-loop remediation and prevention enforcement paths early (revoke public links, quarantine, ticket, redact, block, delete) so visibility becomes risk reduction.</p></li></ul><h2><strong>3) Turn context and LMM natural language into a real differentiation lever</strong></h2><p>Modern DLP decisions are increasingly identity and entitlement-driven. Vendors should operationalize context:</p><ul><li><p>Identity,  entitlements and sharing posture should directly reduce noise and improve prioritization.</p></li><li><p>Explanations must be human-usable: why this object mattered, why this actor and action is risky, and what changed after remediation.</p></li><li><p>Enhancing Insider Threat incidents with natural language cognitive Large Language Model (LLM) outputs can significantly increase storyline elaboration on incidents and events.</p></li></ul><h2><strong>4) Be explicit about enforcement points, and avoid one-control-point narratives</strong></h2><p>Buyers are increasingly skeptical of vendors that imply universal coverage from a single enforcement surface. Vendors should clearly articulate:</p><ul><li><p>Where controls actually execute (SaaS/API, inline SSE/SASE/GW, endpoint, browser/session, email).</p></li><li><p>Which actions are enforceable per channel (block, quarantine, revoke sharing, redact/delete, label/classify, coach/warn, ticket/workflow).</p></li><li><p>How policy intent stays consistent across distributed control points (a real control plane vs. disconnected features).</p></li><li><p>How they properly stitch together events and data from various sources across the DLP overall deployment architecture to properly create incidents and perform remediation actions in-context, or nudges to users without creating fatigue.</p></li></ul><h2><strong>5) Win on remediation depth (with guardrails), not alert volume</strong></h2><p>The market is shifting from find to fix, nudge,inform. Vendors should strengthen remediation and prevention depth and safety and their ability to lightly engage users:</p><ul><li><p>Prioritize reversible and low-friction actions first (revoke sharing, quarantine, remove public access) before heavy blocking.</p></li><li><p>Provide automation with guardrails (approvals, exception handling, rollback, and proof-of-remediation and prevention).</p></li><li><p>Track outcomes that matter: exposure reduction, % auto-remediated, MTTR, and repeat-offender reduction.</p></li><li><p>Engage users lightly through agentic communications via communications channels (Slack, Teams, etc) for light nudge and user contextual education.</p></li></ul><h2><strong>6) Treat GenAI and agent platforms as a default runtime</strong></h2><p>GenAI and agent platforms introduce high-frequency leakage paths (prompts, uploads, outputs) and emerging MCP agent/tool-call surfaces. Vendors should:</p><ul><li><p>Ship concrete prompt/output controls (detect, warn, redact, block) based on sensitivity and context.</p></li><li><p>Provide audit-grade logging for GenAI interactions, including relevant inputs/outputs where feasible and permitted.</p></li><li><p>Package GenAI policies as templates aligned to real data types (source code, credentials/secrets, regulated identifiers, contracts/M&amp;A).</p></li><li><p>Consider and Expand integrations and capabilities towards Agentic Workflow and agentic platforms (See consideration list for supported data loss controls in the mapping below)</p></li></ul><h2><strong>7) Raise the evidence bar with: audit-grade, investigation-ready artifacts</strong></h2><p>As DLP becomes a control plane, evidence and chain-of-custody become competitive wedges. Vendors should:</p><ul><li><p>Attach defensible evidence to each high-impact event: actor, object, action, sensitivity, destination, timestamps, and remediation or prevention result.</p></li><li><p>Provide investigation-ready timelines and, where possible, lineage/provenance signals that support incident response and audit readiness.</p></li></ul><h2><strong>8) Leverage standardized labeling, and seek cross-product integrated enforcement</strong></h2><p>Since customers increasingly utilize various vendors in their data loss prevention and data security programs, it&#8217;s incumbent on existing vendors to work more harmoniously together, sharing enough information properly to improve the enforcement and control layers. Vendors should:</p><ul><li><p>Integrate or develop sharing mechanisms between discovery and control planes to properly utilize standardized labeling schemes if this capability is not already present.</p></li><li><p>Consider leveraging the Microsoft security graph (as an example) and other sources of risk information as common context sources for enforcement or as elevated risk signals</p></li></ul><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Software Analyst Cyber Research! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><div><hr></div><h1><strong>Market Competitors: Data Loss Prevention (DLP)</strong></h1><p><strong>Key Vendor Differentiators:</strong></p><p>Automation depth, Audit-grade evidence, Data Lineage, Closed-loop Autonomous Tuning</p><p><strong>Great Reset Vendor Alignment Archetypes delivering Modern DLP capabilities:</strong></p><ul><li><p>API / SaaS-first</p></li><li><p>Inline SSE/SASE/GW</p></li><li><p>Endpoint agent</p></li><li><p>Browser extensions</p></li><li><p>Enterprise browsers</p></li><li><p>DSPM-led control plane</p></li><li><p>Hybrid</p></li></ul><p></p><p></p><div><hr></div><p></p><h1>Notable Vendor Profiles</h1><h2>CrowdStrike</h2><h3>Vendor Profile</h3><p>CrowdStrike&#8217;s center of gravity in DLP is as a data security solution embedded into the broader Falcon security platform,  spanning endpoint, SaaS, and cloud data security, including real-time visibility and control of data movement across environments and insider-risk investigation workflows. In practice, CrowdStrike tends to be evaluated when buyers want to consolidate security telemetry and response in a single operating console, reduce tool sprawl, and connect data movement events to identity, device posture, and threat activity, rather than stand up a standalone, multi-channel enterprise DLP suite from scratch. CrowdStrike is an integrated data security capability within the Falcon platform, including DLP and DSPM capabilities for data at rest and extending them with real-time visibility into data in motion across endpoint, SaaS, and cloud environments.</p><h3>Products/Services Overview</h3><ul><li><p><strong>Falcon platform-delivered data security module(s)</strong> Intended to detect and control sensitive data movement across endpoints, SaaS applications, and cloud environments</p></li><li><p><strong>Insider-risk oriented workflows</strong> that make who did what with data investigable across endpoint, SaaS, and cloud environments,  alongside endpoint,  identity and cloud telemetry (useful for investigations, response, and policy exception handling).</p></li><li><p><strong>Platform-driven integration approach:</strong> Data security events and detections across endpoint, SaaS, and cloud environments are designed to be consumed in the same operational plane as endpoint security, identity protection, and broader detection and response functions (reduces swivel-chair across tools).</p></li><li><p><strong>Policy-driven controls and reporting/audit</strong> features appropriate for enterprise security operations.</p></li></ul><h4>Market Category</h4><p>DLP / Data Security Platform (DSP)</p><h4>Market Sub-Category</h4><p><strong>Insider Risk / DDR</strong></p><h4>Great DLP Reset Alignment</h4><p><strong>Hybrid</strong></p><p>CrowdStrike aligns to the Great DLP Reset less as a single DLP product and more as a consolidation-driven layer that connects data movement risk to identity, endpoint posture, cloud posture and response operations. In the Reset framing, where DLP evolves into a unified data control plane, CrowdStrike&#8217;s role is typically strongest on the investigation and response side and enforcement at endpoint egress as well as visibility and control across SaaS and cloud environments, helping security teams reduce time-to-triage by correlating data loss and data movement events with broader threat and user behavior context. The main tradeoff is architectural as teams seeking first-class SaaS-first/API remediation or deep DSPM-style truth layer and discovery may treat CrowdStrike as complementary rather than primary, while Falcon-centric organizations may prioritize it as the operational backbone that unifies security actions.</p><h4>Core Functions and Use Cases</h4><ul><li><p><strong>Cross environment data loss visibility:</strong> understand and govern sensitive data at rest and data movement across endpoints, SaaS applications, and cloud services..</p></li><li><p><strong>Insider risk investigation and response:</strong> Detect anomalous behavior and connect suspicious data movements to identity, device posture, and security events. Supports  event based forensic screen captures to provide full context of detection.</p></li><li><p><strong>Operational consolidation:</strong> Bring data security signals into a single SecOps operating plane to accelerate triage and response.</p></li><li><p><strong>Policy-driven monitoring and guardrails:</strong> Establish baseline monitoring and targeted preventative controls for high-risk scenarios.</p></li></ul><h3>Use Cases and Pain Points Addressed</h3><ol><li><p><strong>Detect and investigate suspicious file movement by employees or contractors</strong></p></li></ol><blockquote><p>Detect anomalous behavior and connect data movement events to identity and endpoint context to reduce investigation time and improve defensibility. Supports event based forensic screen capture to provide full context of detection.</p></blockquote><ol start="2"><li><p><strong>Reduce the swivel chair, multi-console approach during data incident response</strong></p></li></ol><blockquote><p>Centralize data-related events where SecOps teams already work, reducing handoffs between endpoint, SIEM, and standalone DLP tools.</p></blockquote><ol start="3"><li><p><strong>Targeted prevention for high-risk exfiltration paths across endpoints, SaaS applications, and cloud environments.</strong></p></li></ol><blockquote><p>Apply policy guardrails to the data movement patterns that commonly show up in insider scenarios (scope depends on enabled controls).</p></blockquote><ol start="4"><li><p><strong>Support audit and incident review workflows</strong></p></li></ol><blockquote><p>Preserve a clearer narrative of what occurred, by whom, and on which endpoint(s), enabling more consistent post-incident reporting.</p></blockquote><ol start="5"><li><p><strong>Rationalize overlapping tools in platform-consolidation programs</strong></p></li></ol><blockquote><p>Where buyers have multiple partial controls (endpoint + SSE + M365), CrowdStrike can function as the operational glue for triage and response, though not necessarily the deepest enforcement layer everywhere.</p></blockquote><h3>Differentiation and Competitive Novelty</h3><ul><li><p><strong>Strongest differentiation is</strong> <strong>operational consolidation</strong>: Aligns data security events with endpoint and identity telemetry in a single platform experience.</p></li><li><p><strong>Investigation-first posture</strong>: Often well-suited to insider-risk-heavy requirements where proving intent, tracing activity, and accelerating response are as important as blocking.</p></li><li><p><strong>Platform adoption leverage</strong>: Can be compelling when Falcon is already deployed widely, lowering friction compared to introducing a new, standalone DLP management plane.</p></li></ul><p><strong>SACR Key take away:</strong></p><p>CrowdStrike is best suited for organizations prioritizing consolidation of data security within a broader security platform, particularly where connecting data movement, user activity, and response workflows is important. It is typically evaluated in scenarios focused on insider risk investigations and operational unification, especially in environments with an existing Falcon deployment, rather than as a standalone, multi-channel enterprise DLP platform.</p><h2>Cyberhaven</h2><h3>Vendor Profile</h3><p>Cyberhaven is a data detection &amp; response (DDR) platform built around data lineage. The core thesis is that classic DLP fails at modern workflows because content-only inspection lacks context. Cyberhaven finds and follows data through endpoints and browser activity to determine where it came from, how it was transformed, and what a user is trying to do with it. In practice, Cyberhaven is best understood as a last-mile enforcement and investigation layer for DLP programs: it focuses on data-in-use (copy/paste, uploads/downloads, sharing actions) and produces richer evidence for investigations and insider-risk scenarios.</p><h3>Products/Services Overview</h3><ul><li><p><strong>Data Detection &amp; Response (DDR) platform:</strong> A lineage-centric platform that finds and follows data through endpoints and browser activity to determine provenance and intent.</p></li><li><p><strong>Reimagined DLP:</strong> Provides prevention and policy enforcement based on data lineage and context rather than content-only inspection.</p></li><li><p><strong>Insider Risk Management:</strong> Combines behavioral signals with data lineage to identify and resolve attribution of persistent IP leakage.</p></li><li><p><strong>AI security capabilities:</strong> Delivers inventory and controls for AI tools and agent-like workflows, addressing data recombination and exfiltration at scale.</p></li></ul><h4>Market Category</h4><p>Insider Risk / DDR</p><h4>Great DLP Reset Alignment</h4><p><strong>Hybrid</strong></p><p>Cyberhaven aligns with the Great DLP Reset as a last-mile enforcement and investigation layer that preserves the truth of sensitive provenance through data lineage, even as data is modified. Architecturally, it deploys across endpoint agents and browser extensions to capture granular in-use activities. The tradeoff is that while it produces significantly richer evidence for forensic investigations and reduces alert fatigue via context-aware decisions, it carries the higher operational burden associated with endpoint and browser-mediated deployments compared to API-first models.</p><h4>Core Functions and Use Cases</h4><ol><li><p><strong>Lineage-driven detection and classification</strong></p><ul><li><p>Track data objects and derivatives through user workflows to preserve provenance and intent context.</p></li></ul></li><li><p><strong>Prevent exfiltration in data-in-use paths</strong></p><ul><li><p>Focus on last-mile actions: copy/paste, upload/download, email/web destinations, and other endpoint/browser mediated movements.</p></li></ul></li><li><p><strong>Insider risk and investigations</strong></p><ul><li><p>Use lineage to accelerate investigation timelines and reduce &#8220;swivel-chair&#8221; work.</p></li><li><p>Example from briefing: Cyberhaven described supporting investigations where the goal is to identify the source of persistent IP leakage and resolve attribution (e.g., find a mole scenario).</p></li></ul></li><li><p><strong>AI-era leakage paths</strong></p><ul><li><p>Cyberhaven described AI as a major driver of demand, even for organizations that are not AI-forward, because AI accelerates data recombination and exfil at scale.</p></li></ul></li></ol><h3>Use Cases and Pain Points Addressed</h3><h3>Differentiation and Competitive Novelty</h3><ul><li><p><strong>Data lineage as the core primitive</strong> (not just a feature): lineage is used to inform classification, enforcement decisions, and evidence generation.</p></li><li><p><strong>Context-first enforcement model:</strong> emphasis on deciding <em>when to block vs warn vs allow</em> using provenance + identity and behavior signals, not only content patterns.</p></li><li><p><strong>Strong fit for existential data scenarios:</strong> advanced manufacturing / product design, frontier AI labs, and highly regulated environments where data is the business.</p></li></ul><p><strong>SACR Key take away:</strong></p><p>Cyberhaven is best positioned for organizations where data is the business, such as frontier AI labs, advanced manufacturing, or highly regulated sectors requiring deep forensic proof of intent. Shortlist Cyberhaven when your threat model requires tracking data derivative fragments through complex user workflows and you are prepared to operationalize endpoint/browser telemetry to achieve investigation-ready timelines.</p><h2>Cyera</h2><h3>Vendor Profile</h3><p>Cyera is a data security platform vendor that has expanded from DSPM (sensitive data discovery, classification, and exposure analysis) into DLP via Omni DLP, positioned as an agentic intelligence layer that correlates and enriches DLP signals from existing enforcement tools rather than replacing them outright. In DLP terms, Cyera&#8217;s center of gravity is improving time-to-triage and policy confidence by adding data sensitivity and access context (data at rest truth) to data in motion and in use events coming from email/web/SSE/endpoint, SaaS, and AI ecosystems.</p><h3>Products/Services Overview</h3><ul><li><p><strong>DSPM / data security platform foundation:</strong> Agentless discovery and classification of sensitive data across cloud/SaaS/hybrid/on-prem data stores, plus exposure and access analysis to establish what data exists, where, and who can reach it.</p></li><li><p><strong>Omni DLP (DLP module):</strong> Agentic intelligence layer for aggregating DLP events from existing tools, enriching with Cyera data context, and prioritizing and triaging alerts, positioned as sitting above existing DLP controls (not a rip-and-replace).</p></li><li><p><strong>Browser Shield (AI module):</strong> Browser extension for mapping AI footprint, resolving session-level identity, and enforcing real-time blocking by intercepting prompts to analyze conversational context and intent before data is ever transmitted to public LLMs, sanctioned copilots, or emerging AI agents.</p></li><li><p><strong>Policy and tuning assistance:</strong> Guidance on which policies are noisy vs. high-signal and recommendations intended to help teams move from monitor-only to safer enforcement over time. Orchestrates policies to achieve the same goals in different technical silos.</p></li><li><p><strong>Remediation workflow support (platform-wide):</strong> One-click or guided remediation actions and integrations with ticketing / SOAR-style workflow tools (e.g., ServiceNow/Jira and automation partners referenced by Cyera) to operationalize findings.</p></li><li><p><strong>Integrations ecosystem:</strong> Published integrations and partner ecosystem intended to connect data context to downstream security and operations tools.</p></li></ul><h4>Market Category</h4><p>Insider Risk / DSPM / Data and AI Security Platform / DLP</p><h4>Great DLP Reset alignment</h4><p>Hybrid</p><p>Cyera aligns to the reset narrative by treating classic DLP as a fragmented set of enforcement points that struggles without a strong truth layer (sensitive-data understanding and access context) and without an operationally efficient way to reduce noise. In practice, Cyera&#8217;s model is to establish high-confidence data context via DSPM, ingest and normalize signals from existing DLP enforcement controls, then use that context to drive prioritization, tuning recommendations, and targeted remediation workflows. The tradeoff is architectural dependency and value is highest when Cyera can integrate broadly into the enforcement and telemetry sources already deployed.</p><h4>Core Functions and Use Cases</h4><ul><li><p><strong>Sensitive data discovery and classification as DLP prerequisite:</strong> Build an inventory of sensitive data and its locations to drive precise DLP scoping.</p></li><li><p><strong>Cross-channel DLP signal rationalization:</strong> Reduce alert flooding of the SOC and data owners by correlating and enriching events with data and access context and highlighting the subset most likely to represent meaningful risk.</p></li><li><p><strong>Policy improvement workflow:</strong> Identify noisy policies and provide tuning guidance to improve confidence before enforcement changes.</p></li><li><p><strong>Exposure-driven remediation:</strong> Route concrete remediation (remove public links, reduce over-sharing, reduce risky access paths) to the right owners with auditability.</p></li><li><p><strong>AI-era data loss governance:</strong> Apply the same data context and runtime signals concept to AI-related data interactions.</p><ul><li><p><strong>Shadow AI discovery:</strong> Inventory every AI tool accessed via managed browsers, move from unsanctioned to approved</p></li><li><p><strong>AI prompt protection:</strong> Block user prompts that leak sensitive data or violate acceptable use policy, including malicious content, in browser-based sessions</p></li></ul></li></ul><h3>Use Cases and Pain Points Addressed</h3><ol><li><p><strong>Reduce false positive triage load in existing DLP programs</strong> by adding data sensitivity and access context to alerts, so analysts can focus on fewer, higher-confidence events (enables faster time-to-decision).</p></li><li><p><strong>Make monitor-only policies safer to operationalize</strong> by measuring where rules produce noise and guiding tuning toward higher precision (reduces business disruption risk when moving toward blocking).</p></li><li><p><strong>Prioritize remediation based on business risk context</strong> (where sensitive data is, who can access it, and how it is being shared/exposed), enabling targeted cleanup (revoke access, fix sharing posture, ticket to owners).</p></li><li><p><strong>Speed up scoping during investigations by connecting where sensitive data lives</strong> to what event happened (reduces time spent chasing owners and data lineage manually).</p></li><li><p><strong>Integrate data risk signals into existing IT/security workflows</strong> (ticketing/automation) so remediation doesn&#8217;t require a new operational process for every finding.</p></li></ol><h4>Differentiation and Competitive Novelty</h4><ul><li><p><strong>Brain over the stack positioning:</strong> Omni DLP is explicitly framed as augmenting, not replacing, existing DLP enforcement points, which can fit enterprises that already standardized on Microsoft,SSE/SASE,email,endpoint and SaaS controls.</p></li><li><p><strong>DSPM-to-DLP linkage:</strong> Uses sensitive data discovery and classification and access context as a first-class input to DLP alert quality and prioritization (differentiates vs. DLP approaches that rely primarily on inline content inspection without strong enterprise-wide data inventory).</p></li><li><p><strong>Operational emphasis on triage and tuning cycles:</strong> Compresses tuning cycles and improves confidence in enforcement decisions by using richer context and analytics over alerts/policies.</p></li><li><p><strong>Platform remediation orientation:</strong> Converting findings into actions via guardrails and audit trails and workflow integrations rather than stopping at visibility.</p></li></ul><p><strong>SACR Key take away:</strong></p><p>Cyera is best fit for CISOs who already have meaningful DLP enforcement deployed (Microsoft/SSE/email/endpoint/SaaS controls) but are dissatisfied with signal quality, triage workload, and the lack of data-context-driven prioritization OR are starting their DLP program and seeking to establish baseline policies without incurring long tuning cycles. Shortlist Cyera when the goal is to make DLP operationally viable by anchoring decisions in sensitive data truth (discovery and classification and access context) and orchestrating remediation through existing workflows, rather than pursuing a single-vendor rip-and-replace.</p><h2>Microsoft</h2><p>(Microsoft Purview DLP)</p><p><strong>Vendor Profile</strong></p><p>Microsoft&#8217;s DLP capabilities are primarily delivered as part of the Purview data security platform positioned as the default data protection control for Microsoft 365&#8211;centric enterprises that need to reduce accidental oversharing and policy violations across collaboration, email, and endpoints. Its center of gravity in DLP is native platform DLP which uses a centralized policy model administered in Purview, applied across core Microsoft 365 workloads (e.g., Exchange, SharePoint, OneDrive, Teams, Agent 365, Copilot) and extended to endpoints and some browser-mediated workflows via Endpoint DLP and related browser capabilities. It positions this as a way to build a layered protection strategy that spans cloud, endpoint, browser, and network. It addresses M365 environments by being built directly into its productivity suite, Purview is also one of the only solutions that works within the compliance boundaries of that productivity suite. In the Great DLP Reset framing, Microsoft is strongest when the environment is already anchored in Microsoft identity, productivity, and compliance workflows, while cross-SaaS and non-Microsoft enforcement breadth (although it has consistently expanded for the last 2 years) can require additional products or complementary vendors.</p><h3><strong>Products/Services Overview</strong></h3><ul><li><p>Microsoft Purview Data Loss Prevention: Centralized creation and management of DLP policies, applied across supported Microsoft 365 locations, on-prem file shares and Microsoft Fabric for structured data and user activities; uses deep content analysis and policy actions (conditions and actions) for protection and control. Purview now includes  M365, endpoints, Fabric, Copilot, on-prem file shares, browsers, networks, and Copilot Studio/Foundry-built agents.</p></li><li><p><strong>Microsoft 365 workload DLP (Exchange, SharePoint, OneDrive, Teams):</strong> DLP coverage across Microsoft 365 collaboration and messaging surfaces in Teams support which includes chat and channel messages (including private channels) under specific licensing, and Teams file-sharing inherits SharePoint and OneDrive controls because of how Teams stores files.</p></li><li><p>Endpoint DLP (Part of overall Microsoft Purview Data Loss Prevention): Extends DLP monitoring and enforcement to Windows 10/11 and macOS (latest major versions) devices, Windows servers and network shares once onboarded, with visibility in Activity Explorer and enforcement through DLP policies.</p></li><li><p><strong>Edge for Business for Cloud Apps</strong>: Inline data loss prevention is directly built into Edge for Business for real-time text/file upload scenarios, such as AI prompts &amp; responses; it also supports data protection controls for unmanaged device and BYOD scenarios via Edge.</p></li><li><p><strong>Browser-related extension and controls:</strong> Microsoft Purview extensions to extend Endpoint DLP capabilities into Edge, Chrome, Safari and Firefox on Windows devices.</p></li><li><p><strong>DLP for Copilot interactions:</strong> Microsoft provides capabilities to apply Purview DLP to protect interactions with Microsoft 365 Copilot and Copilot Chat, Copilot Studio Agents as well as pre-built agents in Copilot.</p></li><li><p>Shared classification foundations (within Purview): DLP conditions can incorporate Microsoft Purview Information Protection elements such as sensitive information types (including out-of-box and customer-defined) and trainable classifiers (Names Entities, EDM, Fingerprinting, OCR, etc) in supported locations.</p></li></ul><h4><strong>Market Category</strong></h4><p>Integrated DLP</p><h4><strong>Market Sub-Category</strong></h4><p>Productivity-suite/native platform</p><h4><strong>Great DLP Reset alignment</strong></h4><p>Hybrid</p><p>Microsoft aligns to the Great DLP Reset primarily as a native control plane with multiple enforcement points anchored in the Microsoft estate. It represents the pragmatic reset path for Microsoft-first enterprises: leverage existing classification, compliance administration, and identity context to apply DLP policy across collaboration and messaging, then extend to endpoints and browser workflows. The main tradeoff is that while Microsoft can deliver fast value inside the M365 boundary, modern DLP programs frequently need consistent enforcement and remediation across non-Microsoft SaaS, cloud data platforms, and new AI workflows; native integration with both secure browsers and SSE/SASE(which Microsoft supports) to detect and intercept sensitive data in flight to 3rd party AI apps (at the web traffic layer).  Those broader requirements can increase complexity or drive a fill the gaps strategy with SSE/SASE, SaaS-first remediation, or DSPM-led tools. With Enterprise AI Microsoft offers built-in data security and compliance controls for M365 Copilot, Copilot Chat, Copilot Studio-built agents, and Foundry-built agents; adoptees can also choose to leverage their SDK to extend Purview data security and compliance controls to their own proprietary apps and agents.</p><h4><strong>Core Functions and Use Cases</strong></h4><ul><li><p><strong>Microsoft 365 collaboration and email DLP:</strong> Reducing oversharing and inappropriate transmission of sensitive data in Exchange and collaboration repositories, with enforcement tied to content and policy conditions.</p></li><li><p><strong>Endpoint data-in-use visibility and control:</strong> Monitoring user actions on sensitive items on managed endpoints and enforcing protective actions via DLP policies once devices are onboarded.</p></li><li><p><strong>Teams message and file-sharing governance:</strong> Controlling sensitive data sharing in Teams chats and channels and files shared via Teams (leveraging SharePoint and OneDrive storage models).</p></li><li><p><strong>Data protection in the browser via inline &amp; endpoint DLP:</strong> Detecting and blocking sensitive text or files uploading in Edge for Business using built-in inline data protection controls, without extensions or device onboarding. Extending enforcement and monitoring for sensitive item access, pasting, or uploading capabilities (for example cloud-app DLP scenarios) in Windows via the Purview extension for organizations using Edge, Chrome or Safari.</p></li><li><p><strong>AI-era coverage in Microsoft surfaces:</strong> Applying DLP policy to interactions with Microsoft 365 Copilot, Copilot Chat, and Copilot Studio agents. The Purview SDK is available to extend Purview policies to proprietary or custom-built AI apps &amp; agents</p></li></ul><h3><strong>Use Cases and Pain Points Addressed</strong></h3><ol><li><p><strong>Preventing regulated data sharing via Exchange email:</strong> Use of DLP policy conditions and actions for Exchange to identify sensitive items and enforce outcomes matters because email remains a high-frequency exfiltration channel with strong compliance implications.</p></li><li><p><strong>Reducing oversharing in SharePoint, OneDrive, Teams file workflows:</strong> Apply DLP to documents in collaboration stores and the sharing workflows that expose them matters because collaboration-first is a primary leakage mode.</p></li><li><p>Monitoring and preventing risky endpoint actions on sensitive items: Endpoint DLP extends DLP from cloud workloads to local device behavior and provides centralized visibility in Activity Explorer (now available directly in DSPM) which matters for data-in-use risks and local exfiltration paths.</p></li><li><p>Extending policy to browser upload and access attempts on Windows: Using the Purview extension to monitor and enforce attempts to access or upload sensitive items to cloud services in Chrome matters because so many SaaS interactions happen in the Chrome browser even in very Microsoft-centric environments. Microsoft can also block inline text/file uploads in the Chrome browser (including prompts and responses) via network DLP. Microsoft can also apply differentiated protections on endpoints for apps, web domains and peripheral devices like USB, printers.</p></li><li><p><strong>Applying DLP to Copilot interactions:</strong> Using Purview DLP to protect interactions with Microsoft 365 Copilot and Copilot Chat matters because AI workflows introduce non-file leakage paths that often sit inside productivity surfaces.</p></li></ol><h3><strong>Differentiation and Competitive Novelty</strong></h3><ul><li><p><strong>Ecosystem-native control plane:</strong> Purview&#8217;s differentiation is tight integration with the Microsoft 365 administrative and compliance plane, letting Microsoft-first organizations govern core collaboration and messaging surfaces without introducing a separate DLP stack for those channels.</p></li><li><p><strong>Unified policy administration across multiple Microsoft locations:</strong> Microsoft emphasizes centralized policy management and unified alerting and remediation within the Purview portal for buyers, the practical value is reduced console sprawl inside the Microsoft estate.</p></li><li><p>Broad coverage across enterprise apps and devices when standardized on Microsoft Purview where DLP spans Microsoft 365 plus endpoints (Windows and macOS) and browser pathways. This contrasts with point products that begin as SaaS-first remediation or browser-only enforcement.</p></li><li><p><strong>Integration with adjacent Purview capabilities:</strong> Microsoft highlights alignment with Information Protection (labels and SITs) and Insider Risk Management (adaptive protection concepts), which can be attractive where governance and risk programs are already Microsoft-aligned.</p></li></ul><p><strong>SACR Key take away:</strong></p><p>Microsoft Purview DLP is a strong default shortlist for Microsoft&#8211;centric organizations that want fast, centralized policy control across Exchange, SharePoint, OneDrive, and Teams, with a clear path to extend controls to endpoints and selected browser workflows. It tends to be most effective when the organization accepts Microsoft&#8217;s governance model and can operationalize endpoint onboarding and sustained policy tuning.</p><h2>Netskope</h2><h3>Vendor Profile</h3><p>Netskope is a cloud security platform vendor best known for Security Service Edge (SSE/SASE) capabilities (secure web gateway, CASB, ZTNA) with DLP embedded as a core control for protecting sensitive data moving across web and cloud application traffic (In-Motion and At-Rest). In DLP, Netskope&#8217;s center of gravity is inline enforcement (real-time control when traffic is steered through Netskope) combined with API-based SaaS and IaaS controls (out-of-band scanning and remediation for sanctioned apps). This dual-mode approach targets a practical enterprise reality where some DLP outcomes require real-time blocking (e.g., upload prevention) or coaching, while other outcomes prioritize fast deployment and at-rest governance in SaaS via APIs.</p><h2>Products/Services Overview</h2><ul><li><p><strong>Cloud-delivered DLP (within Netskope One / Intelligent SSE):</strong> Content inspection and policy enforcement for sensitive data moving through web and cloud app traffic, typically administered as part of the broader SSE control plane.</p></li><li><p><strong>Inline DLP enforcement (proxy-based):</strong> Real-time inspection and control for web and SaaS transactions when traffic is routed through Netskope (forward and/or reverse proxy patterns).</p></li><li><p><strong>API-based or Connector based for SaaS, IaaS and OnPrem datastores</strong>: Out-of-band API and connectors into sanctioned SaaS, IaaS and on-premises data stores and services to discover and classify data at rest, detect policy violations, and take policy actions (noting that enforcement is inherently after-the-fact versus inline).</p></li><li><p><strong>DLP detection techniques:</strong> Support for multiple detection approaches such as dictionaries/identifiers, proximity analysis, OCR, fingerprinting for text and images as well as File classifiers for a set of images and texts (i.e. source code or passports), and exact match style approaches.</p></li><li><p><strong>Policy action set:</strong> actions can include alerting and various remediation controls including user coaching, adjusting permissions, or protection with MIP.</p></li><li><p><strong>Endpoint DLP (as an add-on capability):</strong> Endpoint-focused controls for preventing sensitive content transfer to channels such as USB storage devices, printers, Bluetooth, and similar device-control scenarios, positioned as leveraging Netskope&#8217;s DLP profiles and rules with endpoint control policies.</p></li><li><p>Email DLP (as an add-on capability): Focus on SMTP email traffic leveraging Netskope&#8217;s DLP profiles and rules to safeguard data.</p></li><li><p><strong>AI security / AI Gateway (adjacent):</strong> AI Gateway and Agentic Broker that can apply DLP as part of policy enforcement for app-to-app (i.e. MCP) traffic between AI agents, apps and LLMs (deployable as a virtual appliance). This is relevant when buyers want DLP policies to extend into AI usage patterns.</p></li><li><p><strong>Data Lineage (as an add-on capability): </strong>Provides comprehensive visibility into the provenance, movement, and usage of data across cloud, web, endpoint, and AI applications visually with data lineage graph.</p></li><li><p><strong>DLP On Demand: </strong>Allows developers via REST APIs to integrate data protection into custom apps and workloads. It supports secure, local processing of structured/unstructured data. Deployment options include an appliance in IaaS (AWS, Azure, GCP) or on-premises (VMware, Hyper-V, KVM).</p></li></ul><h3>Market Category</h3><p>Integrated DLP</p><h4>Market Sub-Category</h4><p>SSE/SASE-integrated</p><p><strong>Great DLP Reset Alignment</strong></p><p>Hybrid</p><p>Netskope aligns to the Great DLP Reset as a distributed enforcement vendor anchored in SSE/SASE as it provides a real-time enforcement plane via inline proxy control for web and SaaS traffic, while also offering out-of-band SaaS and API governance for data at rest and collaboration risk in sanctioned applications, IaaS and on-premises repositories. This maps to the reset&#8217;s core tradeoff: inline enforcement can deliver strong prevention outcomes but introduces steering/decryption and ongoing tuning burdens but API-based SaaS controls can be faster to deploy and useful for at-rest remediation, but inherently have after-the-fact characteristics and app-dependent action depth. This is complemented by Netskope DLP Endpoint, DLP Email and the integration of DLP into Enterprise Browser to provide deployment and enforcement options. Netskope&#8217;s architecture is often most compelling when the organization wants a single policy narrative spanning both modes as well as a unified view on data and incident management.</p><h3>Core Functions and Use Cases</h3><ul><li><p><strong>Real-time prevention for web,SaaS and email traffic:</strong> Stopping or controlling sensitive data movement during in-flight web/SaaS/email interactions (uploads, posts and downloads) where real-time outcomes are needed.</p></li><li><p><strong>SaaS/API/IaaS/On-Premises governance and remediation:</strong> Scanning content already resident in sanctioned SaaS services, identifying sharing violations or sensitive content exposure, and executing supported remediation actions.</p></li><li><p><strong>Unified policy administration across enforcement modes:</strong> Applying consistent data protection policies across both inline and API surfaces to reduce policy fragmentation.</p></li><li><p><strong>Endpoint-adjacent controls (select scenarios):</strong> Preventing sensitive content from moving to removable media or peripheral channels (USB/print/Bluetooth), for organizations that want endpoint controls under the same security umbrella.</p></li><li><p><strong>AI-era data controls (where adopted):</strong> Extending data protection intent into AI usage patterns via Netskope&#8217;s AI security constructs (requires careful scoping and many buyers treat this as a separate workstream).</p></li></ul><h3>Use Cases and Pain Points Addressed</h3><ol><li><p><strong>Blocking sensitive uploads to cloud storage or SaaS in real time:</strong> Inline enforcement can prevent an upload before it completes, reducing the exposure window that exists in out-of-band API scanning models. This matters for high-risk workflows where detect and remediate later is not acceptable. Enforcement spans to Enterprise Browser, ZTNA, Cloud Firewall and Email.</p></li><li><p><strong>Detecting and remediating sensitive data at rest in sanctioned SaaS apps:</strong> API connections can scan existing content and enforce policy actions within supported apps, which matters for collaboration sprawl and legacy content already present in SaaS repositories.</p></li><li><p><strong>Reducing false positives for regulated identifiers via higher-precision matching options:</strong> Techniques such as exact match datasets and fingerprinting are designed to reduce over-triggering in environments where pattern matches alone are noisy.</p></li><li><p><strong>Controlling exfiltration to removable media and peripherals:</strong> Endpoint DLP use cases around USB storage and peripheral channels matter in regulated industries and insider-risk scenarios where local exfiltration paths remain a top concern.</p></li><li><p><strong>Coaching  and justification (nudge) patterns for unsanctioned app usage (DLP-adjacent governance):</strong> Offers policy-driven user coaching and justifications for accessing unsanctioned apps.Which complement DLP since it can reduce shadow IT pathways that become data-loss channels.</p></li></ol><h4>Differentiation and Competitive Novelty</h4><ul><li><p><strong>Dual-mode SSE DLP strategy:</strong> The combination of inline real-time enforcement plus API-based SaaS governance allows buyers to choose enforcement surfaces by risk scenario and operational feasibility.</p></li><li><p><strong>Large-scale private edge infrastructure (NewEdge):</strong> Netskope&#8217;s ability to run real-time security services at scale is part of the DLP value proposition for latency-sensitive inline enforcement (buyers should validate performance in their geographies and traffic patterns).</p></li><li><p><strong>Breadth of cloud app context typical of CASB heritage:</strong> Strong alignment to SaaS instance awareness and activity context, which can improve policy precision compared to network-only DLP approaches.</p></li><li><p><strong>Precision classification tooling (AI based file classification/fingerprinting/exact match/OCR):</strong> These mechanisms can be important in large enterprises with heavy compliance regimes, though operational overhead and efficacy should be validated rather than assumed.</p></li><li><p><strong>Platform integration surface (Cloud Exchange):</strong> Positioning for integration with third-party tools and workflows, relevant for SOC integration and evidence to operations pipelines.</p></li></ul><p><strong>SACR Key take away:</strong></p><p>Netskope is a strong shortlist candidate for enterprises that are adopting (or rationalizing toward) SSE/SASE and want DLP integrated into the same real-time enforcement plane, while also maintaining API-based governance for sanctioned SaaS content at rest. It is best-fit when the organization can commit to the operational prerequisites of inline control (steering, decryption strategy, exception governance) and wants one policy approach spanning both inline and API modes.</p><h2>Palo Alto Networks</h2><h3>Vendor Profile</h3><p>Palo Alto Networks positions Enterprise DLP as an integrated component of a broader security platform, with a center of gravity in AI-powered classification, inline prevention and centralized policy administration. The product story is strongest when the buyer&#8217;s goal is to enforce consistent data protection policies wherever data moves, especially across web, SaaS, and AI-driven workflows and SaaS usage through a single control plane, rather than deploying a standalone DLP suite. Palo Alto Networks is typically evaluated in programs where organizations are already modernizing toward SSE/SASE  architectures, where DLP becomes embedded directly into traffic paths and user workflows rather than bolted on post-facto.</p><h3>Products/Services Overview</h3><p>Palo Alto Networks&#8217; DLP capability set is oriented around:</p><ul><li><p>AI-powered discovery and classification  utilizing 1,000+ machine learning and LLM-based classifiers for structured and unstructured data</p></li><li><p>Centralized policy definition and management for sensitive data controls</p></li><li><p>Inline inspection and enforcement across all data-in-motion vectors including web, SaaS, email, endpoints, and on-premises networks (traffic-path enforcement)</p></li><li><p>Multi-channel coverage that extends across data-in-motion, Data-at-rest, and data -in-use via platform integrations.</p></li><li><p>Incident workflow and operational handling (alerting, triage, escalation, and integration into security operations processes)</p></li><li><p>Support for common DLP actions (block, quarantine, encrypt, redact and sanitize patterns, and related preventative or corrective actions depending on channel)and end-user coaching/remediation notifications.</p></li><li><p>Governance-oriented outcomes: auditability, reporting, and consistent application of policy intent across the enforced surfaces</p></li></ul><h4>Core Market Category</h4><ul><li><p><strong>Integrated DLP (delivered inside a broader platform)</strong></p></li></ul><h4>Market Sub-Category</h4><ul><li><p><strong>SSE/SASE-Integrated DLP</strong></p></li></ul><h4>Great DLP Reset Alignment</h4><p><strong>Inline SSE/SASE enforcement (data-in-motion)</strong></p><p>Palo Alto Networks aligns to the Great DLP Reset primarily as a modern in-motion control point vendor where DLP is delivered as a centralized control plane enforced through the SSE/SASE inline traffic path for  web, SaaS, AI-workflows, email, endpoints, and on-premises networks, rather than classic perimeter appliances or endpoint-only programs. In the storyline, PANW represents the shift to enforcing policy where data actually moves in SaaS-heavy and hybrid work environments. The tradeoff PANW embodies is high-leverage, enforceable prevention breadth in exchange for the operational realities of in-line programs (steering and decryption decisions, policy tuning, and ongoing exception management). PANW is therefore best framed as the SSE/SASE enforcement engine in a modern DLP architectures.</p><h3>Core Functions and Use Cases</h3><ul><li><p><strong>Inline protection for </strong> web, SaaS, AI-workflows, email, endpoints, and on-premises networks<strong> </strong>: Detect and stop sensitive data exfiltration in real-time across all primary traffic paths including web, SaaS, email, endpoints, and on-premises networks</p></li><li><p><strong>Central policy orchestration</strong>: Define policy intent once and apply it consistently across enforced surfaces.</p></li><li><p><strong>Compliance and governance enforcement</strong>: Supports regulated data handling requirements with inspection, enforcement, and evidence trails.</p></li><li><p><strong>Operationalization for security teams</strong>: Integrate DLP signals into incident handling workflows and security operations processes.</p></li></ul><h3>Use Cases and Pain Points Addressed</h3><ol><li><p><strong>Stopping sensitive uploads and sharing through web/SaaS</strong></p></li></ol><blockquote><p>Prevent data leaks via browser-based uploads, web apps, and sanctioned SaaS usage when traffic can be routed through enforcement.</p></blockquote><ol start="2"><li><p><strong>Securing GenAI Adoption: </strong>Visibility into GenAI app usage and blocking sensitive data transfers within AI prompts.</p></li><li><p><strong>Reducing shadow sharing and unsafe collaboration patterns</strong></p></li></ol><blockquote><p>Apply policy guardrails to common user behaviors (sharing externally, uploading to unsanctioned destinations, or moving sensitive files into risky contexts).</p></blockquote><ol start="3"><li><p><strong>Protecting regulated identifiers and sensitive business data</strong></p></li></ol><blockquote><p>Enforce controls for PII/PHI/PCI patterns and other sensitive data classes with consistent handling and reporting.</p></blockquote><ol start="4"><li><p><strong>Establishing auditable controls (governance and defensibility)</strong></p></li></ol><blockquote><p>Provide traceability for why something was detected or blocked and how policy was applied, useful for audit readiness and post-incident review.</p></blockquote><ol start="5"><li><p><strong>Extending DLP into emerging AI-era workflows</strong></p></li></ol><blockquote><p>Address data exposure risk created by GenAI usage patterns.</p></blockquote><h3>Differentiation and Competitive Novelty</h3><ul><li><p><strong>DLP as part of a broader control plane</strong>: The main differentiator is platform consolidation, DLP isn&#8217;t an isolated tool, it&#8217;s a one policy-driven enforcement layer in a larger security stack.</p></li><li><p><strong>Inline enforcement strength</strong>: Palo Alto Networks is typically compelling when buyers prioritize deterministic prevention in the path over purely out-of-band scanning.</p></li><li><p><strong>Enterprise operational fit</strong>: Strong fit for organizations that already run large-scale network/security programs and want DLP to align with existing security architecture decisions.</p></li></ul><p><strong>SACR Key take away:</strong></p><p>Palo Alto Networks is best viewed as a high-confidence choice for organizations that want DLP to be an enforceable, centralized control embedded in their broader security platform, especially when web and SaaS traffic-path enforcement is a strategic priority. The tradeoff is that success depends on operational readiness and steering/inspection decisions, policy discipline, and sustained program ownership. For CISOs, the decision is about whether they are prepared to run DLP as a program in the traffic path, where the payoff is broad prevention leverage.</p><h2>Proofpoint</h2><h3>Vendor Profile</h3><p>Proofpoint is a cybersecurity vendor best known for protecting people and communications, with a long-standing center of gravity in email security and adjacent compliance and governance. In DLP, Proofpoint positions its capabilities around reducing data loss driven by employee behavior, compromised accounts, and misdirected communication, with coverage spanning email and expanding into cloud/SaaS and endpoint-oriented controls as part of a broader people-centric data security and governance narrative.</p><h3>Products/Services Overview</h3><ul><li><p><strong>Enterprise Data Loss Prevention (Enterprise DLP):</strong> A multi-channel DLP capability intended to apply common detectors/classifiers across channels and support unified alerting/investigation workflows.</p></li><li><p><strong>Email Data Loss Prevention (Email DLP / Adaptive Email DLP):</strong> Outbound email-focused DLP controls positioned to detect and prevent sensitive data leakage in email bodies and attachments, Proofpoint also emphasizes behavior and relationship context for misdirected email risk in its narrative material.</p></li><li><p><strong>Endpoint Data Loss Prevention:</strong> Endpoint-focused monitoring and prevention for risky file activity (Proofpoint frames Endpoint DLP as a subset of its Insider Threat Management capability set).</p></li><li><p><strong>Insider Threat Management (ITM):</strong> Insider-risk oriented visibility, context, and analysis that is positioned to accelerate investigation and response for user-driven data loss scenarios.</p></li><li><p><strong>Web Security (with DLP-adjacent controls):</strong> Proofpoint describes web protection and integrated DLP use cases such as controlling uploads to personal webmail and unapproved SaaS and using browser isolation to constrain risky interactions (copy/paste, uploads/downloads) depending on configuration.</p></li><li><p><strong>Data Security Posture Management (DSPM):</strong> Proofpoint markets DSPM-style discovery and classification and remediation controls as part of a broader data security portfolio which includes AI Autonomous Classifiers and agentless scanning.</p></li></ul><h3>Market Category</h3><p>Enterprise DLP</p><h3>Market Sub-Category</h3><p>Email-security-integrated</p><h3>Great DLP Reset Alignment</h3><p>Proofpoint aligns to the DLP reset storyline primarily as an email-heritage vendor expanding DLP into a broader, multi-channel program anchored on people and communications with a narrative emphasizing reducing analyst burden by correlating content detections with user and behavioral context and investigation workflows while extending enforcement beyond email into cloud and endpoint coverage as needed. The architectural tradeoff for many buyers is that Proofpoint&#8217;s strengths often show up fastest where email and user communications risk is central (and where Proofpoint is already deployed).</p><h3>Core Functions and Use Cases</h3><ul><li><p><strong>Email exfiltration prevention and mis-send risk reduction:</strong> Reduce sensitive data leakage through outbound email, including attachments and addressed recipients.</p></li><li><p><strong>Insider-driven data loss detection and investigation:</strong> Add user and activity context to data-loss events to help triage negligent vs. malicious vs. compromised-user scenarios.</p></li><li><p><strong>Multi-channel policy extension (where deployed):</strong> Apply consistent classifiers and detectors across multiple channels (email plus cloud and endpoint) to reduce one-off policy silos.</p></li><li><p><strong>Compliance-driven monitoring and evidence:</strong> Support monitoring and investigative evidence needed for regulated data movement.</p></li></ul><h3>Use Cases and Pain Points Addressed</h3><ol><li><p><strong>Prevent sensitive data from leaving via outbound email</strong>: Enabled by email content inspection and policy-based enforcement which matters because email remains a high-frequency exfiltration path and a common source of accidental exposure.</p></li><li><p><strong>Reduce misdirected-email incidents</strong>: Enabled by behavioral and relationship-oriented signals (as described in Proofpoint&#8217;s adaptive narrative) which matters because misaddressed messages are a frequent, hard to train-away failure mode.</p></li><li><p><strong>Consolidate alerting and investigations across channels:</strong> Enabled by unified alert and investigation interface and reusable detectors which matters because cross-channel incidents otherwise require multiple consoles and manual correlation.</p></li><li><p><strong>Endpoint file-activity prevention for everyday users</strong>:  Enabled by endpoint DLP controls positioned to detect and prevent risky file activity which matters because endpoint actions (copying, staging, syncing) often precede broader exfiltration.</p></li><li><p><strong>Constrain risky web interactions (select use cases)</strong>: Enabled by web security plus isolation patterns which matters for controlling uploads and downloads and limiting data movement to personal webmail or unapproved SaaS in some operating models.</p></li></ol><h3>Differentiation and Competitive Novelty</h3><ul><li><p><strong>Email-security-led DLP integration:</strong> Proofpoint&#8217;s DLP is commonly evaluated in conjunction with its email security footprint which can reduce deployment friction for outbound email controls compared to new stack DLP rollouts.</p></li><li><p><strong>People/behavior context as a first-class narrative:</strong> Proofpoint emphasizes correlating content findings with behavior and threat context to speed triage and clarify intent (different from purely content-centric DLP operating models).</p></li><li><p><strong>Detector reuse across channels:</strong> Proofpoint provides a library of detectors and classifiers that can be applied across channels, aiming to reduce per-channel policy rebuild effort.</p></li></ul><p><strong>SACR Key take away:</strong></p><p>Proofpoint is a strong shortlist candidate when outbound email risk, misdirected communication, and people-driven data loss are central to the threat model, especially for organizations already standardized on Proofpoint for email security and looking to extend DLP with consistent detectors and more contextual investigations. For CISOs modernizing DLP, the goal is to evaluate coverage across the exact channels that matter in your environment (priority SaaS apps, endpoints, web, and any AI-related workflows) and confirm the operational model for triage and remediation across teams.</p><h1>DLP Vendor Market Map</h1><p>This section provides a broader landscape view of DLP vendors beyond the profiled set, organized by the market-evolution phases described earlier. The goal is not to force a single winner list, but to show where different products typically anchor (classic suite enforcement, inline and SSE control points, discovery-led control planes, or AI-era and runtime controls) so buyers can quickly shortlist options that match their environment, deployment constraints, and maturity stage. Vendor placement is directional: many offerings span phases, but most have a primary center of gravity based on how they deliver first value and where they require the most operational investment.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!DAlq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F364a08c6-f65d-42e9-aba9-ec4d4d62f8ab_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!DAlq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F364a08c6-f65d-42e9-aba9-ec4d4d62f8ab_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!DAlq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F364a08c6-f65d-42e9-aba9-ec4d4d62f8ab_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!DAlq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F364a08c6-f65d-42e9-aba9-ec4d4d62f8ab_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!DAlq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F364a08c6-f65d-42e9-aba9-ec4d4d62f8ab_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!DAlq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F364a08c6-f65d-42e9-aba9-ec4d4d62f8ab_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/364a08c6-f65d-42e9-aba9-ec4d4d62f8ab_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1406583,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://softwareanalyst.substack.com/i/194969072?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F364a08c6-f65d-42e9-aba9-ec4d4d62f8ab_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!DAlq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F364a08c6-f65d-42e9-aba9-ec4d4d62f8ab_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!DAlq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F364a08c6-f65d-42e9-aba9-ec4d4d62f8ab_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!DAlq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F364a08c6-f65d-42e9-aba9-ec4d4d62f8ab_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!DAlq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F364a08c6-f65d-42e9-aba9-ec4d4d62f8ab_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Note:</strong> SACR vendor writeups below are intentionally directional. Where SACR has first-party briefing notes or public engineering and deployment documentation, the description is firmer. Where some sources are primarily marketing, wording and positions are conditional.</p><h2><strong>Practical Recommendations for CISO&#8217;s and Practitioners</strong></h2><p><strong>Buyer Starting Point Decision Tree</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!mOBS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8250a088-1519-4b80-b8ec-21363fb7c0ac_1600x900.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!mOBS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8250a088-1519-4b80-b8ec-21363fb7c0ac_1600x900.jpeg 424w, https://substackcdn.com/image/fetch/$s_!mOBS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8250a088-1519-4b80-b8ec-21363fb7c0ac_1600x900.jpeg 848w, https://substackcdn.com/image/fetch/$s_!mOBS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8250a088-1519-4b80-b8ec-21363fb7c0ac_1600x900.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!mOBS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8250a088-1519-4b80-b8ec-21363fb7c0ac_1600x900.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!mOBS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8250a088-1519-4b80-b8ec-21363fb7c0ac_1600x900.jpeg" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8250a088-1519-4b80-b8ec-21363fb7c0ac_1600x900.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!mOBS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8250a088-1519-4b80-b8ec-21363fb7c0ac_1600x900.jpeg 424w, https://substackcdn.com/image/fetch/$s_!mOBS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8250a088-1519-4b80-b8ec-21363fb7c0ac_1600x900.jpeg 848w, https://substackcdn.com/image/fetch/$s_!mOBS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8250a088-1519-4b80-b8ec-21363fb7c0ac_1600x900.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!mOBS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8250a088-1519-4b80-b8ec-21363fb7c0ac_1600x900.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>DLP Reset Program Focus Recommendations by phase</strong></h3><ul><li><p><strong>Phase 0 (classic):</strong> Retain for regulated identifiers and mature endpoint and network needs, but constrain scope and staffing expectations, refresh and integrate to advance to later phases.</p></li><li><p><strong>Phase 1 (SaaS and cloud sprawl):</strong> Prioritize SaaS-first enforcement and remediation in the noisiest collaboration channels.</p></li><li><p><strong>Phase 2 (control plane):</strong> Invest in discovery and classification and the addition of identity and entitlement context, then focus on automated remediation and workflows where possible, or human in loop for exception handling or deeper triage and remediation validation (if needed).</p></li><li><p><strong>Phase 3 (AI-era):</strong> Implement explicit prompt and agent controls and browser and session last-mile controls with strong logging and ideally mapping data lineage from end (source) to end (destination).</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!64zc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc65d30c1-c484-47bc-8016-7ccb75b9594e_1600x900.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!64zc!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc65d30c1-c484-47bc-8016-7ccb75b9594e_1600x900.jpeg 424w, https://substackcdn.com/image/fetch/$s_!64zc!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc65d30c1-c484-47bc-8016-7ccb75b9594e_1600x900.jpeg 848w, https://substackcdn.com/image/fetch/$s_!64zc!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc65d30c1-c484-47bc-8016-7ccb75b9594e_1600x900.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!64zc!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc65d30c1-c484-47bc-8016-7ccb75b9594e_1600x900.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!64zc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc65d30c1-c484-47bc-8016-7ccb75b9594e_1600x900.jpeg" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c65d30c1-c484-47bc-8016-7ccb75b9594e_1600x900.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!64zc!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc65d30c1-c484-47bc-8016-7ccb75b9594e_1600x900.jpeg 424w, https://substackcdn.com/image/fetch/$s_!64zc!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc65d30c1-c484-47bc-8016-7ccb75b9594e_1600x900.jpeg 848w, https://substackcdn.com/image/fetch/$s_!64zc!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc65d30c1-c484-47bc-8016-7ccb75b9594e_1600x900.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!64zc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc65d30c1-c484-47bc-8016-7ccb75b9594e_1600x900.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Actionable Security Program Steps for CISOs and Security Leaders</strong></h2><ol><li><p><strong>Establish the truth layer first (discovery + classification)</strong></p><ul><li><p><strong>Implementation considerations:</strong> prioritize highest-risk SaaS and cloud data stores, define sensitivity taxonomy.</p></li><li><p><strong>Success metrics:</strong> % of sensitive data discovered and classified, time-to-first-signal.</p></li><li><p><strong>Timeline:</strong> Weeks for initial coverage; ongoing for expansion.</p></li></ul></li><li><p><strong>Map your enforcement surfaces to real runtime environments</strong></p><ul><li><p><strong>Implementation considerations:</strong> Decide where API actions suffice vs where inline SSE or endpoint is necessary.</p></li><li><p><strong>Success metrics:</strong> % of high-risk channels covered by enforceable controls.</p></li><li><p><strong>Timeline:</strong> 1&#8211;2 quarters depending on steering and endpoint roll out.</p></li></ul></li><li><p><strong>Reduce policy burden with context-rich decisions</strong></p><ul><li><p><strong>Implementation considerations:</strong> Integrate identity, entitlements, sharing posture, and behavioral signals to manage insider risk and reduce false positives in triage and policy.</p></li><li><p><strong>Success metrics:</strong> False positive rate, analyst time per incident.</p></li><li><p><strong>Timeline:</strong> Incremental, measurable within 30&#8211;60 days post integration.</p></li></ul></li><li><p><strong>Prioritize automated remediation and prevention over alerting</strong></p><ul><li><p><strong>Implementation considerations:</strong> start with reversible actions (warn and revoke link), then escalate to redact,delete,quarantine.</p></li><li><p><strong>Success metrics:</strong></p><ol><li><p>Mean time to remediate (MTTR) and mean time to prevention</p></li><li><p>% incidents auto-remediated</p></li><li><p>Business disruption rate</p></li><li><p>Timeline: 60&#8211;120 days to mature workflows.</p></li></ol></li></ul></li><li><p><strong>Make AI workflow governance explicit</strong></p><ul><li><p><strong>Implementation considerations:</strong> define controls for prompt pasting, Copilot scopes, and agent tool-call logging.</p></li><li><p><strong>Success metrics:</strong></p><ol><li><p>% GenAI apps covered</p></li><li><p>Number of policy-enforced AI events</p></li><li><p>Audit completeness</p></li><li><p>Timeline: 30&#8211;90 days for initial controls depending on surfaces.</p></li></ol></li></ul></li><li><p><strong>Treat browser and session controls as last-mile DLP where needed</strong></p><ul><li><p><strong>Implementation considerations:</strong> Use targeted deployment for high-risk groups and workflows.</p></li><li><p><strong>Success metrics:</strong> reduction in SaaS screenshot, copy, download leakage events.</p></li><li><p><strong>Timeline:</strong> pilot in weeks; expand by cohort.</p></li></ul></li><li><p><strong>Align the program to measurable outcomes</strong> (e.g., compressing MTTR and anchoring the program in quantifiable risk reduction outcomes)</p><ul><li><p><strong>Implementation considerations:</strong> Define risk scenarios (exposed data in SaaS, oversharing to copilots, public repo leaks).</p></li><li><p><strong>Success metrics: </strong>Reduction lower mean time to resolution (MTTR) in exposed sensitive objects, fewer critical exposures, improved evidence trails. (e.g., <em>reduce MTTR</em>, <em>align to measurable outcomes</em>)</p></li><li><p><strong>Timeline:</strong> Ongoing, baseline within a quarter.</p></li></ul></li></ol><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZepC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3edc8f0-4bf6-4add-8493-1912625c45be_1600x900.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZepC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3edc8f0-4bf6-4add-8493-1912625c45be_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!ZepC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3edc8f0-4bf6-4add-8493-1912625c45be_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!ZepC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3edc8f0-4bf6-4add-8493-1912625c45be_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!ZepC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3edc8f0-4bf6-4add-8493-1912625c45be_1600x900.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZepC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3edc8f0-4bf6-4add-8493-1912625c45be_1600x900.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f3edc8f0-4bf6-4add-8493-1912625c45be_1600x900.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ZepC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3edc8f0-4bf6-4add-8493-1912625c45be_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!ZepC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3edc8f0-4bf6-4add-8493-1912625c45be_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!ZepC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3edc8f0-4bf6-4add-8493-1912625c45be_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!ZepC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3edc8f0-4bf6-4add-8493-1912625c45be_1600x900.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>Security Engineering and Architectural Practitioner Guidance</strong></h3><p><strong>First:</strong> Establish the truth layer, then prove remediation in one high-noise channel.</p><p>Start by building a defensible inventory of sensitive data (discovery + classification), then pick a single collaboration channel where risk is visible and operational friction is high (e.g., Drive and SharePoint, Slack and Teams, GitHub) and close the loop with a small set of reversible, automated actions.</p><ul><li><p><strong>Scope:</strong> 1&#8211;3 repositories and apps with the most sensitive data and the most frequent oversharing and exposure patterns.</p></li><li><p><strong>Controls to emphasize:</strong> Classification and evidence trails first; automation second (revoke external links, quarantine, label, owner notification).</p></li><li><p><strong>Success criteria:</strong> Faster time-to-first-signal, measurable reduction in exposed sensitive objects, and a remediation workflow that doesn&#8217;t become a ticket factory.</p></li><li><p><strong>Avoid:</strong> Starting with broad block policies or multi-channel rollouts before you have trusted classification and stable workflows.</p></li></ul><p><strong>Next:</strong> Enrich findings with identity and entitlements context and expand repository coverage.</p><p>Once you can find sensitive data and take consistent action in one channel, add the context required to prioritize what truly matters (who has access, how it was shared, what level of exposure exists) and broaden coverage to the next set of repositories.</p><ul><li><p><strong>Add context:</strong> identity signals (SSO and IdP), group membership, entitlement and access graphs, sharing posture, and (where possible) lineage and audit context.</p></li><li><p><strong>Expand systematically:</strong> Add the next repositories based on risk scenarios (customer data stores, executive collaboration spaces, developer ecosystems).</p></li><li><p><strong>Improve triage:</strong> Drive down false positives and analyst time-per-incident by prioritizing high impact and high exposure findings.</p></li><li><p><strong>Standardize policy intent:</strong> Keep policies consistent as coverage grows (same sensitivity taxonomy, same response ladder).</p></li></ul><p><strong>Then:</strong> introduce heavier enforcement points only where the risk scenario demands it (inline SSE and endpoint).</p><p>Inline and endpoint controls are powerful, but they introduce architectural and operational tax. Add them after discovery-led visibility and remediation are working, and only for scenarios where out-of-band and API actions are insufficient.</p><ul><li><p><strong>Use inline SSE when:</strong> real-time control is mandatory (regulated egress), you need web and SaaS traffic inspection, or you must prevent exfil in-session.</p></li><li><p><strong>Use endpoint controls when:</strong> device-level actions are the dominant exposure path (removable media, local copies, un-managed sync clients, print and screen capture).</p></li><li><p><strong>Pilot with a narrow cohort:</strong> high-risk teams and users, a small set of apps, and a clear warn and block escalation path.</p></li><li><p><strong>Keep the program measurable:</strong> track tuning effort, user friction, and risk reduction so enforcement doesn&#8217;t recreate the classic DLP burden.</p></li></ul><h1><strong>Future View: Emerging DLP Vendors and Trends</strong></h1><p>This section shifts focus to the emerging vendors and new architectural narratives that are shaping the next generation of Data Loss Prevention (DLP). It moves beyond established players to examine startups and specialized platforms that prioritize AI-driven intelligence, rapid time-to-value, and addressing specific high-friction challenges like insider risk and SaaS collaboration leakage. These companies represent the cutting edge of the DLP Reset, often employing agentless models, edge AI, and deeply integrated remediation workflows to deliver measurable risk reduction with minimal operational burden, signaling the future direction of data security control planes.</p><h2>The Great DLP Reset AI and Agentic Transformation</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!R4mp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2baa24f2-27c0-4286-bdb3-48ab921a267b_1600x900.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!R4mp!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2baa24f2-27c0-4286-bdb3-48ab921a267b_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!R4mp!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2baa24f2-27c0-4286-bdb3-48ab921a267b_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!R4mp!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2baa24f2-27c0-4286-bdb3-48ab921a267b_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!R4mp!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2baa24f2-27c0-4286-bdb3-48ab921a267b_1600x900.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!R4mp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2baa24f2-27c0-4286-bdb3-48ab921a267b_1600x900.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2baa24f2-27c0-4286-bdb3-48ab921a267b_1600x900.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!R4mp!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2baa24f2-27c0-4286-bdb3-48ab921a267b_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!R4mp!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2baa24f2-27c0-4286-bdb3-48ab921a267b_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!R4mp!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2baa24f2-27c0-4286-bdb3-48ab921a267b_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!R4mp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2baa24f2-27c0-4286-bdb3-48ab921a267b_1600x900.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Normalized Features Across DLP Vendors (Total of 42 vendors Assessed)</h2><p>The following chart depicts the features across the in-scope Data Loss Prevention providers (total of 42) in SACR exploration of DLP vendors in the market in 2026. The features emphasize compliance oriented mandates such as providing evidence and auditability, classification of data, policy and orchestration features with the fourth priority being automation and remediation.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1iIo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2920c6a-77e0-4664-a7c4-a94ae9ce209c_1600x900.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1iIo!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2920c6a-77e0-4664-a7c4-a94ae9ce209c_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!1iIo!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2920c6a-77e0-4664-a7c4-a94ae9ce209c_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!1iIo!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2920c6a-77e0-4664-a7c4-a94ae9ce209c_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!1iIo!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2920c6a-77e0-4664-a7c4-a94ae9ce209c_1600x900.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1iIo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2920c6a-77e0-4664-a7c4-a94ae9ce209c_1600x900.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a2920c6a-77e0-4664-a7c4-a94ae9ce209c_1600x900.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!1iIo!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2920c6a-77e0-4664-a7c4-a94ae9ce209c_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!1iIo!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2920c6a-77e0-4664-a7c4-a94ae9ce209c_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!1iIo!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2920c6a-77e0-4664-a7c4-a94ae9ce209c_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!1iIo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2920c6a-77e0-4664-a7c4-a94ae9ce209c_1600x900.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Below is a list of key differentiating features SACR found across data loss prevention vendors. The lower end of the features are either emerging capabilities (e.g. net new features) or features not prioritized by all vendors in the market. Features including operations oriented features such as endpoint rollout capabilities, compliance focused features such as templates and compliance packs and ability to perform revoke of sharing links and the ability to perform redact and delete. Emerging areas of stronger client interest for example in AI-era features such as prompt redaction and LLM semantic extraction from content are aligned to our called out AI-era focus. Also noteworthy is JIT coaching (just in time coaching) for guiding users in real-time to tell them how they ought to handle data and auto-tuning, also aligned to our view of future features in the data loss prevention (DLP) market.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!12ys!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefc821a6-da81-4078-b689-e80d302fa88c_1600x900.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!12ys!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefc821a6-da81-4078-b689-e80d302fa88c_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!12ys!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefc821a6-da81-4078-b689-e80d302fa88c_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!12ys!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefc821a6-da81-4078-b689-e80d302fa88c_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!12ys!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefc821a6-da81-4078-b689-e80d302fa88c_1600x900.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!12ys!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefc821a6-da81-4078-b689-e80d302fa88c_1600x900.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/efc821a6-da81-4078-b689-e80d302fa88c_1600x900.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!12ys!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefc821a6-da81-4078-b689-e80d302fa88c_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!12ys!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefc821a6-da81-4078-b689-e80d302fa88c_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!12ys!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefc821a6-da81-4078-b689-e80d302fa88c_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!12ys!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefc821a6-da81-4078-b689-e80d302fa88c_1600x900.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>AI-era DLP is Causing Changes Across Several Key Areas</strong></h3><p>DLP is critical given the massive expansion of sensitive data across SaaS platforms, cloud, AI, AI agents and premises environments, and into centralized repositories like data lakes, all of which present new and complex vectors for data loss. AI is increasingly being used in DLP solutions and being added to the complex architectures used, while also enabling new capabilities in emerging DLP solution features.</p><p>Below is a chart of new emerging classification technologies and their penetration and use by various vendors in our DLP Reset market analysis. Notice that technologies like LLM-based classification and ML semantics have emerged but are lower than traditional rules/regex/pattern style classifiers. This is because these are emerging technologies and capabilities in the latest generation of AI-era tools. We also noted that image recognition, OCR (Optical Character Recognition) and PDF examination was another area of variance between vendors that is often unsupported in some vendors and enforcement channels.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Tb3S!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e698e18-00b6-4d5f-ad43-753d87153081_1600x900.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Tb3S!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e698e18-00b6-4d5f-ad43-753d87153081_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!Tb3S!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e698e18-00b6-4d5f-ad43-753d87153081_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!Tb3S!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e698e18-00b6-4d5f-ad43-753d87153081_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!Tb3S!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e698e18-00b6-4d5f-ad43-753d87153081_1600x900.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Tb3S!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e698e18-00b6-4d5f-ad43-753d87153081_1600x900.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2e698e18-00b6-4d5f-ad43-753d87153081_1600x900.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Tb3S!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e698e18-00b6-4d5f-ad43-753d87153081_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!Tb3S!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e698e18-00b6-4d5f-ad43-753d87153081_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!Tb3S!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e698e18-00b6-4d5f-ad43-753d87153081_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!Tb3S!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e698e18-00b6-4d5f-ad43-753d87153081_1600x900.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>AI-era DLP is evolving in several key areas:</p><ul><li><p><strong>LLM/semantic classification as the new detection engine:</strong> Higher-fidelity classification of unstructured data (docs, chat, code) and fewer brittle regex-only policies.</p></li><li><p><strong>Truth-layer + context becomes mandatory:</strong> Discovery-led inventories (DSPM-style) plus identity, entitlements, and sharing posture help AI and agents decide and take action on what is materially risky.</p></li><li><p><strong>GenAI prompt and output controls (narrow but urgent):</strong> Controls for prompt pasting and uploads, output redaction and masking, and policy-driven warnings and blocks in AI chat and copilots.</p></li><li><p><strong>AI and Agent governance expands the DLP surface area:</strong> Tool-call logging via MCP and platform integrations with Co-Worker and agentic platforms, least-privilege data access for agents, and guardrails that constrain what agents can retrieve/send.</p></li><li><p><strong>Browser and session becomes a first-class enforcement plane:</strong> Last-mile controls over copy/paste, upload and download, printing, and screen capture across SaaS and GenAI workflows.</p></li><li><p><strong>Shift from alerting to automated remediation:</strong> Revoke links, quarantine, redact/delete, label, and other actions that reduce exposure without creating ticket-factory operations.</p></li><li><p><strong>Audit-grade evidence as a competitive wedge:</strong> Investigation-ready timelines (actor, object, action, timestamp, remediation proof) and lineage and provenance where feasible.</p></li></ul><p><strong>Market bifurcation in the near term:</strong></p><ul><li><p><strong>Guardrail point solutions</strong> (prompt, agent and runtime visibility and control) with high relevance but narrower breadth.</p></li><li><p><strong>Broader DLP and control-plane platforms</strong> claiming agentic autonomy and cross-plane orchestration have high upside, but require proof of real enforcement depth and measurable burden reduction.</p></li></ul><p><strong>Longer term expected convergence towards Unified Agentic Defense Platforms</strong> ( see SACR <a href="https://softwareanalyst.substack.com/p/the-convergence-of-ai-and-data-security">UADP report</a>)</p><h1>Emerging DLP Vendors to Watch</h1><p>This section shifts focus to the emerging vendors and specialized platforms that are shaping the next generation of Data Loss Prevention (DLP). These startups prioritize AI-driven intelligence, rapid time-to-first-signal, and addressing high-friction challenges like insider risk and SaaS collaboration and data leakage. By employing agentless models, edge AI, and deeply integrated remediation workflows, these companies deliver measurable risk reduction with minimal operational burden, signaling a future direction of Unified Data Control Planes (UDCP) and control of data (as well as other cybersecurity functions) in the browser or on endpoints.</p><h2>Above Vendor Profile</h2><p>Above Security (Above) positions itself as an AI-native managed insider-risk platform designed to interpret the reconstruction of user intent by correlating signals across identity, endpoint, SaaS, and AI runtimes. The platform aims to reduce operational burden by providing investigation-ready behavioral timelines and delivering coaching-first interventions to shape employee behavior in real time.</p><h3>Products/Services Overview</h3><ul><li><p>Investigator Fleet: Above markets a fleet of specialized investigator agents, including Shadow AI &amp; IT, Data Exfiltration, Flight Risk, and Communications investigators to maintain continuous monitoring of high-risk exfiltration paths. Operational Packaging: Above delivers its investigator fleet as a unified behavioral investigation framework rather than discrete modules, with specific capabilities like inline coaching positioned as specialized functional add-ons.</p></li></ul><h4>Market Category</h4><p>Insider Risk / DDR</p><h4>Market Sub-Category</h4><p>Behavioral Intelligence / Browser-first</p><h4>Great DLP Reset Alignment</h4><p>Hybrid</p><p>Above functions as a hybrid control plane within the DLP Reset framework, utilizing a browser extension combined with sanctioned SaaS APIs for enforcement and telemetry. It offers additional endpoint sensors and GenAI-specific governance capabilities, with an architecture that leverages connectors for Google Workspace, Microsoft 365, Slack, and Workday, augmented by endpoint telemetry from CrowdStrike. The platform claims rapid deployment in minutes without the requirement for manual policy authoring or complex rule configuration.</p><h3>Core Functions and Use Cases</h3><ul><li><p>Continuous discovery and monitoring: Above establishes visibility across SaaS and browser surfaces, including clipboards, downloads, pastes, uploads, shares, OAuth abuse, Shadow SaaS/AI usage, and risky third-party grants, OAuth, and extensions, to correlate disparate events into a single, cohesive investigation.</p></li><li><p><strong>Audit-grade evidence:</strong> The platform produces human-readable timelines and investigation reports designed for Security, HR, and Legal teams to provide proof of intent and remediation.</p></li><li><p><strong>Coaching-first intervention:</strong> Implementation of polite interventions and point-of-violation nudges to guide users away from risky actions without the friction of deterministic blocking.</p></li><li><p><strong>Shadow AI/IT governance:</strong> Explicit focus on identifying and governing emerging AI and IT leakage paths as a core part of the data security program.</p></li></ul><h3>Use Cases and Pain Points Addressed</h3><ul><li><p><strong>Reduce operational burden and alert fatigue</strong> by prioritizing investigation narratives and contextual timelines over simple anomaly detection.</p></li><li><p><strong>Govern emerging AI/IT leakage paths</strong> by continuously monitoring and providing visibility into Shadow AI usage.</p></li><li><p><strong>Drive proactive behavior change</strong> through coaching-first interventions and point-of-violation nudges, reducing accidental and negligent incidents.</p></li><li><p><strong>Accelerate forensic investigations</strong> with audit-grade evidence, human-readable timelines, and proof of intent/remediation for Security, HR, and Legal teams.</p></li><li><p><strong>Achieve rapid time-to-value</strong> with deployment in &#8220;minutes&#8221; and no requirement for manual policy creation.</p></li></ul><h3>Differentiation and Competitive Novelty</h3><ul><li><p><strong>Investigation narrative over alerting:</strong> Above explicitly positions itself as a move away from the ticket factory anomaly detection problem toward intent-driven context.</p></li><li><p><strong>Agentic investigator framing:</strong> Employs purpose-built AI agents to continuously correlate signals and reconstruct forensic timelines autonomously.</p></li><li><p><strong>Coaching-centric posture:</strong> Prioritizes the mitigation of accidental and negligent incidents through behavior modification rather than purely malicious detection.</p></li></ul><p><strong>SACR take-away:</strong></p><p>Above functions primarily as a behavioral intelligence and insider-risk layer, leveraging browser &amp; endpoint-native session visibility across modern work apps and SaaS API enforcement planes to deliver rapid time-to-first-signal and comprehensive evidentiary timelines. The platform is not intended as a replacement for classic inline SSE/SASE/GW network-path controls but serves as a critical truth layer for interpreting user intent in modern work runtimes.</p><h2>Bold Security</h2><h3>Vendor Profile</h3><p>Bold Security is an emerging endpoint-centric data protection platform positioning itself as an AI-era reboot of endpoint DLP and user risk. Its center of gravity is data-in-use control at the user action layer, real-time classification and intervention on endpoints to prevent high-risk behaviors such as copying/uploading sensitive content to unsanctioned destinations and pasting sensitive information into GenAI tools.</p><h3>Products/Services Overview</h3><ul><li><p><strong>Endpoint agent and on-device classification (as positioned):</strong> Continuous analysis of data sensitivity plus user and application interactions to determine risk in real time.</p></li><li><p><strong>User action guardrails:</strong> Coaching, warning and blocking of risky actions before data leaves the device (copy/paste, uploads, screenshots, printing, unmanaged sync, USB).</p></li><li><p><strong>Investigation/evidence layer (as positioned):</strong> Forensic evidence and flow mapping with data lineage.</p></li><li><p><strong>GenAI-era controls (as positioned):</strong> Controls for pasting into AI tools and detecting proprietary data in screenshots/images; validate which AI apps and what actions are enforceable.</p></li></ul><h2><strong>Market Category</strong></h2><p>Endpoint DLP (emerging / AI-era)</p><h2><strong>Great DLP Reset Alignment</strong></h2><p>Hybrid</p><p>Bold aligns to the Great DLP Reset primarily as a last-mile enforcement approach. Rather than relying on traffic steering through inline gateways, it aims to prevent leakage at the moment of use on the endpoint and to reduce operational burden through coaching-first intervention. If its claims hold up, Bold would fit buyers who believe the dominant leakage paths are endpoint- and browser-mediated user actions (including GenAI prompt and upload behaviors). The main architectural questions are how much of a truth layer it provides or integrates with beyond endpoint telemetry and whether it can participate in a broader remediation control plane (revoke links/redact/delete in SaaS), and whether evidence and data lineage outputs are audit-grade.</p><h2><strong>Overall Viability and Execution</strong></h2><p>Execution is likely to go well when organizations want rapid endpoint-centric time-to-first-signal, prioritize prevention and coaching at user action points, and can deploy an endpoint agent broadly with acceptable privacy and performance posture. Execution is likely to be harder where buyers expect broad, cross-channel DLP coverage (SaaS/API, inline SSE/SASE, email) and deep, well-documented classifier and integration ecosystems, because available public materials provide limited confirmation of connector breadth, action depth beyond the endpoint, and evidentiary rigor.</p><h2><strong>Core Functions and Use Cases</strong></h2><ul><li><p><strong>Endpoint data-in-use prevention:</strong> Intervene on risky user actions (copy/upload/paste) before sensitive content leaves the device.</p></li><li><p><strong>GenAI leakage-path controls:</strong> Reduce inadvertent disclosure via prompts/uploads to GenAI tools (validate coverage).</p></li><li><p><strong>User coaching to reduce negligent exposure:</strong> Nudge users away from risky behaviors to lower incident volume.</p></li><li><p><strong>Investigation support via evidence capture:</strong> Provide incident context/evidence suitable for security, compliance, and HR-driven investigations (validate).</p></li></ul><h2><strong>Use Cases and Pain Points Addressed</strong></h2><ol><li><p>Prevent sensitive data from being pasted into AI tools.</p></li><li><p>Reduce accidental exfiltration to personal cloud and unmanaged destinations.</p></li><li><p>Detect sensitive content in screenshots/images (OCR-oriented claim).</p></li><li><p>Produce investigation-ready evidence via forensic context and flow mapping.</p></li></ol><h2><strong>Differentiation and Competitive Novelty</strong></h2><ul><li><p><strong>On-device AI positioning:</strong> Emphasis on local processing and real-time, context-aware classification.</p></li><li><p><strong>Coaching-first and prevention:</strong> Focused on reducing incident volume and operational drag vs alert-heavy DLP programs.</p></li><li><p><strong>Evidence/lineage story:</strong> Positions flow mapping and data lineage as a first-class output.</p></li></ul><h2><strong>SACR Key take away</strong></h2><p>Bold is best treated as an emerging endpoint DLP vendor to monitor or to evaluate in a controlled pilot when endpoint and GenAI user actions are the dominant leakage paths and when the organization wants coaching-first prevention rather than purely detection. Before procurement, validate enforceable actions by channel, classifier transparency and tuning model, evidence schema and chain-of-custody rigor, integration depth into SIEM/case management and any SaaS/API remediation capabilities, and operational burden (deployment, exceptions, performance impact) for a real enterprise environment.</p><h2>Ent  (<a href="http://ent.ai/">Ent.ai</a>)</h2><h3>Vendor Profile</h3><p>Ent is an early-stage vendor that is pursuing intent-aware security oriented around user behavior and endpoint telemetry, with an emphasis on insider-risk-style visibility and intervention for modern data movement (including AI-era misuse scenarios). Ent&#8217;s center of gravity appears closer to endpoint behavioral monitoring and intervention (a form of insider risk / user activity security) than to a traditional enterprise DLP suite with coverage across email, SaaS APIs, and inline network controls.</p><h3>Products/Services Overview</h3><ul><li><p>Intent-aware / behavior-driven security platform</p></li><li><p>Aims to capture user-driven telemetry at the endpoint and use that context to detect risky data handling or insider-risk patterns, intervention models are described as warn/block/guide.</p></li><li><p>Endpoint-focused data interaction visibility, monitoring interactions between the user and the OS (Windows, Mac, Linux),  various applications and websites (with browser extension) to provide context-rich signals (e.g., focus changes, screenshots, i/o changes, copy/paste type events, clicks, i/o changes, etc).</p></li><li><p>Intervention types extend to 20+ configurable, including warn, block, redirect, obfuscate, record, disable network, with user acknowledgement flows</p></li><li><p>Policy/decisioning approach combined with a customizable policy engine concept blending rules and ML/LLM techniques for observability, prevention and time-bound forensic enrollment.</p></li></ul><h3>Market Category</h3><h4>Insider Risk / DDR / Intent-Aware Security</h4><h3>Great DLP Reset alignment (Vendor)</h3><h4>Hybrid</h4><p>Ent maps to the Great DLP Reset primarily as a future bet on richer user and action context and faster, more workflow-native interventions with awareness training, i.e., improving the signal and investigation narrative around how sensitive data is actually being handled by users in modern app workflows, including potential GenAI misuse and click-fix attack scenarios. The tradeoff is that Ent&#8217;s enforceable coverage across the broader enterprise control plane (SaaS API actions like revoking sharing, inline network controls, email controls, etc.) is still nascent. In practice, this positions Ent as potentially complementary to established DLP controls, useful if it can deliver better context and more actionable, low-noise detections, while still requiring buyers to validate where it truly enforces versus where it only observes and alerts.</p><h3>Core Functions and Use Cases</h3><ul><li><p>Insider-risk-style visibility into sensitive data handling</p><ul><li><p>Detect and investigate risky user behaviors around sensitive data movement where traditional controls may lack context.</p></li></ul></li><li><p>AI-era misuse monitoring (directional)</p><ul><li><p>Where Ent has relevance to monitoring risky user interactions that could involve GenAI tools; exact coverage for specific GenAI apps, and whether controls extend beyond endpoint observation</p></li></ul></li><li><p>Contextual intervention at the point of user action (directional)</p><ul><li><p>Supports coach/warn/block patterns and time-bound temporary access grants with full explainability; configurable policies with reversibility and exceptions/approval workflows supported.</p></li><li><p>Forensic context enrichment for investigations with full-grade evidence</p></li><li><p>Potential value is richer timelines and event context, audit-grade chain-of-custody and export formats should be validated by prospects.</p></li></ul></li></ul><h3>Use Cases and Pain Points Addressed</h3><ol><li><p><strong>Reducing blind spots around user-driven data movement</strong></p><ul><li><p><strong>Enabling capability:</strong> Endpoint telemetry capturing user actions (e.g., focus changes, copy/paste-like interactions) to improve context and triage, in addition to preventing incidents with interventions. Why it matters: many DLP programs struggle with high alert volume and insufficient context for decisive response.</p></li></ul></li><li><p><strong>Insider risk investigations with stronger event context</strong></p><ul><li><p><strong>Enabling capability:</strong> Timeline reconstruction, baseline and anomaly detection, and full evidence capture around user actions. Why it matters: insider investigations often fail due to incomplete context and disputed intent; stronger evidence/auditability can shorten investigations and improve outcomes.</p></li></ul></li><li><p><strong>Human-in-the-loop intervention to reduce accidental leakage</strong></p><ul><li><p><strong>Enabling capability:</strong> Just-in-time warnings/coaching or blocking at the moment of action. Why it matters: CISOs often need prevention that does not rely solely on punitive blocking and that supports productivity-preserving guardrails.</p></li></ul></li><li><p><strong>Complementing incumbent endpoint and DLP tooling</strong></p><ul><li><p><strong>Enabling capability:</strong> Coexistence model with EDR/DLP stacks and clarity on integration points. Why it matters: most enterprises will not replace endpoint and DLP incumbents quickly; the adoption path typically requires additive value with minimal operational disruption.</p></li></ul></li></ol><p><strong>SACR Key take away: <br></strong>Ent  is best treated as an emerging vendor to monitor (or to evaluate in a controlled pilot) for organizations that want stronger user-action context and intervention on endpoints, particularly for insider-risk-style scenarios and modern human, SaaS and AI tool workflows where intent and context matter as much as content inspection for accelerating forensics investigation. Shortlist Ent when your current DLP tooling produces alerts that are hard to investigate or act on, and when you believe endpoint-level context could materially reduce false positives and improve response confidence. Before buying, validate where Ent can truly enforce actions versus observe, privacy/telemetry minimization and governance, integration depth into SIEM/ticketing and key apps, auditability and evidentiary rigor, and operational burden (deployment, tuning, and exception handling) in a real enterprise environment.</p><h2>Harmonic Security</h2><h3>Vendor Profile</h3><p>Harmonic Security prioritizes the governance of workforce GenAI adoption, focusing on identifying and mitigating prompt-based exfiltration and agentic workflow risks. Its center of gravity resides in the AI runtime enforcement plane, specifically browser sessions, desktop applications, and agentic toolchains (via MCP). The platform delivers high-fidelity, real-time sensing of sensitive content and user intent, positioning Harmonic as an enablement-led control plane designed for modern AI runtimes rather than a traditional, high-burden compliance suite.</p><h3>Products/Services Overview</h3><ul><li><p><strong>AI Governance &amp; Control Platform:</strong> Establishes centralized visibility and policy orchestration for workforce AI usage across web and enterprise surfaces to ensure secure adoption.</p></li><li><p><strong>Harmonic Protect:</strong> A browser-extension-led enforcement point that monitors and intervenes in employee interactions with AI tools, focusing on identifying risky telemetry and providing just-in-time user guidance.</p></li><li><p><strong>Endpoint Agent:</strong> A lightweight sensor intended to extend the truth layer beyond the browser to desktop AI applications and thick-client scenarios; OS support and performance overhead remain key validation points.</p></li><li><p><strong>MCP Gateway:</strong> A locally deployed gateway designed to discover and inventory Model Context Protocol (MCP) clients and servers, capturing interaction logs and enforcing data protection at the agentic workflow layer.</p></li><li><p><strong>Usage Intelligence:</strong> Provides deep telemetry into adoption patterns, aimed at helping security leaders focus governance efforts and establish a definitive truth layer for AI usage.</p></li></ul><h3>Market Category: Top-level solution alignment.</h3><h4>Browser Security / Session-Layer DLP</h4><h3>Great DLP Reset Alignment</h3><h4>Hybrid</h4><p>Harmonic aligns with the Great DLP Reset as a pragmatic, AI-era control layer that addresses the fragmentation of sensitive data across AI prompts and agentic toolchains. Architecturally, it spans a truth layer for usage intelligence and a distributed enforcement plane (browser, agent, and MCP Gateway). The core tradeoff is breadth: Harmonic functions as a high-relevance wedge for AI-era leakage rather than a universal legacy DLP replacement, serving as a critical complement to existing SSE/SASE/GW and DSPM controls.</p><h2>Core Functions and Use Cases</h2><ul><li><p><strong>Secure AI Adoption:</strong> Establishes governance guardrails to reduce accidental sensitive data exposure as organizations scale GenAI usage.</p></li><li><p><strong>Prompt Protection:</strong> Detects and intervenes in real-time to prevent sensitive prompts, uploads, or outputs from leading to data loss.</p></li><li><p><strong>Shadow AI Governance:</strong> Identifies risky usage patterns, including the use of personal accounts versus corporate instances.</p></li><li><p><strong>Agentic Workflow Controls:</strong> Monitors MCP clients/servers and enforces tool-level access controls for agents that bypass traditional web proxies.</p></li><li><p><strong>Forensic Auditability:</strong> Produces investigation-ready logs and context for AI-related incidents to support forensic chain-of-custody requirements.</p></li></ul><h3>Use Cases and Pain Points Addressed</h3><ol><li><p><strong>Mitigating Prompt Leakage:</strong> Provides in-browser monitoring to stop sensitive data entry into public AI tools where legacy DLP lacks context.</p></li><li><p><strong>Agent Least-Privilege Governance:</strong> Uses MCP Gateway to restrict agentic access to enterprise data, addressing invisible data paths.</p></li><li><p><strong>Just-in-Time User Coaching:</strong> Implements stop-and-think workflows to reduce accidental leakage without resorting to punitive, high-friction blocking.</p></li><li><p><strong>Establishing an Adoption Baseline:</strong> Leverages usage intelligence dashboards to inform governance planning before turning on strict enforcement.</p></li><li><p><strong>Securing Thick-Client AI:</strong> Extends protection beyond the browser to desktop-based AI apps and IDE-like tools via endpoint sensors.</p></li></ol><p><strong>SACR Key Takeaway:</strong></p><p>Harmonic Security is a high-confidence shortlist candidate when the urgent data exfiltration problem is centered on AI prompts, desktop AI clients, and emerging agentic workflows where legacy DLP and SSE controls provide insufficient telemetry. It is best-fit for security teams seeking to enable AI adoption through practical governance guardrails rather than deterministic blocklists. Before procurement, validate the exact enforcement depth per surface, the rigor of audit trails, and the maturity of platform integrations into existing identity and security operations workflows.</p><h2>Jazz Security</h2><h3>Vendor Profile</h3><p>Jazz Security is an AI-native Data Loss Prevention (DLP) vendor positioning itself as a rebuild from first principles alternative to legacy, rule-heavy DLP programs. Its center of gravity is endpoint-anchored data-in-use and data-in-motion protection: capturing high-fidelity user/workflow telemetry, reconstructing narrative context around potentially risky actions, and enabling targeted, real-time interventions (as described in SACR internal materials and vendor/public statements). In practical terms, Jazz aims to reduce the operational drag of traditional DLP (false positives, brittle policies, and long investigations) by focusing on what happened and why in a workflow, not just whether a pattern matched.</p><h3>Products/Services Overview</h3><ul><li><p><strong>Forensic endpoint agent (data-in-use telemetry collection)</strong></p><ul><li><p>An endpoint component described as collecting user actions and metadata to capture how data is handled during real workflows (e.g., copy/paste-like actions, screensharing-like flows, uploads/downloads, and other user-driven vectors).</p></li></ul></li><li><p><strong>Investigator / investigation automation layer (context reconstruction)</strong></p><ul><li><p>An analysis layer described as taking endpoint telemetry and producing pre-investigated incident narratives (sequence of actions, relevant context, and why an event may be risky) to shorten time-to-triage and reduce analyst workload.</p></li></ul></li><li><p><strong>Natural-language policy / DLP copilot concept</strong></p><ul><li><p>Jazz&#8217;s materials describe a policy experience where security intent can be expressed in natural language and refined conversationally, rather than maintaining large sets of brittle rules.</p></li></ul></li><li><p><strong>Real-time enforcement / intervention actions (endpoint action layer)</strong></p><ul><li><p>Jazz materials describe selective interventions such as user nudges, justification prompts, and blocking of specific risky actions.</p></li></ul></li><li><p><strong>Unmanaged device coverage via browser plugin</strong></p><ul><li><p>Jazz materials mention a browser plugin option for unmanaged devices.</p></li></ul></li></ul><h3>Market Category</h3><p>Endpoint DLP Suite</p><h3>Great DLP Reset alignment (Vendor)</h3><p>Enforcement Plane (where blocking/action happens)</p><p>Jazz aligns to the Great DLP Reset as an emerging vendor providing last-mile, user-action-centric enforcement approach: it emphasizes data protection at the moment people actually handle data (in apps, workflows, and user interfaces), rather than starting with broad discovery/classification across cloud repositories or relying primarily on network chokepoints. The reset theme here is operational: reduce the traditional DLP burden by replacing high-volume alert streams with workflow narratives and targeted interventions. The tradeoff is scope and dependency: an endpoint-first model can be powerful for data-in-use, but it must be validated for coverage gaps (data-at-rest, SaaS-native remediation, non-user-based automation) and for feasibility in environments with strict endpoint constraints.</p><h3>Core Functions and Use Cases</h3><ul><li><p><strong>Data-in-use protection on endpoints</strong></p><ul><li><p>Controls and visibility for how users actually interact with sensitive data during daily work, including actions that many traditional controls miss or contextualize poorly.</p></li></ul></li><li><p><strong>Insider-risk and negligent exfiltration investigations</strong></p><ul><li><p>Workflow reconstruction to distinguish &#8220;one-off mistakes&#8221; from suspicious patterns and reduce investigation time.</p></li></ul></li><li><p><strong>Operational burden reduction for DLP programs</strong></p><ul><li><p>Fewer, higher-context incidents rather than high-volume alerting; intended to reduce tuning workload and analyst fatigue.</p></li></ul></li><li><p><strong>Coverage for unmanaged/contractor scenarios (where supported)</strong></p><ul><li><p>A browser-plugin approach is described for unmanaged devices; validate efficacy and limitations versus full endpoint coverage.</p></li></ul></li><li><p><strong>AI-era leakage at the point of use (directional)</strong></p><ul><li><p>Jazz materials position relevance to AI chat interactions as another UI/workflow surface.</p></li></ul></li></ul><h3>Use Cases and Pain Points Addressed</h3><ol><li><p><strong>Preventing accidental leakage via common user actions</strong></p><ul><li><p><strong>Enabling capability:</strong> endpoint-level observation of user actions plus targeted interventions (nudge/justify/block). Why it matters: many real data losses are negligent or accidental, and blunt blocking policies can cause heavy friction.</p></li></ul></li><li><p><strong>Accelerating triage and reducing false positives through workflow context</strong></p><ul><li><p><strong>Enabling capability:</strong> incident narratives that incorporate surrounding workflow context rather than single events. Why it matters: classic DLP often generates alerts without enough context to act, driving &#8220;alert fatigue&#8221; and abandonment.</p></li></ul></li><li><p><strong>Investigating suspected insider activity with clearer intent signals</strong></p><ul><li><p><strong>Enabling capability:</strong> reconstruction of sequences of actions across apps/sessions to interpret intent (accidental vs. negligent vs. malicious). Why it matters: insider cases are rarely provable from a single event.</p></li></ul></li><li><p><strong>Extending DLP controls to unmanaged devices via browser plugin (where applicable)</strong></p><ul><li><p><strong>Enabling capability:</strong> browser plugin approach described for unmanaged devices. Why it matters is that contractors and BYOD are common gaps, but heavy endpoint control is often infeasible.</p></li></ul></li><li><p><strong>Supporting AI-related data exposure investigations</strong></p><ul><li><p><strong>Enabling capability:</strong> UI/workflow telemetry around user interactions that may include AI chat tools. Why it matters: AI introduces new copy/paste/upload leakage patterns that can evade legacy controls or overwhelm teams with low-context alerts.</p></li></ul></li></ol><h3>Differentiation and Competitive Novelty</h3><ul><li><p><strong>UI/workflow-centric telemetry as a design anchor</strong></p><ul><li><p>Competitive context: contrasts with approaches that rely primarily on network inspection or SaaS API connectors; can provide richer &#8220;intent&#8221; signals but depends on endpoint deployment.</p></li></ul></li><li><p><strong>Pre-investigated narrative model for incidents</strong></p><ul><li><p>Competitive context: aims to reduce manual correlation across tools and logs; differentiates on analyst experience and speed of investigation.</p></li></ul></li><li><p><strong>Natural-language policy / copilot-style policy management</strong></p><ul><li><p>Competitive context: attempts to reduce rule authoring and maintenance burden; must be validated for guardrails, testing, and auditability.</p></li></ul></li><li><p><strong>Surgical prevention philosophy</strong></p><ul><li><p>Competitive context: focuses on blocking only the risky step (versus broad deny policies), which may reduce business disruption if implemented well.</p></li></ul></li></ul><p><strong>SACR Key take away:<br></strong>Jazz Security is best suited for CISOs who believe the biggest DLP failure mode is operational, too much noise, too little context, and controls that users bypass, and who want a modern, endpoint-anchored approach that explains incidents in workflow terms and enables targeted intervention at the moment of use. Shortlist Jazz when endpoint data-in-use risk, insider/negligent behavior, and AI-era copy/paste/upload workflows are primary concerns, and when you have the organizational ability to deploy and govern an endpoint agent responsibly.</p><h2><strong>Island</strong></h2><h3>Vendor Profile</h3><p>Island provides policy controls via it&#8217;s enterprise browser, enterprise network and endpoint software. In DLP architectures, Island is best understood as a browser and session enforcement plane but has been broadening its capability. It delivers controls for the last-mile user actions (copy/paste, upload/download, printing, screen capture) that often bypass network-only and traditional SASE controls, especially for SaaS and GenAI usage that happens in-browser. Uniquely Island Desktop, device control and the Island service help isolate and control data across various workspace boundaries.</p><h3>Products/Services Overview</h3><ul><li><p>Enterprise Browser (managed Chromium-based workspace)</p></li><li><p>Enterprise Extension (for existing consumer browsers)</p></li><li><p>Island Desktop (Endpoint Software)</p></li><li><p>Enterprise Network (Policy Control)</p></li><li><p>Enterprise Network (Access)</p></li><li><p>Browser security and data controls (policy, isolation patterns depending on config)</p></li><li><p>Visibility and audit logging for web and SaaS sessions</p></li></ul><h4>Market Category</h4><p>Browser Security / Session-Layer DLP</p><h4>Great DLP Reset Alignment</h4><p>Enforcement Plane (where blocking/action happens)</p><h3>Core Functions and Use Cases</h3><ul><li><p>Prevent data exfiltration from SaaS via in-session controls.</p></li><li><p>GenAI governance in the browser and on the desktop (prompt/response controls are possible depending on policy model and integrations) and agentic tools (For example, Island can mask sensitive data when an AI agent is interacting with a website).</p></li><li><p>Control unmanaged devices and contractor access by moving the control point into the browser.</p></li><li><p>Session evidence: log key actions for compliance and investigation.</p></li><li><p>Last mile controls across both web and desktop apps, including cut/copy/paste, file application access, file movement, print, screenshot, and share controls.</p></li><li><p>Governing and tracking data movement from corporate apps to non-corporate apps, such as file movements and copy-paste, including tenancy awareness (ex. corporate Gmail vs personal Gmail and AI services and chat interfaces)</p></li></ul><h3>Differentiation and Competitive Novelty</h3><ul><li><p>Strong control over dominant leakage paths in SaaS environments.</p></li><li><p>Does not require SSL/TLS break and inspection of traffic.  This is useful when TLS decryption and traffic steering is politically difficult but in-session control is acceptable.</p></li><li><p>Includes hundreds of data classifiers, including pattern matching, AI-based content classifiers and custom prompts (useful for tricky data controls like HIPAA, where you might have two pieces of data that are compliant on their own but become a violation when they are combined), exact data matching, and third-party sensitivity labels</p></li></ul><h4>SACR Key Take Away</h4><p>For CISOs, Island is a high-leverage DLP enforcement point when the browser is the primary workspace (SaaS + GenAI). Use it to control last-mile actions, paired with data discovery (DSPM) and SaaS/API controls and  SaaS API Protection (out-of-band CASB using APIs for a complete program. Island also is good for data lineage tracking and data protection within boundaries, especially important when delivering unique experiences in multi-user environments (for instance Banking, retail and hotel operations), which include recording and data lineage for sensitive operations.</p><h2>Keep Aware</h2><h3>Vendor Profile</h3><p>Keep Aware positions as an enterprise browser security platform that embeds controls directly into end-user browsers (via an extension-style approach) to address two problems that classic DLP and perimeter controls often struggle with: last-mile, in-browser data leakage (copy/paste, form entry, uploads, account switching, and GenAI prompt inputs), and browser-native threats such as phishing techniques and risky in-page behaviors. Its center of gravity in DLP is browser/session-layer prevention and monitoring rather than data-at-rest discovery or large-scale inline network inspection.</p><h3>Products/Services Overview</h3><ul><li><p><strong>Enterprise browser security management console</strong></p><ul><li><p>Centralized policy management and visibility across &#8220;industry standard browsers&#8221; (vendor wording), with deployment described as quick/minimally disruptive.</p></li></ul></li><li><p><strong>Browser Data Loss Prevention (DLP) use case coverage</strong></p><ul><li><p>Monitoring and control of in-browser actions associated with leakage (typing, pasting, uploads).</p></li><li><p>Controls intended to reduce leakage via personal-account usage inside the same browser context (e.g., switching between corporate and personal accounts).</p></li><li><p>Stated compatibility with Microsoft Purview sensitivity labeling/workflows.</p></li></ul></li><li><p><strong>Browser Detection &amp; Response (BDR) / threat prevention capabilities</strong></p><ul><li><p>Click-by-click telemetry and DOM analysis (vendor-described) for investigation and blocking of certain browser-resident threats and in-page behaviors.</p></li><li><p>Coverage claims include phishing patterns (e.g., &#8220;browser-in-the-browser&#8221;) and the ability to block actions such as copy/paste, uploads/downloads, network requests, and credential-related behaviors.</p></li></ul></li><li><p><strong>Security operations integrations</strong></p><ul><li><p>Vendor claims integration into SIEM/SOAR and common workflow tools (examples shown publicly include Splunk, Microsoft Sentinel, Tines, Jira, Rapid7, Slack, Microsoft Teams).</p></li></ul></li></ul><h3>Market Category</h3><h4>Browser Security / Session-Layer DLP</h4><h3>Market Sub-Category</h3><h4>Browser/session (last mile)</h4><h3>Great DLP Reset alignment</h3><p>Enforcement Plane (where blocking/action happens)</p><p>Keep Aware aligns to the Great DLP Reset narrative by treating the browser session as a primary enforcement point for modern data movement and AI-era leakage paths. Instead of assuming a small number of network chokepoints or relying on after-the-fact SaaS API remediation, the approach emphasizes last-mile user actions,typing into web apps, pasting into chat interfaces, uploading files, and interacting with GenAI prompts, where sensitive data often leaves the organization despite existing controls. The architectural tradeoff is that value depends on consistent endpoint/browser coverage and sound policy tuning in the browser runtime; it complements (rather than replaces) data discovery/truth-layer platforms and may not address non-browser channels (thick clients, unmanaged endpoints, or backend-to-backend data flows) without additional tooling.</p><h3>Core Functions and Use Cases</h3><ul><li><p><strong>Browser/session DLP for modern SaaS work</strong></p><ul><li><p>Reduce leakage via user actions inside web applications (copy/paste, uploads, form entry).</p></li></ul></li><li><p><strong>GenAI prompt/input governance at the browser layer</strong></p><ul><li><p>Apply controls to sensitive data entered into public or unsanctioned AI web experiences.</p></li></ul></li><li><p><strong>Personal account and identity boundary controls</strong></p><ul><li><p>Detect/limit risky mixing of corporate and personal accounts during browser sessions.</p></li></ul></li><li><p><strong>Browser threat detection and investigation</strong></p><ul><li><p>Provide investigative telemetry (click-by-click) and browser-native detections oriented to phishing and malicious in-page behaviors.</p></li></ul></li><li><p><strong>SOC workflow integration</strong></p><ul><li><p>Feed browser events into existing SIEM/SOAR and collaboration tools to reduce tool sprawl.</p></li></ul></li></ul><h3>Use Cases and Pain Points Addressed</h3><p><strong>Preventing sensitive data paste into web apps and AI chat interfaces</strong></p><ul><li><p>Enabling capability: monitoring and policy control over typing/pasting in the browser.</p></li><li><p>Why it matters: addresses a common leakage path that may bypass API-only controls and occurs before data becomes a stored object.</p></li></ul><ol start="2"><li><p><strong>Controlling uploads of sensitive files into SaaS, webmail, or shadow IT destinations</strong></p><ul><li><p>Enabling capability: browser-layer inspection/controls on uploads.</p></li><li><p>Why it matters: reduces exfiltration through sanctioned browsers even when network chokepoints are inconsistent.</p></li></ul></li><li><p><strong>Reducing corporate-to-personal account mixing (e.g., personal webmail/storage usage)</strong></p><ul><li><p>Enabling capability: policy to limit/monitor access to personal accounts on corporate devices.</p></li><li><p>Why it matters: a frequent root cause of accidental data movement outside governed tenants.</p></li></ul></li><li><p><strong>Faster phishing investigation with browser-native telemetry</strong></p><ul><li><p>Enabling capability: click-by-click telemetry and DOM analysis to investigate what the user saw/did.</p></li><li><p>Why it matters: shortens time-to-triage when network and endpoint logs are insufficient to reconstruct browser UI deception.</p></li></ul></li><li><p><strong>Operationalizing browser signals in existing SOC tooling</strong></p><ul><li><p>Enabling capability: SIEM/SOAR/workflow integrations.</p></li><li><p>Why it matters: improves adoption when events become actionable where analysts already work.</p></li></ul></li></ol><h3>Differentiation and Competitive Novelty</h3><ul><li><p><strong>Focus on browser-native enforcement rather than network-inline inspection</strong></p><ul><li><p>Competitive context: positioned against &#8220;proxy + decryption&#8221; approaches; promises value where inline steering is undesirable or infeasible.</p></li></ul></li><li><p><strong>Inside-the-browser visibility claims (DOM analysis, user-action telemetry)</strong></p><ul><li><p>Competitive context: differentiates from tools that only see URL/category or network flow metadata.</p></li></ul></li><li><p><strong>Combination of DLP-style controls and detection/response framing</strong></p><ul><li><p>Competitive context: attempts to unify data leakage controls with phishing/threat investigation in a single browser-resident control point.</p></li></ul></li><li><p><strong>Purview adjacency (sensitivity labels) and SOC tool integrations</strong></p><ul><li><p>Competitive context: tries to coexist with incumbent suites rather than forcing rip/replace.</p></li></ul></li></ul><p><strong>SACR Key take away:</strong></p><p>Keep Aware is best evaluated as a browser/session enforcement layer for modern DLP, particularly for SaaS-heavy organizations struggling with copy/paste, uploads, account switching, and GenAI prompt exposure that bypass traditional chokepoints. Shortlist it when the security program wants practical, last-mile controls without committing to broad inline steering/decryption changes, and when phishing investigation would materially benefit from richer browser-native evidence.</p><h2>MIND (mind.io)</h2><h3>Vendor Profile</h3><p>MIND is an AI-native data security platform focused on modernizing data loss prevention and insider risk by combining discovery and classification of sensitive (primarily unstructured) data with runtime prevention controls across endpoints, browsers, SaaS apps, email, Agentic AI and GenAI usage. Its center of gravity is autonomous and low-ops DLP that aims to reduce the policy and triage burden through richer classification, context, and automation, while still providing concrete enforcement at user-controlled leak points (endpoint + browser) and remediation for exposure in common SaaS repositories.</p><h3>Products/Services Overview</h3><ul><li><p><strong>Data discovery and classification (&#8220;MIND AI&#8221; / multi-layer classification)</strong></p><ul><li><p>Continuous inventory and classification of sensitive data across connected environments (SaaS, endpoints, on-prem file shares, email), oriented to unstructured content.</p></li><li><p>Multi-method approach: combines deterministic techniques with proprietary SLM/LLMs and statistical/semantic approaches to improve precision and reduce false positives.</p></li></ul></li><li><p><strong>Data detection and response (DDR) / context-driven investigation support</strong></p><ul><li><p>Enrichment of risky events with who, what, where, when and why context, with prioritization intended to reduce analyst noise.</p></li><li><p>Redacted meta-data of source file is  available (e.g., storing redacted representations rather than full sensitive values).</p></li></ul></li><li><p><strong>Loss prevention and mitigation (runtime controls and remediation)</strong></p><ul><li><p>Endpoint agent + browser extension used for prevention at most common exfiltration paths (copy/paste, uploads, local actions), and for capturing lineage/evidence.</p></li><li><p>Automated/assisted remediation actions: revoke access/remove public links, quarantine/delete, apply labels, engage data owners, etc.</p></li><li><p>Block with override/justification and user coaching/notifications are supported as a way to reduce friction while still enforcing policy intent.</p></li></ul></li><li><p><strong>Integrations and ecosystem connectivity</strong></p><ul><li><p>Public materials reference integration with identity (notably Okta) and common enterprise/SaaS systems; integrations with collaboration tools (Slack/Teams) for nudges/coaching and workflows are also supported.</p></li></ul></li><li><p><strong>Trust/compliance posture (public trust center)</strong></p><ul><li><p>The public trust center lists SOC 2 Type 2 and ISO/IEC 27001:2022, plus ISO/IEC 42001:2023 (AI management system), and regulatory frameworks (e.g., GDPR, HIPAA, CCPA).</p></li></ul></li></ul><p><strong>Market Category</strong></p><p>Insider Risk / DDR / DLP / DSPM</p><p><strong>Great DLP Reset alignment (Vendor)</strong></p><p>Hybrid</p><p>MIND aligns with the Great DLP Reset shift by treating DLP less as a set of brittle, channel-specific regex rules and more as a continuous data security program anchored in better classification and context, then applied across distributed enforcement points. Architecturally it behaves like a hybrid of: truth-layer discovery/classification for unstructured data, a control-plane experience to prioritize issues and drive remediation, and enforcement at the user action layer (endpoint and browser) for AI-era leak paths (prompt pastes, uploads, local exfil). The tradeoff is that this approach depends on endpoint/browser rollout and integration depth; it is not inherently an inline proxy/SSE choke-point model, and it may not address all agent-to-agent or backend-to-backend data flows without additional controls.</p><h3>Overall Viability and Execution</h3><p>Publicly, MIND has communicated a $30M Series A (June 2025) and positioning as a fast-moving vendor in autonomous DLP. The company also states recognition as a RSAC 2025 Innovation Sandbox finalist (Top 10), Blackhat Startup Spotlight Honorable Mention (2025). These are signals of momentum, but they do not fully substitute for operational diligence on support maturity, roadmap execution, and referenceability.</p><p>What tends to go well with this type of platform is rapid visibility into unstructured data risk plus pragmatic controls at common leak points (endpoint and browser). What tends to be hard is scaling endpoint and browser deployments, aligning security controls with business workflows (especially where blocking is politically costly), and ensuring integrations deliver real remediation and audit-grade evidence rather than simply producing more alerts.</p><p><strong>Core Functions and Use Cases</strong></p><ul><li><p><strong>Unstructured data discovery and classification across modern estates</strong></p><ul><li><p>Find and classify sensitive content in files and common repositories to establish a credible baseline for policy decisions.</p></li></ul></li><li><p><strong>Insider risk detection with context and prioritization</strong></p><ul><li><p>Identify risky behaviors and reduce false positives by using identity/activity/destination context.</p></li></ul></li><li><p><strong>GenAI usage guardrails for common user-driven leakage paths</strong></p><ul><li><p>Detect and prevent sensitive data from being pasted or uploaded into GenAI tools (browser-mediated) and similar destinations.</p></li></ul></li><li><p><strong>Endpoint-centric enforcement and evidence collection</strong></p><ul><li><p>Control data-in-use actions (e.g., USB/peripherals, local actions) and collect investigation artifacts (activity logs; screenshots are referenced in internal notes).</p></li></ul></li><li><p><strong>Automated remediation for exposure in SaaS and collaboration environments</strong></p><ul><li><p>Reduce dwell time for oversharing/public link exposure via targeted remediation actions (subject to connector action depth).</p></li></ul></li></ul><h3>Use Cases and Pain Points Addressed</h3><ol><li><p><strong>Rapidly identifying sensitive unstructured crown jewel data across SaaS and file shares</strong></p><ul><li><p>Enabling capability: continuous discovery + multi-layer classification across connected sources.</p></li><li><p>Why it matters: without credible classification, prevention controls become noisy and politically fragile.</p></li></ul></li><li><p><strong>Reducing oversharing risk in collaboration platforms (e.g., public links, external sharing)</strong></p><ul><li><p>Enabling capability: detection of exposure + remediation actions (remove links/revoke access/quarantine/delete, depending on system).</p></li><li><p>Why it matters: many real incidents start as &#8220;quiet&#8221; oversharing, not obvious exfiltration.</p></li></ul></li><li><p><strong>Preventing sensitive prompt pastes/uploads into GenAI web tools</strong></p><ul><li><p>Enabling capability: browser/endpoint-mediated inspection prior to destination submission (as described in internal notes).</p></li><li><p>Why it matters: GenAI prompts are now a frequent, high-velocity leak path that bypasses legacy controls.</p></li></ul></li><li><p><strong>Controlling endpoint exfiltration paths while preserving legitimate workflows</strong></p><ul><li><p>Enabling capability: endpoint agent controls plus policy actions like block, warn, or &#8220;block with override + justification.&#8221;</p></li><li><p>Why it matters: reduces operational friction by supporting exception handling without abandoning enforcement.</p></li></ul></li><li><p><strong>Building investigation-grade context for insider and accidental leakage</strong></p><ul><li><p>Enabling capability: context enrichment and evidence capture (logs/metadata; screenshots referenced in internal notes).</p></li><li><p>Why it matters: accelerates time-to-understand and supports auditability.</p></li></ul></li><li><p><strong>Agentic AI visibility:</strong></p><ul><li><p>Enabling capability:<strong> </strong>Endpoint and can place controls on endpoint agentic workflows.</p></li><li><p>Why it matters: Complementary approach to AI and agentic data loss and visibility.</p></li></ul></li></ol><h3>Differentiation and Competitive Novelty</h3><ul><li><p><strong>Autonomous DLP posture that combines discovery, prevention, and remediation in one workflow</strong></p><ul><li><p>Competitive context: contrasts with single-plane tools (discovery-only DSPM, or enforcement-only DLP) that require stitching.</p></li></ul></li><li><p><strong>Multi-layer classification approach explicitly described as beyond regex-only, with tuning intended to reduce false positives</strong></p><ul><li><p>Competitive context: aims to reduce alert fatigue vs legacy DLP engines; depends on real-world precision/recall under customer data.</p></li></ul></li><li><p><strong>Endpoint and browser enforcement emphasis (plus SaaS connectors)</strong></p><ul><li><p>Competitive context: focuses on user action leak paths and AI-era interactions rather than relying on network-inline choke points.</p></li></ul></li><li><p><strong>Trust posture emphasizing AI governance standards</strong></p><ul><li><p>Competitive context: ISO/IEC 42001:2023 (as publicly announced) is a notable signal in AI-heavy security tooling, but buyers still need to validate how models are governed operationally (change management, testing, drift, explainability).</p></li></ul></li></ul><p><strong>SACR Key take away:</strong></p><p>MIND is best considered by CISOs who want a pragmatic, AI-era modernization of DLP and insider risk that reduces operational drag by pairing stronger unstructured-data classification with enforcement at the user action layer (endpoint + browser) and automated remediation for common SaaS exposures. Shortlist it when the organization&#8217;s dominant leakage paths are browser/endpoint-mediated (including GenAI prompt and upload behaviors) and when the team needs faster time-to-value than multi-quarter classic DLP rollouts.</p><h2>Orion Security</h2><h3>Vendor Profile</h3><p>Orion Security is an AI-native data loss prevention platform positioned to reduce the operational brittleness of traditional DLP by shifting emphasis from static, manually maintained policies to context-rich detection of why sensitive data is moving. Its center of gravity is real-time detection and prevention of risky data movement across multiple enforcement points (endpoint agent, browser extension,email gateway, and SaaS/API integrations), with particular focus on high-noise environments where security teams struggle to distinguish legitimate workflow activity from true exfiltration, especially as GenAI usage increases the volume of sensitive data interactions.</p><h3>Products/Services Overview</h3><ul><li><p><strong>Unified DLP platform spanning multiple enforcement surfaces</strong></p><ul><li><p>Endpoint agent capabilities intended to observe and control local data actions and common exfiltration paths.</p></li><li><p>Browser extension capabilities intended to control last-mile user actions in web/SaaS and GenAI interactions.</p></li><li><p>Email Gateway that adds another security layer to prevent data exfiltration though emails, even when sent through unmanaged devices (like mobile phones).</p></li><li><p>SaaS/API integrations intended to observe and act on risky data movement and oversharing in connected services (action depth varies by connector and must be validated).</p></li></ul></li><li><p><strong>Context- and behavior-oriented detection engine (&#8220;beyond policies&#8221; positioning)</strong></p><ul><li><p>Uses context signals (identity, destination, environment, and lineage) to judge likelihood of data loss vs normal business activity.</p></li></ul></li><li><p><strong>Data lineage / tracing-oriented investigation support</strong></p><ul><li><p>Emphasis on mapping or reconstructing data movement paths to improve triage and provide investigation narrative (what happened and how data moved).</p></li></ul></li><li><p><strong>User interaction and enforcement workflows</strong></p><ul><li><p>Vendor materials describe controls such as warnings/coaching, justification/override patterns, and automated blocking, with escalation options.</p></li></ul></li><li><p><strong>Integration into security operations workflows</strong></p><ul><li><p>Vendor-provided materials describe integrating into existing SOC/case management patterns.</p></li></ul></li></ul><h3>Market Category</h3><p>Enterprise DLP Suite</p><h3><strong>Great DLP Reset alignment</strong></h3><p>Hybrid</p><p>Orion aligns with the Great DLP Reset thesis by treating DLP as a context-driven control plane paired with distributed enforcement, rather than a policy spreadsheet attached to a few chokepoints. The model is oriented to using richer context to reduce false positives and avoid policy sprawl, placing controls closer to where modern data movement occurs (endpoint and browser-mediated SaaS and GenAI workflows), and providing a more investigation-ready view of data movement (lineage/flow framing). The primary tradeoffs are typical of emerging AI-native DLP approaches: buyers must validate explainability and governance of AI-driven decisions, confirm the practical breadth of integrations and enforcement depth, and ensure deployment/change-management (agents and extensions) is acceptable at scale.</p><h3>Overall Viability and Execution</h3><p>Public reporting indicates Orion raised a significant funding round in early 2026, and investor commentary portrays strong early go-to-market momentum. This supports near-term viability and suggests the company is investing aggressively in product development and enterprise sales, but it does not substitute for customer diligence on support maturity, roadmap stability, and implementation outcomes across diverse environments.</p><p>Orion is described as highly responsive during RFP/POC phases, with a set-and-forget aspiration (reduced tuning burden versus legacy DLP). What tends to go well are deployments, fast initial visibility and a clearer signal-to-noise story when buyers are already suffering from alert fatigue. What tends to be hard: enterprise-scale rollout (endpoint + browser), providing consistent enforcement across varied data channels, and meeting the expectations of organizations that require mature global support, deep compliance artifacts, and highly deterministic controls for regulated workflows.</p><h3>Core Functions and Use Cases</h3><ul><li><p><strong>Reducing false positives and policy sprawl in DLP programs</strong></p><ul><li><p>Use context/behavior to improve precision and reduce ongoing tuning overhead.</p></li></ul></li><li><p><strong>Securing SaaS and browser-mediated workflows (including GenAI use)</strong></p><ul><li><p>Control and monitor common last-mile leak paths such as web uploads, copy/paste, and prompt entry.</p></li></ul></li><li><p><strong>Endpoint-centric prevention for data-in-use actions</strong></p><ul><li><p>Address local exfil paths (e.g., file movement patterns, local application interaction) with agent-based controls.</p></li></ul></li><li><p><strong>Incident investigation and evidence-building for data movement</strong></p><ul><li><p>Provide lineage/flow visibility to accelerate triage and support auditability.</p></li></ul></li><li><p><strong>Augmenting existing DLP investments rather than forcing rip-and-replace</strong></p><ul><li><p>Public interview content indicates Orion may run alongside incumbent stacks in larger enterprises, focusing on context enrichment and reduction of noisy detections.</p></li></ul></li></ul><h3>Use Cases and Pain Points Addressed</h3><ol><li><p><strong>Cutting noise in existing DLP deployments without weakening enforcement</strong></p><ul><li><p>Enabling capability: context-aware detection to distinguish legitimate business workflows from suspicious movement.</p></li><li><p>Why it matters: reduces analyst fatigue and increases trust in DLP signals.</p></li></ul></li><li><p><strong>Preventing sensitive data entry into public GenAI tools via browser sessions or desktop apps</strong></p><ul><li><p>Enabling capability: Browser extension and enforcement for copy/paste and  prompt submission patterns desktop app for data exfiltration prevention.</p></li><li><p>Why it matters: GenAI creates a high-frequency, human-driven leak path that traditional DLP often misses or over-blocks.</p></li></ul></li><li><p><strong>Stopping risky uploads/shares from endpoints to SaaS destinations</strong></p><ul><li><p>Enabling capability: endpoint agent + SaaS context to judge destination risk and take actions (warn/block/justify).</p></li><li><p>Why it matters: many leaks are &#8220;normal&#8221; user workflows pointed at the wrong destination or account context.</p></li></ul></li><li><p><strong>Detecting anomalous exfiltration behavior (insider or compromised identity patterns)</strong></p><ul><li><p>Enabling capability: behavior/intent analysis combined with identity and environment signals.</p></li><li><p>Why it matters: material incidents often look like legitimate access until correlated with context and unusual movement.</p></li></ul></li><li><p><strong>Building investigation-ready narratives of how data moved</strong></p><ul><li><p>Enabling capability: lineage/flow mapping to show the sequence of movement and implicated users/apps.</p></li><li><p>Why it matters: speeds containment decisions and improves defensibility in audits and post-incident reviews.</p></li></ul></li></ol><h3>Differentiation and Competitive Novelty</h3><ul><li><p><strong>Beyond policies positioning: intent and workflow-aware DLP rather than rule-first DLP</strong></p><ul><li><p><strong>Competitive context:</strong> contrasts with legacy suites that rely heavily on static patterns and long tuning cycles.</p></li></ul></li><li><p><strong>Multi-surface enforcement portfolio (endpoint agent, browser extension and SaaS/API)</strong></p><ul><li><p><strong>Competitive context:</strong> attempts to unify prevention across the most common modern leak points without requiring a full SSE/SASE-inline architecture.</p></li></ul></li><li><p><strong>Lineage/flow emphasis as a primary mechanism for trust and triage</strong></p><ul><li><p><strong>Competitive context:</strong> aims to compete on evidence quality and analyst usability, not only detection.</p></li></ul></li><li><p><strong>Coexistence model for large enterprises</strong></p><ul><li><p><strong>Competitive context:</strong> public interview material indicates Orion may supplement entrenched platforms (e.g., to reduce noise and add context) rather than demanding immediate replacement.</p></li></ul></li></ul><p><strong>SACR Key take away:</strong></p><p>Orion Security is best suited for CISOs who are dissatisfied with legacy DLP&#8217;s tuning burden and false-positive fatigue and want a more context-driven approach to preventing real data loss, especially in SaaS-heavy environments where GenAI usage and browser-mediated workflows dominate. Shortlist Orion when you need faster, higher-trust signal and practical enforcement at endpoint and browser leak points, and when the organization is willing to evaluate an emerging vendor&#8217;s AI-driven detection model through a rigorous pilot.</p><h2><strong>Teleskope</strong></h2><h3>Vendor Profile</h3><p>Teleskope positions as a data protection platform that combines event-driven  discovery/classification with native policy-driven remediation and preventive controls, oriented primarily around reducing data exposure and privacy and compliance risk across cloud data stores and SaaS applications. Teleskope&#8217;s center of gravity is closer to DSPM-style discovery plus DLP workflows (automated fixes inside connected systems) rather than classic in-line network DLP enforcement across all channels.</p><h3>Products/Services Overview</h3><ul><li><p><strong>Connectors + discovery and scanning pipeline:</strong> Connector-based enrollment for data sources, crawling to inventory assets and scanning to classify sensitive elements and documents and collect metadata for an observatory view.</p></li><li><p><strong>Classification engine:</strong> Broad set of sensitive data elements and support for structured/unstructured sources overlayered by context intelligence (document type, access levels, business profile, etc).</p></li><li><p><strong>Policy engine (Policy Maker):</strong> Declarative policies using triggers (e.g., sensitivity, accessibility, staleness), scoping filters, and actions can run in observe-only mode before enabling remediation actions. Policy simulation is also available.</p></li><li><p><strong>Native automated remediation / data transformation actions:</strong> Actions such as revoking access, redaction and anonymization, masking, quarantining, relocating, deterministic encryption with referential integrity, synthetic replacement, and workflow-driven notifications and tickets are available.</p></li><li><p><strong>Alerting and workflow integrations:</strong> Documented integrations include Slack, Jira, Email and other third-party automation/alerting paths (buyers should validate depth e.g., bidirectional ticket updates vs one-way notifications).</p></li><li><p><strong>AI governance:</strong> Public materials describe controls intended to reduce sensitive data usage in training and inference and to support a redact API embedded in workflows. Specifically, Teleskope is among four OpenAI approved partners for conversation message logs in the Logs Platform meaning it offers real time sensitive data detection and remediation for AI Agent conversations.</p></li></ul><h3>Market Category</h3><p>DSPM / Data Security Platform with DLP Workflows.</p><h4>Great DLP Reset Alignment</h4><p>Hybrid</p><p>Teleskope aligns to the modern DLP reset narrative as a platform that starts with event-driven  discovery/classification (truth-layer mechanics) and then expresses governance through a policy/control-plane construct that can drive remediation actions in connected systems. The architectural tradeoff to validate is where prevention actually occurs: Enforcement is delivered API-driven and data-store&#8211;driven (e.g., redaction, access changes, deletion), a deliberate architectural choice prioritizing near real-time coverage at the data layer without the latency and agent-dependency constraints of in-line controls  which may not replace in-line controls for web traffic or endpoint data-in-use exfiltration paths without complementary enforcement technologies.</p><h3>Overall Viability and Execution</h3><p>Execution tends to go well when organizations want rapid visibility into where sensitive data resides across cloud and SaaS sources, and when they have a clear plan for remediation actions that can be safely automated (with approvals/guardrails) per connector. Execution tends to be harder where customers expect a single product to provide broad, real-time prevention across every channel (web, endpoint, email, SaaS, Slack, OpenAI, GenAI prompts), because the available materials emphasize discovery plus policy-driven remediation, and the exact enforcement points and response latency vary by connector and deployment model.</p><h3>Core Functions and Use Cases</h3><ul><li><p><strong>Sensitive data discovery and inventory:</strong> Building an inventory of assets and locating sensitive elements across connected stores and applications to reduce unknown exposure.</p></li><li><p><strong>Exposure reduction via policy automation:</strong> Identifying risky accessibility conditions (e.g., overly permissive sharing) and triggering actions/notifications through policies where supported.</p></li><li><p><strong>Privacy operations enablement:</strong> Supporting privacy-driven workflows such as DSAR-oriented deletion/retrieval based on classification findings and downstream integrations (validate exact system coverage and action depth).</p></li><li><p><strong>Data minimization and lifecycle hygiene:</strong> Using staleness and age-based signals to drive cleanup workflows (where connector metadata supports it).</p></li><li><p><strong>AI-era data readiness (as positioned by the vendor):</strong> Applying redaction/masking and dataset-use controls intended to reduce sensitive data propagation into AI workflows (validate which AI surfaces are actually controlled vs monitored).</p></li></ul><h3>Use Cases and Pain Points Addressed</h3><ol><li><p><strong>Reduce overexposed collaboration data in SaaS repositories:</strong> Uses connectors and classification to find sensitive content and (where supported) revoke access or remediate sharing conditions, reducing the blast radius of accidental oversharing.</p></li><li><p><strong>Automate redaction/anonymization for persisted sensitive data:</strong> Provides defined redaction mechanisms (masking, synthetic replacement, deterministic encryption with referential integrity) to transform data at rest as part of policy workflows or API-driven integration, useful for lowering exposure in non-production environments and certain compliance use cases (validate reversibility, key management, and downstream app compatibility).</p></li><li><p><strong>Support DSAR deletion/retrieval workflows:</strong> Uses classification findings to locate subject data across systems and drive deletion/retrieval steps through integrations (validate the full set of systems where delete is supported vs locate and ticket).</p></li><li><p><strong>Route findings into existing SecOps/ITSM workflows:</strong> Integrations such as Slack/Jira/Tines can turn findings into operational tickets/alerts, helping teams avoid a net-new console-only workflow (validate deduplication, ownership routing, and closure feedback loops).</p></li><li><p><strong>Policy-driven monitoring for stale or risky data:</strong> Staleness triggers and connector metadata can be used to flag or act on data that is old, orphaned, or otherwise a governance concern (validate metadata quality per connector).</p></li></ol><h2><strong>Differentiation and Competitive Novelty</strong></h2><ul><li><p><strong>Context-aware classification beyond pattern matching: </strong>Unlike regex-based or flat ML classifiers that identify sensitive data by matching known patterns, Teleskope&#8217;s classification engine builds a model of the customer&#8217;s specific environment &#8212; incorporating document type, business context, access levels, and intent inference &#8212; to identify what is actually risky in that organization. This enables classification of sensitive documents that contain no regulated data fields (e.g., M&amp;A term sheets, proprietary formulas, board-level communications) and materially reduces false positives by understanding that some data is expected to look sensitive. The engine is built on a hierarchical multi-head architecture and is complemented by Prism, a document intelligence capability that classifies documents as whole objects rather than scanning for field-level patterns within them.</p></li><li><p><strong>Remediation-forward posture:</strong> Compared with visibility-heavy DSPM tools, Teleskope emphasizes taking actions (redact,mask,encrypt,delete,revoke access) as first-class outcomes, not just findings (buyers should validate safety controls, approvals, and rollback patterns per action).</p></li><li><p><strong>Deployment flexibility (including self-hosted into customer cloud):</strong> Teleskope offers single-tenant SaaS and air-gapped self-hosted options, which may matter for regulated buyers with data residency or operational control requirements.</p></li><li><p><strong>Policy model based on sensitivity, accessibility and staleness:</strong> A relatively straightforward policy vocabulary can help teams operationalize governance without modeling every scenario as a separate DLP rule tree (validate how this maps to complex exception handling and business-unit workflows).</p></li></ul><h2><strong>SACR Key take away:</strong></h2><p>Teleskope is best evaluated by CISOs as a discovery-to-remediation data security platform that can reduce data exposure and privacy/compliance risk across cloud and SaaS footprints,especially where the organization wants policy-driven automation (redaction, access tightening, deletion workflows) rather than only visibility. Shortlist it when your primary challenge is sensitive data sprawl and slow or manual cleanup and when you can grant the permissions needed for enforceable connector actions.</p><p></p><div><hr></div><p></p><h2><strong>Conclusions</strong></h2><p>DLP is being rebuilt into a new Unified Data Loss Control Plane (DLCP) because enterprise data no longer lives behind a few enforceable chokepoints, data at rest is difficult to map and share with other data security tooling, AI is leaking data through shadow AI and AI workflows have introduced entirely new leakage paths through coming agent to agent interactions. The market direction is clear: discovery-led truth layers, context-rich policy decisions, and automation-driven remediation are replacing the old model of static rules and endless tuning. Solutions are moving to runtime enforcement vs detection and response through manual processes, and autonomous operations are becoming available rapidly to enhance data defense in the era of realtime agents and greater sprawl.</p><p><strong>SACR Key Takeaway:</strong> For CISOs, the strategic implication is to treat DLP as a control plane program rather than a single product. Winning strategies start by making sensitive data and access realities visible, then apply the minimum necessary enforcement across SaaS APIs, inline controls, endpoints, and browser and AI surfaces, with remediation automation and evidence quality as the core success measures. DLP is dead. Long live the Data Control Plane. The DLP reset favors platforms that enable a data control plane and programs that reduce time-to-value, shrink tuning burden, and credibly govern SaaS and AI workflows with automated remediation and auditable evidence.</p><div><hr></div><h3>Sources and References</h3><ul><li><p><em>1 - AI adoption has reached 73% of enterprises in 2026, while real time security governance is just beginning to emerge at 7%. (<a href="https://www.netskope.com/resources/reports-guides/ai-risk-and-readiness-report">Netskope</a>)</em></p></li><li><p><em>2 - A commissioned study conducted by Forrester Consulting on behalf of Google, &#8220;Cloud Workers Are Key To Disruption Preparedness&#8221;, 2020.</em></p></li></ul><p></p><p></p><div><hr></div><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Software Analyst Cyber Research! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/p/the-great-dlp-reset-securing-data?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/p/the-great-dlp-reset-securing-data?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/p/the-great-dlp-reset-securing-data/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/p/the-great-dlp-reset-securing-data/comments"><span>Leave a comment</span></a></p><div class="directMessage button" data-attrs="{&quot;userId&quot;:6770950,&quot;userName&quot;:&quot;SACR&quot;,&quot;canDm&quot;:null,&quot;dmUpgradeOptions&quot;:null,&quot;isEditorNode&quot;:true}" data-component-name="DirectMessageToDOM"></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><p></p>]]></content:encoded></item><item><title><![CDATA[The Rise of UADP: Market Share, Growth, and the Consolidation of Security Platforms]]></title><description><![CDATA[A quantitative analysis of how DSPM, DLP, ITDR, NHI, and AI security are converging into a single security architecture. The key players driving the new market categories.]]></description><link>https://softwareanalyst.substack.com/p/the-rise-of-uadp-market-share-growth</link><guid isPermaLink="false">https://softwareanalyst.substack.com/p/the-rise-of-uadp-market-share-growth</guid><dc:creator><![CDATA[SACR]]></dc:creator><pubDate>Mon, 13 Apr 2026 18:51:13 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!phUT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabeea296-2b28-432b-8d34-e9de03f7932b_1920x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h1><strong>Authors</strong></h1><ul><li><p><a href="https://www.linkedin.com/in/jocelynleeyh/">Jocelyn Lee</a> is a Researcher at SACR. She is a dual-degree candidate at Wharton and Penn Engineering, specializing in finance, statistics, and scientific computing. She is an incoming long/short equity analyst at Millennium, with experience across investment banking, fundamental investing, and strategy consulting, and has contributed to research in financial markets. She conducted extensive months of research to develop this study. </p></li></ul><h3><strong>Co-author:</strong></h3><ul><li><p><a href="https://www.linkedin.com/in/lawrencepingree/">Lawrence Pingree</a> is the Head of Data and AI Security at SACR, where he leads research on data protection, AI security, and agentic security models. He brings more than ten years of analyst experience from Gartner and has authored over 300 research notes across cloud security, endpoint defence, SD-WAN, and AI security.</p></li></ul><p></p><div><hr></div><h1><strong>Executive Summary</strong></h1><p>Enterprise security architecture is undergoing a structural break. The rapid adoption of AI and agents is not only reshaping enterprise security architectures, but it is also redefining how security budgets are allocated. The latest <a href="https://red.anthropic.com/2026/mythos-preview/">development by Claude Mythos</a> is evidence of the rapidly evolving landscape.</p><p>The security architecture required for AI agents is not entirely new; it is a convergence problem.</p><p>As identity, data, and runtime risk converge, our firm defined a new category for securing agents 2 months ago:&nbsp;<strong><a href="https://softwareanalyst.substack.com/p/the-convergence-of-ai-and-data-security">Unified Agentic Defence Platforms (UADP)</a>. </strong>This new stack is emerging as the next major control layer in cybersecurity. While our prior analysis focused on the technical architecture underpinning UADP, this report examines <em>the market through a different lens:</em> how <strong>spending is distributed today,</strong> <strong>which vendors are capturing share, and how platform consolidation will reshape the competitive landscape over the next five years.</strong></p><p>While emerging categories such as AI security posture management (AISPM) and non-human identity (NHI) security introduce newer controls tailored to secure new systems like LLM &amp; agents, they are insufficient on their own. Effective protection still depends on established domains such as DLP, DSPM, and ITDR, which provide the data visibility, classification, and identity-aware detection required to govern agent behaviour. The market, however, has not yet caught up to the architecture. Spending remains fragmented across: </p><ol><li><p><strong>DSPM</strong> - Data Security Posture Management</p></li><li><p><strong>DLP</strong> - Data Loss Prevention</p></li><li><p><strong>ITDR</strong> - Identity Threat Detection and Response</p></li><li><p><strong>NHI</strong> - Non-Human Identity (Encompasses machine and agent identities)</p></li><li><p><strong>AI security</strong> - AI-Security Posture Management, and AI runtime controls </p><p></p></li></ol><p>Each category reflects a partial view of the same underlying control problem. Over time, this fragmentation is expected to collapse as enterprises prioritize integrated platforms that enforce policy across domains.</p><p>This report breaks down that transition. It analyzes how security spending is distributed today, how it is likely to shift as convergence accelerates, and which vendors are structurally positioned to capture share in a unified control plane. The outcome is not just category growth, but a reallocation of power toward platforms that can operate across data, identity, and AI-driven execution.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!phUT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabeea296-2b28-432b-8d34-e9de03f7932b_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!phUT!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabeea296-2b28-432b-8d34-e9de03f7932b_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!phUT!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabeea296-2b28-432b-8d34-e9de03f7932b_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!phUT!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabeea296-2b28-432b-8d34-e9de03f7932b_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!phUT!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabeea296-2b28-432b-8d34-e9de03f7932b_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!phUT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabeea296-2b28-432b-8d34-e9de03f7932b_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/abeea296-2b28-432b-8d34-e9de03f7932b_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1175253,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://softwareanalyst.substack.com/i/191571789?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabeea296-2b28-432b-8d34-e9de03f7932b_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!phUT!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabeea296-2b28-432b-8d34-e9de03f7932b_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!phUT!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabeea296-2b28-432b-8d34-e9de03f7932b_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!phUT!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabeea296-2b28-432b-8d34-e9de03f7932b_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!phUT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabeea296-2b28-432b-8d34-e9de03f7932b_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Software Analyst Cyber Research! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><h2><strong>SACR Marketshare and Forecast Findings</strong></h2><p>Based on SACR&#8217;s proprietary projection, the <strong>UADP</strong> market is projected to grow from $8.30B in 2025 to $21.59B in 2030, implying approximately 21.08% CAGR through 2030.</p><ol><li><p><strong>DLP</strong> remains the largest and most mature segment, growing from $3.76 billion to $6.95 billion (13.06% CAGR), anchored by decades of deployment across enterprise environments.</p></li><li><p><strong>ITDR</strong> is the second-largest and most mature category, expanding from $1.53 billion to $4.10 billion (21.80% CAGR) as identity becomes the primary attack surface.</p></li><li><p><strong>DSPM</strong> scales from $1.37 billion to $4.17 billion (24.95% CAGR) as organizations seek control over sensitive data in cloud and analytics environments.</p></li><li><p><strong>NHI</strong> <strong>security</strong> expands from $0.94 billion to $3.29 billion (28.37% CAGR) as machine identities proliferate across infrastructure and applications.</p></li><li><p><strong>AI</strong> <strong>security</strong> grows from $0.69 billion to $2.48 billion (29.16% CAGR) as enterprises move AI into production.</p><p></p></li></ol><h2><strong>Actionable Recommendations</strong></h2><p><strong>For CaISOs and Practitioners</strong></p><ul><li><p><strong>Prioritize Unified Control Planes:</strong> Shift away from isolated point solutions toward integrated UADP architectures that can correlate signals across domains (data sensitivity, identity privileges, runtime behavior, and AI interactions) in real time.</p></li><li><p><strong>Address Runtime Security:</strong> Treat AI security as an operational discipline, focusing on controls that monitor and intervene in the runtime layer during live interactions to prevent prompt injection, unauthorized data retrieval, and agent-driven privilege escalation.</p></li><li><p><strong>Expand Identity Governance:</strong> Extend governance programs to cover the new category of non-human identities, including AI agents and automated workflows, by combining identity visibility, behavioral monitoring, and policy enforcement.</p></li></ul><p><strong>For Vendors</strong></p><ul><li><p><strong>Pursue Integration:</strong> Competitive positioning requires integrating capabilities across the five foundational pillars (DSPM, DLP, NHI, ITDR, and AI security) to assemble a unified operational platform.</p></li><li><p><strong>Leverage Distribution and M&amp;A:</strong> Platform integration, strategic acquisitions (like Palo Alto Networks acquiring CyberArk, or Google acquiring Wiz), and ecosystem partnerships should be key elements of strategy to capture disproportionate share. Vendors that control identity, cloud, or productivity ecosystems have a strong distribution advantage.</p></li><li><p><strong>Focus on AI Runtime:</strong> Emphasize capabilities for real-time protection of prompts, model responses, and agent behavior, as this is emerging as the fastest-growing control layer.</p></li></ul><p><strong>For Investors</strong></p><ul><li><p><strong>Target Intersection Points:</strong> Focus on vendors positioned at the intersection of multiple UADP pillars, as they are likely to benefit from platform consolidation dynamics similar to those seen in XDR and CNAPP.</p></li><li><p><strong>Identify Acquisition Targets:</strong> Anticipate that specialist vendors with differentiated capabilities in high-growth segments (like AI security and NHI governance) will become acquisition targets for larger platforms.</p></li></ul><p></p><div><hr></div><h1><strong>Market Definition</strong></h1><h2><strong>Unified Agentic Defense Platforms (UADP)</strong></h2><p>This report refers to the emerging architectural category as <em><a href="https://softwareanalyst.substack.com/p/the-convergence-of-ai-and-data-security">Unified Agentic Defense Platforms (UADP)</a></em>.</p><p>UADPs are Integrated platforms that combine data security, AI and AI agent governance, identity behavior context, runtime enforcement, and detection and response to secure AI models, AI agents, and the data/workflows they process.</p><h3><strong>Defining Technology, Feature(s), and Service Lines</strong></h3><p>AI-driven data protection and governance now encompass a comprehensive framework that is specifically designed to address the unique challenges posed by intelligent agents and agentic workflows. This includes advanced capabilities such as classification of sensitive data, redaction or masking of personally identifiable information (PII), and DLP-style inspection and enforcement mechanisms applied directly to prompts, model outputs, and tool calls. The system extends beyond static controls through Data Security Posture Management (DSPM), enabling continuous discovery of sensitive data sources, such as data lakes, cloud-based SaaS applications, vector databases, and RAG stores,and providing contextual risk assessments for these environments. It also detects and monitors Shadow AI, identifying unauthorized or unapproved AI tools, agents, and agentic workflows that operate outside formal governance policies.</p><p>UADPs offer AI governance and compliance, which ensures alignment with responsible AI principles and evolving regulatory standards throughout the entire lifecycle of AI pipelines, infrastructure, and workflows. A key component involves identity and intent context,offering visibility into both human and non-human actors (such as agents or service accounts) participating in AI processes, to enable precise policy enforcement decisions. Runtime protection mechanisms provide inline controls at the edge of AI and agent workloads, including through proxies and APIs, enabling real-time intervention when anomalies or violations occur. UADP threat detection and response systems are designed to proactively identify critical risks such as prompt injection or linguistic manipulation (LPCI), agent hijacking, and data tampering, offering automated containment and prevention strategies to safeguard AI system integrity and maintain trust in autonomous workflows.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!mwEx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F400e75f0-fc9f-489a-b8c5-1b0ed727d5ff_2088x1178.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!mwEx!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F400e75f0-fc9f-489a-b8c5-1b0ed727d5ff_2088x1178.png 424w, https://substackcdn.com/image/fetch/$s_!mwEx!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F400e75f0-fc9f-489a-b8c5-1b0ed727d5ff_2088x1178.png 848w, https://substackcdn.com/image/fetch/$s_!mwEx!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F400e75f0-fc9f-489a-b8c5-1b0ed727d5ff_2088x1178.png 1272w, https://substackcdn.com/image/fetch/$s_!mwEx!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F400e75f0-fc9f-489a-b8c5-1b0ed727d5ff_2088x1178.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!mwEx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F400e75f0-fc9f-489a-b8c5-1b0ed727d5ff_2088x1178.png" width="1456" height="821" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/400e75f0-fc9f-489a-b8c5-1b0ed727d5ff_2088x1178.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:821,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:908689,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://softwareanalyst.substack.com/i/191571789?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F400e75f0-fc9f-489a-b8c5-1b0ed727d5ff_2088x1178.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!mwEx!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F400e75f0-fc9f-489a-b8c5-1b0ed727d5ff_2088x1178.png 424w, https://substackcdn.com/image/fetch/$s_!mwEx!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F400e75f0-fc9f-489a-b8c5-1b0ed727d5ff_2088x1178.png 848w, https://substackcdn.com/image/fetch/$s_!mwEx!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F400e75f0-fc9f-489a-b8c5-1b0ed727d5ff_2088x1178.png 1272w, https://substackcdn.com/image/fetch/$s_!mwEx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F400e75f0-fc9f-489a-b8c5-1b0ed727d5ff_2088x1178.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><div><hr></div><h1><strong>Introduction and Scope</strong></h1><h1><strong>Report Objective &amp; Methodology</strong></h1><p>The objective of this report is to estimate the size and growth trajectory of the Unified Agentic Defense Platform market.</p><p>The analysis quantifies 2025 market sizes across the five core functional pillars (DSPM, DLP, AI security, ITDR, and non-human identity security) that collectively comprise the UADP architectures, technologies being consolidated, and projects moving forward through 2030 to assess long-term structural growth. For each pillar, the report identifies the top fifteen vendors, estimates the remaining Others segment to capture the long tail of participants, and aggregates the categories to derive a consolidated industry view. Growth is evaluated from both historical momentum as well as forward-looking acceleration.</p><h2><strong>Estimation Methodology</strong></h2><p>The UADP market is constructed as a derived consolidation layer on top of the five component pillars rather than an independently sized category. In the base year, UADP is represented as the direct aggregation of the five categories, reflecting a market where capabilities are still purchased separately. From this baseline, the forward model introduces a convergence adjustment that reflects the increasing consolidation of these capabilities into integrated platforms. This adjustment is not applied at the vendor level, but at the market level to capture shifts in enterprise buying behavior, where multiple point solutions are replaced by unified architectures. As a result, while the underlying segments continue to grow independently, the realized UADP market diverges from the simple sum over time.</p><p>The methodology for this Industry Outlook Projection employs a structured, triangulated approach using multiple data sources and proprietary estimation models to derive current market share and future growth projections. For publicly traded companies, factual data points such as market share and size are extracted and verified through mandated public disclosures, including SEC filings and official press releases. This analysis also incorporates proprietary and indicative data from market research, funding data, and operational indicators like employee count and hiring patterns. For early-stage startups, revenue is estimated by analyzing funding data, active hiring patterns, and public job postings. Valuation analysis combines pricing and customer count data with valuation-to-revenue multiple disclosures. Estimates are adjusted by consideration of technology emergence, market adoption momentum, replacement lifecycles and overall technology maturity.</p><p>The forecast projection incorporates a forward-looking future view analysis based on compound annual growth rate (CAGR) and leverages changes in hiring patterns to gauge company momentum and overall market growth. Revenue is attributed strictly on the basis of functional alignment with the scoped definitions for each pillar. Only monetized software revenue directly mapped to the defined capabilities is included. Where revenue is embedded within broader platform bundles, proportional allocation is applied based on product positioning, disclosure transparency, and competitive context.</p><h2><strong>Defined Segmentation Method</strong></h2><p>Each market share estimate presented in this report is paired with a formal market definition to ensure consistency and analytical discipline. Revenue is included only when the capability aligns directly with the defined functional scope of the category. Standalone IAM seat licensing, pure telemetry or SOC analytics platforms, endpoint protection products without integrated data context, backup and recovery solutions, compliance documentation tools, and security services revenue are excluded from the sizing model. This disciplined scoping approach is intended to prevent double counting and to ensure that the resulting estimates reflect architectural convergence rather than simple aggregation of adjacent security markets. This report solely represents Software Analyst Cyber Research (SACR)&#8217;s point of view rather than asserts an objective truth.</p><h1><strong>Core UADP Consolidating Markets</strong></h1><p>UADPs are constructed from five explicitly defined core categories, each representing a foundational functional pillar with clearly delineated capability requirements used to guide inclusion and analysis.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_nPm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcef1ecd3-d499-41f1-b63d-9b91c9159550_818x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_nPm!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcef1ecd3-d499-41f1-b63d-9b91c9159550_818x1024.png 424w, https://substackcdn.com/image/fetch/$s_!_nPm!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcef1ecd3-d499-41f1-b63d-9b91c9159550_818x1024.png 848w, https://substackcdn.com/image/fetch/$s_!_nPm!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcef1ecd3-d499-41f1-b63d-9b91c9159550_818x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!_nPm!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcef1ecd3-d499-41f1-b63d-9b91c9159550_818x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_nPm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcef1ecd3-d499-41f1-b63d-9b91c9159550_818x1024.png" width="818" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cef1ecd3-d499-41f1-b63d-9b91c9159550_818x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:818,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Core consolidating markets for UADP including DSPM, DLP, AI Security, ITDR, and NHI&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Core consolidating markets for UADP including DSPM, DLP, AI Security, ITDR, and NHI" title="Core consolidating markets for UADP including DSPM, DLP, AI Security, ITDR, and NHI" srcset="https://substackcdn.com/image/fetch/$s_!_nPm!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcef1ecd3-d499-41f1-b63d-9b91c9159550_818x1024.png 424w, https://substackcdn.com/image/fetch/$s_!_nPm!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcef1ecd3-d499-41f1-b63d-9b91c9159550_818x1024.png 848w, https://substackcdn.com/image/fetch/$s_!_nPm!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcef1ecd3-d499-41f1-b63d-9b91c9159550_818x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!_nPm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcef1ecd3-d499-41f1-b63d-9b91c9159550_818x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>UADP Architecture Model</strong></h2><p>UADP architectures integrate signals from data security, identity governance, behavioral detection, and AI protection into a unified decision control plane. Policy decisions generated within this layer are enforced through existing infrastructure security controls such as network gateways, endpoint protection platforms, SaaS governance tools, and cloud workload security systems.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ihOX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c9e2e35-d47a-44df-bd4f-5241955fbea2_1600x900.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ihOX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c9e2e35-d47a-44df-bd4f-5241955fbea2_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!ihOX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c9e2e35-d47a-44df-bd4f-5241955fbea2_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!ihOX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c9e2e35-d47a-44df-bd4f-5241955fbea2_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!ihOX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c9e2e35-d47a-44df-bd4f-5241955fbea2_1600x900.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ihOX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c9e2e35-d47a-44df-bd4f-5241955fbea2_1600x900.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4c9e2e35-d47a-44df-bd4f-5241955fbea2_1600x900.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;UADP Architecture Model showing integration of signals into a unified decision control plane&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="UADP Architecture Model showing integration of signals into a unified decision control plane" title="UADP Architecture Model showing integration of signals into a unified decision control plane" srcset="https://substackcdn.com/image/fetch/$s_!ihOX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c9e2e35-d47a-44df-bd4f-5241955fbea2_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!ihOX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c9e2e35-d47a-44df-bd4f-5241955fbea2_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!ihOX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c9e2e35-d47a-44df-bd4f-5241955fbea2_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!ihOX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c9e2e35-d47a-44df-bd4f-5241955fbea2_1600x900.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1><strong>Revenue Inclusions and Exclusions</strong></h1><p>For the purpose of this report, which estimates the size of the UADP market, revenue attribution is strictly limited to integrated platform software aligned with the UADP architectural definition.</p><p>The objective of this scoping is to isolate revenue directly associated with unified, cross-domain defense control planes - not adjacent or legacy security categories.</p><p>Revenue attributable to UADPs includes monetized software modules that are architecturally integrated and aligned to one or more of the following functional domains within a unified platform: DSPM, DLP, AI Security, NHI, or ITDR.</p><p>On the other hand, examples of revenue explicitly excluded from the revenue sizing include:</p><ul><li><p><strong>Standalone IAM Seat Licensing:</strong> Authentication and access management revenue derived from MFA, SSO, directory services, and baseline access control products where no integrated risk reasoning or enforcement control plane exists.</p></li><li><p><strong>Pure-Play SIEM, XDR, or SOC Telemetry Platforms:</strong> Telemetry ingestion, log analytics, detection platforms, and SOC tooling that lack embedded data context, AI lifecycle governance, and inline enforcement capabilities.</p></li><li><p><strong>Endpoint Protection Products (EDR/AV):</strong> Endpoint security tools that operate independently of data classification, AI governance, or identity-aware enforcement frameworks.</p></li><li><p><strong>Backup, Recovery, and Data Resilience Platforms:</strong> Solutions focused on post-breach recovery, archival storage, or resilience rather than live interaction prevention and unified control.</p></li><li><p><strong>Pure Compliance Documentation or GRC Platforms:</strong> Policy documentation, audit workflow management, and regulatory reporting systems that do not provide runtime intervention capabilities.</p></li><li><p><strong>Security Services and Consulting Revenue</strong>: Managed services, MSSP contracts, advisory services, professional services, and incident response retainers.</p></li><li><p><strong>Standalone Secrets Management or Vaulting:</strong>Machine identity tools that do not integrate behavioral detection and data-aware enforcement into a unified reasoning layer.</p></li></ul><h1><strong>Sub-Segments Industry Analysis</strong></h1><p>Historically, capabilities such as data loss prevention, data security posture management, identity threat detection, and machine identity governance developed as separate product categories addressing specific risk surfaces within enterprise environments. However, the increasing interaction between enterprise data, automated identities, and AI-driven workflows is blurring the boundaries between these markets. Vendors are responding by integrating capabilities that were once delivered through standalone tools into broader security platforms capable of providing unified visibility and enforcement across data, identities, and runtime environments.</p><p>To understand how this convergence is shaping the emerging Unified Agentic Defense Platform (UADP) market, it is first necessary to examine the underlying markets from which these capabilities originate. The following sections analyze the major security domains that collectively form the foundation of the UADP architecture.</p><h2><strong>1) Data Loss Prevention (DLP)</strong></h2><p>DLP in the UADP market is a security capability that monitors and enforces policies on data in motion and use, preventing sensitive information from being exposed or exfiltrated through real-time inspection, detection, and blocking mechanisms across systems and workflows.</p><p>The DLP market is projected to grow from $3.76B in 2025 to $6.95B in 2030, implying a ~13.06% CAGR.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!fLJz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F231e92fe-a12c-45bc-8a05-fbd27ee60f99_1112x612.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!fLJz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F231e92fe-a12c-45bc-8a05-fbd27ee60f99_1112x612.png 424w, https://substackcdn.com/image/fetch/$s_!fLJz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F231e92fe-a12c-45bc-8a05-fbd27ee60f99_1112x612.png 848w, https://substackcdn.com/image/fetch/$s_!fLJz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F231e92fe-a12c-45bc-8a05-fbd27ee60f99_1112x612.png 1272w, https://substackcdn.com/image/fetch/$s_!fLJz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F231e92fe-a12c-45bc-8a05-fbd27ee60f99_1112x612.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!fLJz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F231e92fe-a12c-45bc-8a05-fbd27ee60f99_1112x612.png" width="1112" height="612" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/231e92fe-a12c-45bc-8a05-fbd27ee60f99_1112x612.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:612,&quot;width&quot;:1112,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Data Loss Prevention DLP Market Share estimates for 2025&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Data Loss Prevention DLP Market Share estimates for 2025" title="Data Loss Prevention DLP Market Share estimates for 2025" srcset="https://substackcdn.com/image/fetch/$s_!fLJz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F231e92fe-a12c-45bc-8a05-fbd27ee60f99_1112x612.png 424w, https://substackcdn.com/image/fetch/$s_!fLJz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F231e92fe-a12c-45bc-8a05-fbd27ee60f99_1112x612.png 848w, https://substackcdn.com/image/fetch/$s_!fLJz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F231e92fe-a12c-45bc-8a05-fbd27ee60f99_1112x612.png 1272w, https://substackcdn.com/image/fetch/$s_!fLJz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F231e92fe-a12c-45bc-8a05-fbd27ee60f99_1112x612.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>2025 Market Share Analysis</strong></h3><p>The current structure of the DLP market reflects a fundamental shift in how enterprise data is created, accessed, and transmitted. Historically, DLP deployments were concentrated at network gateways and managed endpoints, where traffic inspection and perimeter enforcement were feasible. However, as enterprise workflows have moved toward SaaS applications, cloud collaboration platforms, and browser-mediated interactions, DLP deployment models have evolved accordingly. As a result, market share is increasingly determined not solely by inspection capabilities or classification depth, but by control over the operational surfaces where data flows. Vendors that are embedded within collaboration environments, SaaS ecosystems, and access layers are better positioned to apply data protection policies with minimal deployment overhead. This shift has reoriented competitive dynamics away from standalone inspection engines and toward distribution advantage within existing enterprise workflows.</p><h3><strong>Top 15 Players in 2025</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!zEMt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d38847c-8275-43af-92be-8e3f2a84081e_1442x808.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!zEMt!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d38847c-8275-43af-92be-8e3f2a84081e_1442x808.png 424w, https://substackcdn.com/image/fetch/$s_!zEMt!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d38847c-8275-43af-92be-8e3f2a84081e_1442x808.png 848w, https://substackcdn.com/image/fetch/$s_!zEMt!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d38847c-8275-43af-92be-8e3f2a84081e_1442x808.png 1272w, https://substackcdn.com/image/fetch/$s_!zEMt!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d38847c-8275-43af-92be-8e3f2a84081e_1442x808.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!zEMt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d38847c-8275-43af-92be-8e3f2a84081e_1442x808.png" width="1442" height="808" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0d38847c-8275-43af-92be-8e3f2a84081e_1442x808.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:808,&quot;width&quot;:1442,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!zEMt!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d38847c-8275-43af-92be-8e3f2a84081e_1442x808.png 424w, https://substackcdn.com/image/fetch/$s_!zEMt!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d38847c-8275-43af-92be-8e3f2a84081e_1442x808.png 848w, https://substackcdn.com/image/fetch/$s_!zEMt!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d38847c-8275-43af-92be-8e3f2a84081e_1442x808.png 1272w, https://substackcdn.com/image/fetch/$s_!zEMt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d38847c-8275-43af-92be-8e3f2a84081e_1442x808.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>Platform distribution advantages</strong></h3><p>A significant portion of market share is concentrated among vendors that operate platforms where enterprise data already resides. Productivity suites, cloud collaboration environments, and integrated compliance frameworks provide natural insertion points for DLP controls. Within these environments, data protection capabilities are often activated through policy configuration rather than deployed as separate products. Microsoft is a primary example of this dynamic. Its DLP capabilities are integrated across Microsoft 365, Purview, and related compliance services, enabling organizations to extend data protection policies across email, documents, and collaboration workflows without additional infrastructure. More broadly, platform vendors benefit from pre-existing integration into day-to-day enterprise operations, which lowers friction for adoption and accelerates deployment at scale.</p><p>This distribution advantage is further reinforced by the increasing integration of AI capabilities into productivity environments. As generative AI systems interact directly with enterprise content, data protection is increasingly treated as a prerequisite for safe AI adoption. Vendors that control document repositories and collaboration layers can extend existing classification and governance frameworks into AI-driven workflows with limited incremental effort. Over time, this dynamic supports a consolidation trend characterized by a &#8220;good enough, already licensed&#8221; adoption pattern. Enterprises with established governance and compliance programs often expand existing platform-native DLP capabilities rather than procure standalone solutions. Consequently, a meaningful portion of incremental DLP adoption is driven by expansion within installed platforms rather than net-new product deployments.</p><h3><strong>SSE and SASE platform expansion</strong></h3><p>A second driver of market evolution is the growing role of SSE and SASE platforms in delivering DLP capabilities at the traffic layer. As enterprise data increasingly moves across SaaS applications, web sessions, and unmanaged devices, enforcement is shifting toward inline control points rather than traditional endpoint or gateway-based architectures. These platforms embed DLP directly into secure web gateways, CASB layers, and browser-mediated access, enabling real-time inspection and policy enforcement at the point of data interaction. This positioning is particularly effective in cloud-first environments where data flows bypass traditional network controls. Recent M&amp;A activity reinforces this shift toward access-layer DLP with improved data context. Zscaler&#8217;s acquisition of Avalor enhances policy accuracy through deeper classification and context, while Netskope&#8217;s acquisition of Dasera expands visibility into structured data environments, strengthening enforcement across SaaS and cloud data flows. Palo Alto Networks&#8217; acquisition of Talon Cyber Security further extends DLP enforcement into the enterprise browser, enabling policy control directly within user sessions.Collectively, these developments indicate that SSE and SASE vendors are redefining DLP as an inline, access-layer capability, positioning them to capture a growing share of net-new deployments in distributed, SaaS-driven environments</p><h3><strong>Pressure on legacy gateway DLP vendors</strong></h3><p>Vendors historically associated with gateway centric DLP architectures face slower incremental growth. Many of these platforms were designed around inspecting traffic moving through corporate networks and enforcing policies through tightly controlled endpoints guarded by centralized networks and entrances to the internet . While these architectures remain deeply embedded within large enterprises, they are less aligned with cloud native and SaaS aligned environments where data moves directly between Cloud and SaaS applications or across browser based collaboration applications and tooling.</p><p>This does not imply immediate displacement. Vendors such as Broadcom continue to maintain a substantial installed base in endpoint DLP, supported by mature classification engines and highly granular policy frameworks developed over many years of enterprise deployments. However, the pace of new deployments increasingly favors architectures that require fewer infrastructure or endpoint dependencies and integrate more naturally with SaaS and cloud collaboration environments. As a result, legacy vendors are likely to retain meaningful market share but capture a smaller portion of net new growth and are increasingly being displaced by vendors with better alignment with SaaS, Browser and Cloud native data loss prevention functionality.</p><h2><strong>2) Data Security Posture Management (DSPM)</strong></h2><p>DSPM in the UADP market is a security capability that discovers, classifies, and monitors sensitive data across environments, identifying exposure risks and misconfigurations through continuous visibility into data location, access paths, and contextual usage.</p><p>The DSPM market is projected to grow from $1.37B in 2025 to $4.17B in 2030, implying a ~24.95% CAGR.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2KXC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc07a7888-133a-4ca0-bdd0-892557065615_1600x895.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2KXC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc07a7888-133a-4ca0-bdd0-892557065615_1600x895.png 424w, https://substackcdn.com/image/fetch/$s_!2KXC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc07a7888-133a-4ca0-bdd0-892557065615_1600x895.png 848w, https://substackcdn.com/image/fetch/$s_!2KXC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc07a7888-133a-4ca0-bdd0-892557065615_1600x895.png 1272w, https://substackcdn.com/image/fetch/$s_!2KXC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc07a7888-133a-4ca0-bdd0-892557065615_1600x895.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2KXC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc07a7888-133a-4ca0-bdd0-892557065615_1600x895.png" width="1456" height="814" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c07a7888-133a-4ca0-bdd0-892557065615_1600x895.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:814,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Data Security Posture Management DSPM Market Share estimates for 2025&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Data Security Posture Management DSPM Market Share estimates for 2025" title="Data Security Posture Management DSPM Market Share estimates for 2025" srcset="https://substackcdn.com/image/fetch/$s_!2KXC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc07a7888-133a-4ca0-bdd0-892557065615_1600x895.png 424w, https://substackcdn.com/image/fetch/$s_!2KXC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc07a7888-133a-4ca0-bdd0-892557065615_1600x895.png 848w, https://substackcdn.com/image/fetch/$s_!2KXC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc07a7888-133a-4ca0-bdd0-892557065615_1600x895.png 1272w, https://substackcdn.com/image/fetch/$s_!2KXC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc07a7888-133a-4ca0-bdd0-892557065615_1600x895.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>2025 Market Share Analysis</strong></h3><p>The current distribution of share reflects both where enterprise data resides and which teams are responsible for governing it. Unlike earlier data security tools focused on classification or compliance reporting, DSPM emerged to address a visibility gap created by rapid cloud adoption. Sensitive data is now distributed across object storage, SaaS platforms, analytics environments, and AI pipelines that traditional controls were not designed to monitor. As a result, DSPM adoption is driven by multiple enterprise buying centers, producing a fragmented market in which vendors gain traction through distinct operational entry points.</p><h3><strong>Top 15 Players in 2025</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!pIgM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1693ef6c-840d-4276-a020-4d74ac258265_1600x894.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!pIgM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1693ef6c-840d-4276-a020-4d74ac258265_1600x894.png 424w, https://substackcdn.com/image/fetch/$s_!pIgM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1693ef6c-840d-4276-a020-4d74ac258265_1600x894.png 848w, https://substackcdn.com/image/fetch/$s_!pIgM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1693ef6c-840d-4276-a020-4d74ac258265_1600x894.png 1272w, https://substackcdn.com/image/fetch/$s_!pIgM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1693ef6c-840d-4276-a020-4d74ac258265_1600x894.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!pIgM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1693ef6c-840d-4276-a020-4d74ac258265_1600x894.png" width="1456" height="814" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1693ef6c-840d-4276-a020-4d74ac258265_1600x894.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:814,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Top 15 Players in the Data Security Posture Management DSPM Market for 2025&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Top 15 Players in the Data Security Posture Management DSPM Market for 2025" title="Top 15 Players in the Data Security Posture Management DSPM Market for 2025" srcset="https://substackcdn.com/image/fetch/$s_!pIgM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1693ef6c-840d-4276-a020-4d74ac258265_1600x894.png 424w, https://substackcdn.com/image/fetch/$s_!pIgM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1693ef6c-840d-4276-a020-4d74ac258265_1600x894.png 848w, https://substackcdn.com/image/fetch/$s_!pIgM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1693ef6c-840d-4276-a020-4d74ac258265_1600x894.png 1272w, https://substackcdn.com/image/fetch/$s_!pIgM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1693ef6c-840d-4276-a020-4d74ac258265_1600x894.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>Data governance heritage and entitlement visibility</strong></h3><p>One of the largest problem spaces in enterprise environments has been data visibility. Thus, several of the foundational leaders in DSPM gained share by building deep visibility into enterprise data estates and the identities that can access them. Vendors that originated in data governance or insider risk detection developed strong capabilities around entitlement mapping, classification depth, and remediation workflows. These features remain particularly valuable in environments where sensitive data resides in collaboration platforms, file systems, and enterprise SaaS applications.</p><p>Varonis illustrates this dynamic. Its long focus on entitlement analysis and automated remediation positioned it well as organizations began seeking ways to understand which users and services could access sensitive information stored across large collaboration environments. In many enterprises, DSPM adoption initially occurs through governance teams attempting to reduce overexposed data stores or enforce least privilege access policies. Vendors that built mature discovery engines and remediation automation therefore retain strong positions in environments where operational data governance remains the primary objective.</p><h3><strong>Cloud security platforms expanding into data visibility</strong></h3><p>A second channel for DSPM adoption has emerged from cloud security and CNAPP platforms. As organizations migrated infrastructure and analytics workloads into public cloud environments, cloud security teams began seeking ways to identify sensitive data residing inside cloud storage, databases, and data pipelines. In these environments, DSPM capabilities are often purchased as an extension of broader cloud security and risk management programs.</p><p>Vendors such as Wiz and Palo Alto Networks have benefited from this shift by embedding data discovery and exposure mapping inside their existing cloud security platforms. When organizations already rely on a cloud security graph to monitor misconfigurations and workload vulnerabilities, adding visibility into sensitive data stores becomes a natural adjacency. This dynamic has allowed cloud security platforms to expand into the DSPM category without necessarily positioning it as a standalone product. Instead, DSPM capabilities function as an additional layer of context within broader cloud risk management frameworks.</p><h3><strong>Cyber resilience platforms entering the category</strong></h3><p>Another emerging source of DSPM adoption comes from cyber resilience and backup vendors expanding beyond traditional recovery capabilities. Historically, backup platforms focused on ensuring that organizations could restore systems after ransomware incidents. However, as ransomware attacks increasingly target sensitive data repositories, resilience programs have begun incorporating preventative visibility into data exposure.</p><p>Vendors such as Rubrik and Veeam have therefore expanded their platforms to include capabilities that identify where sensitive data resides and how it is accessed before an incident occurs. This evolution reflects a broader shift in enterprise security priorities. Organizations are no longer evaluating data protection solely through the lens of recovery performance but also through their ability to understand and reduce data risk before an attack takes place. As a result, DSPM spending is increasingly appearing within cyber resilience budgets rather than purely within governance or compliance programs.</p><h3><strong>Platform bundling and distribution advantages</strong></h3><p>As the category matures, distribution and platform leverage are becoming more important determinants of market share than discovery technology alone. Many enterprises now view DSPM as a prerequisite for broader initiatives such as AI governance, data access control, or regulatory compliance. When DSPM is bundled within larger security or compliance suites, adoption can scale quickly through attached sales and expansion rather than through dedicated procurement cycles.</p><p>Large platform vendors therefore benefit from significant distribution advantages. When DSPM capabilities are embedded within cloud security, compliance platforms, or data governance frameworks, organizations can activate sensitive data visibility without deploying a separate tool. This dynamic has allowed vendors with large installed bases to expand DSPM adoption across existing customers even if their products are not the deepest in every feature category. At the same time, specialized DSPM vendors remain competitive when buyers prioritize deep classification, granular entitlement mapping, and operational remediation.</p><h2><strong>3) AI Security</strong></h2><p>AI security in the UADP market is a security capability that monitors and protects AI systems and workflows, preventing misuse, data leakage, and model abuse through real-time inspection, policy enforcement, and control of prompts, outputs, and agent behavior.</p><p>The AI Security market is projected to grow from $0.69B in 2025 to $2.48B in 2030, implying a ~29.16% CAGR.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7c6A!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa51169dc-e55f-40ce-b207-ae253a94be2f_1096x608.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7c6A!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa51169dc-e55f-40ce-b207-ae253a94be2f_1096x608.png 424w, https://substackcdn.com/image/fetch/$s_!7c6A!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa51169dc-e55f-40ce-b207-ae253a94be2f_1096x608.png 848w, https://substackcdn.com/image/fetch/$s_!7c6A!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa51169dc-e55f-40ce-b207-ae253a94be2f_1096x608.png 1272w, https://substackcdn.com/image/fetch/$s_!7c6A!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa51169dc-e55f-40ce-b207-ae253a94be2f_1096x608.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7c6A!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa51169dc-e55f-40ce-b207-ae253a94be2f_1096x608.png" width="1096" height="608" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a51169dc-e55f-40ce-b207-ae253a94be2f_1096x608.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:608,&quot;width&quot;:1096,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;AI Security Market Share estimates for 2025&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="AI Security Market Share estimates for 2025" title="AI Security Market Share estimates for 2025" srcset="https://substackcdn.com/image/fetch/$s_!7c6A!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa51169dc-e55f-40ce-b207-ae253a94be2f_1096x608.png 424w, https://substackcdn.com/image/fetch/$s_!7c6A!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa51169dc-e55f-40ce-b207-ae253a94be2f_1096x608.png 848w, https://substackcdn.com/image/fetch/$s_!7c6A!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa51169dc-e55f-40ce-b207-ae253a94be2f_1096x608.png 1272w, https://substackcdn.com/image/fetch/$s_!7c6A!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa51169dc-e55f-40ce-b207-ae253a94be2f_1096x608.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>2025 Market Share Analysis</strong></h3><p>The current distribution of share reflects a category that is still forming, with adoption largely occurring through extensions of existing security and cloud platforms rather than standalone procurement. As enterprises deploy AI within established infrastructure and productivity environments, security controls are frequently embedded into broader platforms, resulting in early share concentration among large ecosystem vendors.</p><p>At the same time, a fragmented set of vendors continues to compete across specific segments of the problem, including runtime protection, AI governance, and data-centric controls. Vendors such as Palo Alto Networks, CrowdStrike, Zscaler, Check Point, Netskope, Varonis, HiddenLayer, Noma, and BigID represent a mix of platform extensions and emerging AI-focused capabilities, illustrating a market where platform distribution and point-solution depth coexist.</p><h3><strong>Top 15 Players in 2025</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rYU5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9da46d6-c28d-4ef3-8b76-660ddff5457f_1092x600.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rYU5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9da46d6-c28d-4ef3-8b76-660ddff5457f_1092x600.png 424w, https://substackcdn.com/image/fetch/$s_!rYU5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9da46d6-c28d-4ef3-8b76-660ddff5457f_1092x600.png 848w, https://substackcdn.com/image/fetch/$s_!rYU5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9da46d6-c28d-4ef3-8b76-660ddff5457f_1092x600.png 1272w, https://substackcdn.com/image/fetch/$s_!rYU5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9da46d6-c28d-4ef3-8b76-660ddff5457f_1092x600.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rYU5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9da46d6-c28d-4ef3-8b76-660ddff5457f_1092x600.png" width="1092" height="600" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a9da46d6-c28d-4ef3-8b76-660ddff5457f_1092x600.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:600,&quot;width&quot;:1092,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Top 15 Players in the AI Security Market for 2025&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Top 15 Players in the AI Security Market for 2025" title="Top 15 Players in the AI Security Market for 2025" srcset="https://substackcdn.com/image/fetch/$s_!rYU5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9da46d6-c28d-4ef3-8b76-660ddff5457f_1092x600.png 424w, https://substackcdn.com/image/fetch/$s_!rYU5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9da46d6-c28d-4ef3-8b76-660ddff5457f_1092x600.png 848w, https://substackcdn.com/image/fetch/$s_!rYU5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9da46d6-c28d-4ef3-8b76-660ddff5457f_1092x600.png 1272w, https://substackcdn.com/image/fetch/$s_!rYU5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9da46d6-c28d-4ef3-8b76-660ddff5457f_1092x600.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>Platform vendors benefit from control of the surrounding ecosystem</strong></h3><p>A significant share of AI security adoption is accruing to vendors that control the environments where AI systems are built and consumed. Cloud platforms, productivity suites, and identity layers provide natural insertion points for AI security controls, allowing vendors to extend governance and enforcement into AI workflows with minimal deployment friction.</p><p>Microsoft&#8217;s position reflects this dynamic. Its share is driven not only by discrete AI security features, but by its ability to integrate controls across Entra, Purview, Defender, and Microsoft 365. This enables organizations to address AI-related risks within existing compliance and security programs rather than through separate product adoption. More broadly, platform control is emerging as a primary determinant of share, as enterprises favor solutions that inherit existing identity, data, and policy context.</p><h3><strong>Runtime protection is emerging as the fastest growing control layer</strong></h3><p>As AI deployments move from experimentation into production, security priorities are shifting toward runtime enforcement. Early investment focused on governance and model visibility, but the most critical risks such as prompt injection, unauthorized data access, and unsafe agent behavior occur during live interactions.</p><p>This shift is driving demand for inline controls that operate within AI workflows. Vendors such as Check Point, SentinelOne, and Netskope are incorporating capabilities to inspect prompts, govern agent actions, and enforce policies in real time. Check Point&#8217;s acquisition of Lakera reflects this transition toward runtime-centric security, emphasizing protection at the interaction layer rather than static model analysis. As enterprises operationalize AI systems, runtime protection is likely to capture a growing share of spending.</p><h3><strong>AI security is increasingly being pulled into data security and cloud security budgets</strong></h3><p>Although AI security is often discussed as a standalone market, much of its actual budget is being pulled through adjacent categories and the platform concept articulated as UADP. In many enterprises, the first concrete AI security question is not how to secure a model in the abstract, but how to prevent sensitive enterprise data from being exposed through prompts, retrieval systems, or agentic workflows. In other environments, the starting point is cloud security, where teams need visibility into which models, datasets, and AI services are running in production and how they connect to broader infrastructure.</p><p>This creates a market structure in which AI security adoption frequently rides on top of existing data security and cloud security programs. Data-centric vendors such as Varonis and BigID address AI risk through classification, access governance, and visibility into how sensitive data is accessed by AI systems. In parallel, cloud and access-layer vendors such as Palo Alto Networks, Zscaler, and Netskope incorporate AI visibility and controls into broader infrastructure and traffic management frameworks. This results in a market structure where AI security adoption is pulled through existing control planes, rather than driven by standalone purchasing decisions. Over time, vendors that can embed AI security within broader platforms, aligned to UADP, are likely to benefit from this dynamic.</p><h3><strong>Specialists retain an advantage where workflow depth matters most</strong></h3><p>Despite the distribution advantages of large platforms, specialist vendors remain highly relevant because product differentiation in AI security is still real. The category is evolving quickly, and many enterprises require controls that go beyond broad platform visibility. This is particularly true in environments where organizations are building their own AI applications, orchestrating agents, or securing complex RAG and MCP-based workflows. In these use cases, buyers often prioritize technical depth, response latency, and workflow-level interpretability over broad suite integration.</p><p>Vendors such as HiddenLayer and Noma focus on AI-native protections, including model behavior monitoring, prompt inspection, and runtime defenses tailored to AI systems. These capabilities are particularly relevant in high-maturity environments where buyers prioritize low-latency enforcement, fine-grained control, and interpretability of AI interactions. That type of depth remains valuable because many broader platforms still have uneven coverage across agent-to-agent interactions, tool authorization, and runtime context analysis. As a result, specialists are likely to retain share in high-maturity AI environments even as broader platforms absorb more baseline category demand.</p><h2><strong>4) Non-human Identities (NHI)</strong></h2><p>Non-human identity (NHI) security in the UADP market is a security capability that manages and protects machine identities, preventing unauthorized access and credential misuse through continuous visibility, governance, and enforcement across service accounts, APIs, and automated workloads.</p><p>The NHI market is projected to grow from $0.94B in 2025 to $3.29B in 2030, implying a ~28.37% CAGR.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!OcGm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2fba8ca-da0e-4001-90d4-c7ff78703615_1598x892.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!OcGm!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2fba8ca-da0e-4001-90d4-c7ff78703615_1598x892.png 424w, https://substackcdn.com/image/fetch/$s_!OcGm!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2fba8ca-da0e-4001-90d4-c7ff78703615_1598x892.png 848w, https://substackcdn.com/image/fetch/$s_!OcGm!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2fba8ca-da0e-4001-90d4-c7ff78703615_1598x892.png 1272w, https://substackcdn.com/image/fetch/$s_!OcGm!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2fba8ca-da0e-4001-90d4-c7ff78703615_1598x892.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!OcGm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2fba8ca-da0e-4001-90d4-c7ff78703615_1598x892.png" width="1456" height="813" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f2fba8ca-da0e-4001-90d4-c7ff78703615_1598x892.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:813,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Non-human Identities NHI Security Market Share estimates for 2025&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Non-human Identities NHI Security Market Share estimates for 2025" title="Non-human Identities NHI Security Market Share estimates for 2025" srcset="https://substackcdn.com/image/fetch/$s_!OcGm!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2fba8ca-da0e-4001-90d4-c7ff78703615_1598x892.png 424w, https://substackcdn.com/image/fetch/$s_!OcGm!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2fba8ca-da0e-4001-90d4-c7ff78703615_1598x892.png 848w, https://substackcdn.com/image/fetch/$s_!OcGm!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2fba8ca-da0e-4001-90d4-c7ff78703615_1598x892.png 1272w, https://substackcdn.com/image/fetch/$s_!OcGm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2fba8ca-da0e-4001-90d4-c7ff78703615_1598x892.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>2025 Market Share Analysis</strong></h3><p>The current distribution of share in the NHI market reflects the fact that machine identity security has evolved beyond a narrow infrastructure concern into a core operational control layer. Service accounts, API keys, certificates, workload identities, and increasingly AI-driven processes act as the primary mechanism through which enterprise systems access data and execute workflows. As a result, the category is being shaped by multiple overlapping buying motions, including privileged access management, cloud IAM, secrets management, and identity governance. This has produced a market structure in which identity incumbents, cloud platform providers, and emerging specialists all retain meaningful positions, with share distributed according to where identity control and enforcement already exist within enterprise environments.</p><h3><strong>Top 15 Players in 2025</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!kkSv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b537538-7440-4c4a-8e7b-50797c7211c7_1598x890.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!kkSv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b537538-7440-4c4a-8e7b-50797c7211c7_1598x890.png 424w, https://substackcdn.com/image/fetch/$s_!kkSv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b537538-7440-4c4a-8e7b-50797c7211c7_1598x890.png 848w, https://substackcdn.com/image/fetch/$s_!kkSv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b537538-7440-4c4a-8e7b-50797c7211c7_1598x890.png 1272w, https://substackcdn.com/image/fetch/$s_!kkSv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b537538-7440-4c4a-8e7b-50797c7211c7_1598x890.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!kkSv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b537538-7440-4c4a-8e7b-50797c7211c7_1598x890.png" width="1456" height="811" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1b537538-7440-4c4a-8e7b-50797c7211c7_1598x890.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:811,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Top 15 Players in the Non-human Identities NHI Security Market for 2025&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Top 15 Players in the Non-human Identities NHI Security Market for 2025" title="Top 15 Players in the Non-human Identities NHI Security Market for 2025" srcset="https://substackcdn.com/image/fetch/$s_!kkSv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b537538-7440-4c4a-8e7b-50797c7211c7_1598x890.png 424w, https://substackcdn.com/image/fetch/$s_!kkSv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b537538-7440-4c4a-8e7b-50797c7211c7_1598x890.png 848w, https://substackcdn.com/image/fetch/$s_!kkSv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b537538-7440-4c4a-8e7b-50797c7211c7_1598x890.png 1272w, https://substackcdn.com/image/fetch/$s_!kkSv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b537538-7440-4c4a-8e7b-50797c7211c7_1598x890.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>Identity incumbents benefit from policy authority and installed trust</strong></h3><p>A meaningful portion of NHI share continues to accrue to vendors that already own identity governance and privileged access decisions inside large enterprises. In many organizations, the first response to machine identity sprawl is not to create a new budget category, but to extend existing identity and access governance frameworks to cover service accounts, credentials, and privileged non-human access. Vendors that already control entitlement policy, vaulting, or privileged access workflows therefore benefit from a significant distribution advantage.</p><p>CyberArk illustrates this dynamic. Its position in the market is strengthened not simply by machine identity discovery on its own, but by its role as a trusted control point for privileged access and secrets management across enterprise environments. That becomes more important as organizations seek to govern not only which credentials exist, but also which automated identities can reach sensitive systems and under what conditions. The broader implication is that incumbent identity vendors retain an important share advantage where buyers view NHI as an extension of privileged access control rather than as a greenfield cloud security purchase.</p><h3><strong>AI agents are expanding the category beyond traditional machine identities</strong></h3><p>A key factor contributing to the continued evolution of the category is the expansion of automated and AI-driven workflows, which are broadening the definition of what constitutes a non-human identity. Traditional NHI programs focused on static credentials such as secrets, keys, and service accounts. However, modern systems increasingly rely on automated processes that retrieve data, invoke APIs, and execute tasks across distributed environments. This shift increases demand for platforms that can connect identity governance to data access, workflow context, and execution behavior. Vendors such as Palo Alto Networks, CrowdStrike, and Okta are extending identity and security capabilities to address these more dynamic forms of non-human access, particularly in environments where identity signals must be evaluated alongside runtime activity. As automated systems become more deeply integrated into enterprise workflows, NHI share is likely to shift toward vendors capable of governing both static credentials and dynamic access relationships, particularly where identity intersects with data access and operational execution.</p><h3><strong>Platform vendors are absorbing NHI into broader security architectures</strong></h3><p>As with DSPM and AI security, the NHI category is increasingly being absorbed into larger security platforms. Many enterprises do not want machine identity security to operate as an isolated control plane disconnected from data protection, runtime monitoring, and cloud security telemetry. Instead, they want identity context to inform broader enforcement decisions across the stack. This is especially true in environments where automated systems are retrieving sensitive data or performing actions inside production workflows.</p><p>Large platform vendors therefore benefit when NHI can be positioned as part of a broader architecture rather than as a standalone control. Palo Alto Networks&#8217; acquisition of CyberArk is important in this regard because it signals that identity security, including non-human identity control, is becoming a core layer within larger security fabrics rather than remaining confined to specialist identity vendors. The same pattern is visible more broadly across the market as platforms attempt to unify identity signals with runtime and data context. Over time, this should support share gains for vendors that can embed NHI into broader operational security workflows rather than treat it as a separate vaulting or governance tool.</p><h2><strong>5) Identity Threat Detection &amp; Response (ITDR)</strong></h2><p>The ITDR market is projected to grow from $1.53B in 2025 to $4.10B in 2030, implying a ~21.80% CAGR.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!gblS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cef175f-c0f2-400d-b440-5e53c4a65cf5_1090x598.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gblS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cef175f-c0f2-400d-b440-5e53c4a65cf5_1090x598.png 424w, https://substackcdn.com/image/fetch/$s_!gblS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cef175f-c0f2-400d-b440-5e53c4a65cf5_1090x598.png 848w, https://substackcdn.com/image/fetch/$s_!gblS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cef175f-c0f2-400d-b440-5e53c4a65cf5_1090x598.png 1272w, https://substackcdn.com/image/fetch/$s_!gblS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cef175f-c0f2-400d-b440-5e53c4a65cf5_1090x598.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gblS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cef175f-c0f2-400d-b440-5e53c4a65cf5_1090x598.png" width="1090" height="598" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5cef175f-c0f2-400d-b440-5e53c4a65cf5_1090x598.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:598,&quot;width&quot;:1090,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Identity Threat Detection &amp; Response ITDR Market Share estimates for 2025&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Identity Threat Detection &amp; Response ITDR Market Share estimates for 2025" title="Identity Threat Detection &amp; Response ITDR Market Share estimates for 2025" srcset="https://substackcdn.com/image/fetch/$s_!gblS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cef175f-c0f2-400d-b440-5e53c4a65cf5_1090x598.png 424w, https://substackcdn.com/image/fetch/$s_!gblS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cef175f-c0f2-400d-b440-5e53c4a65cf5_1090x598.png 848w, https://substackcdn.com/image/fetch/$s_!gblS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cef175f-c0f2-400d-b440-5e53c4a65cf5_1090x598.png 1272w, https://substackcdn.com/image/fetch/$s_!gblS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cef175f-c0f2-400d-b440-5e53c4a65cf5_1090x598.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>2025 Market Share Analysis</strong></h3><p>The current distribution of share in the ITDR market reflects a category that is expanding rapidly as identity has evolved from a simple authentication layer into a live attack surface. As attackers increasingly target sessions, tokens, delegated privileges, and identity control planes rather than only endpoints or network perimeters, enterprises are rethinking identity security as a detection and response problem rather than solely a governance problem. Large ecosystem vendors hold a disproportionately large share because identity telemetry is deeply embedded within broader identity, endpoint, and cloud security platforms. As organizations extend identity controls across SaaS applications, cloud workloads, and hybrid infrastructure, many detection and response capabilities are purchased as extensions of existing ecosystems rather than as standalone identity security tools. The market&#8217;s two dominant players - Microsoft and Crowdstrike - together account for more than half of total ITDR revenue, reflecting the structural advantage of vendors that already sit at the identity and endpoint control plane across enterprise environments.</p><h3><strong>Top 15 Players in 2025</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!jWN7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5459bf56-1ca1-41a3-8855-40fc7cf96e24_1086x606.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!jWN7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5459bf56-1ca1-41a3-8855-40fc7cf96e24_1086x606.png 424w, https://substackcdn.com/image/fetch/$s_!jWN7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5459bf56-1ca1-41a3-8855-40fc7cf96e24_1086x606.png 848w, https://substackcdn.com/image/fetch/$s_!jWN7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5459bf56-1ca1-41a3-8855-40fc7cf96e24_1086x606.png 1272w, https://substackcdn.com/image/fetch/$s_!jWN7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5459bf56-1ca1-41a3-8855-40fc7cf96e24_1086x606.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!jWN7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5459bf56-1ca1-41a3-8855-40fc7cf96e24_1086x606.png" width="1086" height="606" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5459bf56-1ca1-41a3-8855-40fc7cf96e24_1086x606.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:606,&quot;width&quot;:1086,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Top 15 Players in the Identity Threat Detection &amp; Response ITDR Market for 2025&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Top 15 Players in the Identity Threat Detection &amp; Response ITDR Market for 2025" title="Top 15 Players in the Identity Threat Detection &amp; Response ITDR Market for 2025" srcset="https://substackcdn.com/image/fetch/$s_!jWN7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5459bf56-1ca1-41a3-8855-40fc7cf96e24_1086x606.png 424w, https://substackcdn.com/image/fetch/$s_!jWN7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5459bf56-1ca1-41a3-8855-40fc7cf96e24_1086x606.png 848w, https://substackcdn.com/image/fetch/$s_!jWN7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5459bf56-1ca1-41a3-8855-40fc7cf96e24_1086x606.png 1272w, https://substackcdn.com/image/fetch/$s_!jWN7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5459bf56-1ca1-41a3-8855-40fc7cf96e24_1086x606.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>Identity control points create a structural distribution advantage</strong></h3><p>A meaningful portion of ITDR share continues to accrue to vendors that already sit at the identity control plane. In many enterprises, the fastest path to ITDR adoption is to extend existing identity infrastructure with behavioral monitoring, anomalous access detection, and response workflows. Vendors that already manage authentication, conditional access, privilege assignment, and session policies therefore have a natural advantage because they can place detection and enforcement close to the source of identity risk.</p><p>Microsoft illustrates this dynamic. Its position in ITDR is supported not only by threat detection capabilities, but by the fact that Entra, Defender, and the broader Microsoft security stack already operate at the intersection of identity, endpoint, and access policy. This gives Microsoft a strong distribution channel for identity-centric detection and automated response, particularly in organizations that already rely on its identity infrastructure. More broadly, the market implication is that vendors controlling authentication and access policy are well positioned to absorb ITDR into broader identity operations rather than leave it as a standalone category.</p><h3><strong>Endpoint and XDR vendors are pulling ITDR into broader detection platforms</strong></h3><p>A second force shaping market share is the growing role of extended detection and response platforms in identity threat detection. Many real-world identity attacks do not occur in isolation &#8212; token theft, session hijacking, privilege escalation, and lateral movement often intersect with endpoint compromise, cloud control plane abuse, or suspicious network behavior. As a result, many buyers increasingly prefer identity threat detection capabilities integrated into a wider detection and response platform rather than operated as a separate identity-only workflow.</p><p>This dynamic favors vendors that can correlate identity signals with endpoint, cloud, and threat intelligence telemetry. CrowdStrike&#8217;s 18.08% share reflects this motion directly &#8212; its identity protection product has been reinforced by the platform&#8217;s endpoint and cloud telemetry, giving buyers a unified view of identity and endpoint risk within a single investigation workflow. SentinelOne follows a similar trajectory, having expanded from endpoint-centric visibility toward a broader detection fabric that includes identity signals. In practice, ITDR often enters the enterprise through SOC modernization and platform consolidation rather than through a standalone identity security purchase, which should support continued share gains for vendors that position identity threat detection as part of a unified investigation and response workflow.</p><p><strong>Active Directory remains the primary attack surface driving specialist share</strong></p><p>A distinct and structurally important segment of ITDR share accrues to vendors focused specifically on Active Directory and Entra ID threat detection. The ITDR category emerged in direct response to the proliferation of directory-targeting attacks, including credential theft techniques, lateral movement through directory services, and abuse of delegated privileges within hybrid identity environments. Active Directory remains the primary identity store for the majority of enterprise environments, and directory infrastructure is implicated in the overwhelming majority of ransomware and breach events.</p><p>Semperis at 4.58% and Netwrix at 3.14% reflect this reality. Both vendors derive their ITDR revenue primarily from hybrid Active Directory and Entra ID threat detection - monitoring directory changes, detecting privilege escalation, and providing automated rollback of malicious modifications in ways that broader platform vendors do not replicate with the same depth or specialization. Their share reflects sustained enterprise demand for directory-specialist detection tools that sit alongside rather than inside larger security platforms. The coexistence of AD specialists with dominant platform vendors is a persistent structural feature of the ITDR market, driven by the fact that directory infrastructure requires dedicated monitoring approaches that general-purpose security platforms address incompletely.</p><h3><strong>Privileged access and NHI expansion are broadening the category</strong></h3><p>Another structural factor influencing share is the widening overlap between ITDR and adjacent identity categories. In earlier phases, ITDR was often framed around human account compromise and directory abuse. That framing is becoming too narrow. Modern environments increasingly require detection and response for privileged sessions, service accounts, workload identities, and AI agents operating with delegated authority. As a result, the operational boundary between ITDR, privileged access management, and non-human identity governance is becoming less distinct.</p><p>CyberArk, the third largest in the market, reflects this convergence directly. Many enterprises no longer view privileged access monitoring and identity threat detection as separate control problems. As attackers target both human and machine identities with equal sophistication, buyers increasingly want to detect anomalous behavior across the full spectrum of access pathways rather than only at the authentication layer. Silverfort&#8217;s 3.92% share reflects a related dynamic: its agentless architecture extends identity protection and behavioral detection across legacy systems and service accounts that sit outside the perimeter of modern identity platforms, covering a gap that larger vendors do not address without significant deployment complexity. BeyondTrust and Delinea similarly derive their ITDR share from privileged access-rooted detection, reflecting the growing enterprise preference for unified privileged access and threat detection over separate tool categories. This convergence should continue to support share for identity security incumbents as buyers prioritize control over the full identity attack surface - human, privileged, and machine - within a single operational framework.</p><h1><strong>Platform Convergence across the UADP Architecture</strong></h1><p>In the current market, the UADP opportunity can be approximated as the <strong>aggregate of the five underlying capability markets analyzed in this report: DSPM, DLP, AI security, NHI governance, and ITDR.</strong> Each of these markets developed independently and continues to generate revenue through distinct products and vendor ecosystems.</p><p>Looking forward, however, market expansion is unlikely to remain purely additive. As enterprise architectures evolve toward AI-driven workflows and automated infrastructure, buyers are increasingly prioritizing platforms capable of correlating signals across these domains. Data sensitivity, identity privileges, runtime behavior, and AI interactions must be evaluated together to produce effective security decisions. As a result, the long-term trajectory of the UADP market will depend not only on the growth of the underlying categories, but also on how effectively vendors integrate capabilities across these pillars into unified operational platforms.</p><p>This shift introduces an additional structural dimension to market growth: platform integration. Vendors that successfully assemble data security, identity governance, AI protection, and behavioral detection into a coherent control plane are likely to capture a disproportionate share of incremental spending. Conversely, vendors that remain confined to single-category products may find growth increasingly constrained as enterprise buyers favor integrated architectures capable of enforcing policy across complex AI-enabled workflows.</p><h2><strong>UADP Industry Analysis</strong></h2><p>The UADP market is projected to grow from $8.30B in 2025 to $21.59B in 2030, implying approximately 21.08% CAGR through 2030. Market size estimates are constructed by combining revenues from adjacent security segments, including DSPM, DLP, AI security, ITDR, and NHI security.The aggregated segment baseline serves as the foundation for UADP sizing in the near term, where spending remains distributed across distinct tools and buying centers. From this baseline, forward projections introduce a convergence adjustment to reflect the increasing consolidation of these capabilities into integrated platforms. This adjustment is applied at the market level to account for shifts in enterprise purchasing behavior, where multiple point solutions are replaced by unified architectures, reducing redundant spend across categories. As a result, the projected UADP market diverges from the simple sum of its components over time, with the 2030 estimate intentionally modeled below the aggregate total of the five segments.</p><p>The growth profile reflects both the expansion of the underlying security categories and the increasing demand for integrated security architectures capable of governing data, identities, and AI-driven workflows within a unified operational framework. Early adoption is driven by the rapid deployment of AI systems and the expansion of non-human identities, which are exposing gaps in traditional security controls. As vendors integrate capabilities across data security, identity governance, AI protection, and behavioral detection, the market transitions from independent category spending toward platform-based security investments, with convergence effects becoming more pronounced toward 2030.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!b1qs!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d7e117f-5a1f-4dce-8d2a-e6223b352f9c_1600x896.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!b1qs!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d7e117f-5a1f-4dce-8d2a-e6223b352f9c_1600x896.png 424w, https://substackcdn.com/image/fetch/$s_!b1qs!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d7e117f-5a1f-4dce-8d2a-e6223b352f9c_1600x896.png 848w, https://substackcdn.com/image/fetch/$s_!b1qs!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d7e117f-5a1f-4dce-8d2a-e6223b352f9c_1600x896.png 1272w, https://substackcdn.com/image/fetch/$s_!b1qs!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d7e117f-5a1f-4dce-8d2a-e6223b352f9c_1600x896.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!b1qs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d7e117f-5a1f-4dce-8d2a-e6223b352f9c_1600x896.png" width="1456" height="815" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5d7e117f-5a1f-4dce-8d2a-e6223b352f9c_1600x896.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:815,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Unified Agentic Defense Platform UADP market size projections for 2025 and 2030&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Unified Agentic Defense Platform UADP market size projections for 2025 and 2030" title="Unified Agentic Defense Platform UADP market size projections for 2025 and 2030" srcset="https://substackcdn.com/image/fetch/$s_!b1qs!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d7e117f-5a1f-4dce-8d2a-e6223b352f9c_1600x896.png 424w, https://substackcdn.com/image/fetch/$s_!b1qs!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d7e117f-5a1f-4dce-8d2a-e6223b352f9c_1600x896.png 848w, https://substackcdn.com/image/fetch/$s_!b1qs!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d7e117f-5a1f-4dce-8d2a-e6223b352f9c_1600x896.png 1272w, https://substackcdn.com/image/fetch/$s_!b1qs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d7e117f-5a1f-4dce-8d2a-e6223b352f9c_1600x896.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Growth Drivers</strong></h2><h3><strong>Enterprise AI adoption is expanding the scope of data and identity governance</strong></h3><p>The rapid deployment of generative AI and autonomous agents across enterprise environments is expanding the scope of data governance beyond traditional storage systems. AI agents now retrieve enterprise knowledge, invoke APIs, and execute workflows with delegated authority, often interacting directly with sensitive data and internal systems. This evolution introduces new pathways through which data can be accessed, synthesized, or exposed during live execution. As organizations scale copilots, RAG systems, and agentic workflows, governance requirements increasingly extend to the entire interaction layer between users, agents, and enterprise data sources. Vendors are responding by integrating data security, identity governance, and runtime controls into unified platforms capable of monitoring how AI systems access and manipulate enterprise information.</p><h3><strong>Fragmentation across data, identity, and runtime security layers is creating demand for unified control planes</strong></h3><p>Most enterprise security architectures remain fragmented across multiple control layers. Data security platforms, identity governance systems, runtime protection tools, and threat detection solutions often operate independently and exchange limited context. As AI systems operate at machine speed and interact across multiple services simultaneously, these fragmented architectures struggle to provide real-time visibility and coordinated enforcement. Enterprises are therefore seeking platforms that can unify these signals into a shared policy and telemetry layer. The emerging UADP architecture reflects this shift, combining data protection, identity visibility, and runtime monitoring into a single security fabric designed to defend autonomous systems and the workflows they execute.</p><h3><strong>Autonomous agents are expanding the enterprise identity surface</strong></h3><p>AI systems increasingly operate with delegated privileges that allow them to access data, call external tools, and perform actions across enterprise applications. This creates a new category of non-human identities that must be governed alongside traditional user accounts. Unlike conventional software processes, AI agents can dynamically decide which resources to access or which actions to take based on contextual reasoning. As a result, security teams must monitor not only human activity but also the behavior of automated agents interacting with sensitive data and infrastructure. UADP platforms address this challenge by combining identity visibility, behavioral monitoring, and policy enforcement to control how both users and AI agents access enterprise systems.</p><h3><strong>AI systems introduce new runtime attack surfaces that traditional security models cannot address</strong></h3><p>Traditional security architectures were designed for deterministic software systems with predictable behavior. Agentic AI introduces probabilistic systems capable of generating new outputs, reasoning about tasks, and autonomously interacting with other services. These systems create new categories of risk, including prompt injection, unauthorized data retrieval, and agent-driven privilege escalation. Because these threats occur during the execution of AI workflows rather than at traditional network boundaries, they require security controls that operate directly within the runtime layer of AI applications. UADP platforms address this challenge by combining runtime protection, data governance, and threat detection capabilities to monitor and intervene in agentic workflows before sensitive data or systems are compromised.</p><h2><strong>Scenario Analysis for UADP Market</strong></h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3Erz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11e15fce-428d-4e18-b211-0624f79a8eba_1080x1350.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3Erz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11e15fce-428d-4e18-b211-0624f79a8eba_1080x1350.png 424w, https://substackcdn.com/image/fetch/$s_!3Erz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11e15fce-428d-4e18-b211-0624f79a8eba_1080x1350.png 848w, https://substackcdn.com/image/fetch/$s_!3Erz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11e15fce-428d-4e18-b211-0624f79a8eba_1080x1350.png 1272w, https://substackcdn.com/image/fetch/$s_!3Erz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11e15fce-428d-4e18-b211-0624f79a8eba_1080x1350.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3Erz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11e15fce-428d-4e18-b211-0624f79a8eba_1080x1350.png" width="1080" height="1350" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/11e15fce-428d-4e18-b211-0624f79a8eba_1080x1350.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1350,&quot;width&quot;:1080,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:322636,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://softwareanalyst.substack.com/i/191571789?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11e15fce-428d-4e18-b211-0624f79a8eba_1080x1350.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3Erz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11e15fce-428d-4e18-b211-0624f79a8eba_1080x1350.png 424w, https://substackcdn.com/image/fetch/$s_!3Erz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11e15fce-428d-4e18-b211-0624f79a8eba_1080x1350.png 848w, https://substackcdn.com/image/fetch/$s_!3Erz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11e15fce-428d-4e18-b211-0624f79a8eba_1080x1350.png 1272w, https://substackcdn.com/image/fetch/$s_!3Erz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11e15fce-428d-4e18-b211-0624f79a8eba_1080x1350.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Notable M&amp;A Shaping the UADP Ecosystem</strong></h2><p>Strategic acquisitions across the industry illustrate how vendors are assembling the capabilities required to compete in an integrated architecture.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!FoOt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe733492d-90b6-486d-bf1b-d1a9b344170c_1600x909.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!FoOt!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe733492d-90b6-486d-bf1b-d1a9b344170c_1600x909.png 424w, https://substackcdn.com/image/fetch/$s_!FoOt!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe733492d-90b6-486d-bf1b-d1a9b344170c_1600x909.png 848w, https://substackcdn.com/image/fetch/$s_!FoOt!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe733492d-90b6-486d-bf1b-d1a9b344170c_1600x909.png 1272w, https://substackcdn.com/image/fetch/$s_!FoOt!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe733492d-90b6-486d-bf1b-d1a9b344170c_1600x909.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!FoOt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe733492d-90b6-486d-bf1b-d1a9b344170c_1600x909.png" width="1456" height="827" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e733492d-90b6-486d-bf1b-d1a9b344170c_1600x909.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:827,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Notable M&amp;A transactions shaping the UADP ecosystem part 1&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Notable M&amp;A transactions shaping the UADP ecosystem part 1" title="Notable M&amp;A transactions shaping the UADP ecosystem part 1" srcset="https://substackcdn.com/image/fetch/$s_!FoOt!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe733492d-90b6-486d-bf1b-d1a9b344170c_1600x909.png 424w, https://substackcdn.com/image/fetch/$s_!FoOt!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe733492d-90b6-486d-bf1b-d1a9b344170c_1600x909.png 848w, https://substackcdn.com/image/fetch/$s_!FoOt!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe733492d-90b6-486d-bf1b-d1a9b344170c_1600x909.png 1272w, https://substackcdn.com/image/fetch/$s_!FoOt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe733492d-90b6-486d-bf1b-d1a9b344170c_1600x909.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!VuP1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30f8b797-d68b-4200-8428-ff55eac4749c_1600x917.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!VuP1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30f8b797-d68b-4200-8428-ff55eac4749c_1600x917.png 424w, https://substackcdn.com/image/fetch/$s_!VuP1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30f8b797-d68b-4200-8428-ff55eac4749c_1600x917.png 848w, https://substackcdn.com/image/fetch/$s_!VuP1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30f8b797-d68b-4200-8428-ff55eac4749c_1600x917.png 1272w, https://substackcdn.com/image/fetch/$s_!VuP1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30f8b797-d68b-4200-8428-ff55eac4749c_1600x917.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!VuP1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30f8b797-d68b-4200-8428-ff55eac4749c_1600x917.png" width="1456" height="834" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/30f8b797-d68b-4200-8428-ff55eac4749c_1600x917.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:834,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Notable M&amp;A transactions shaping the UADP ecosystem part 2&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Notable M&amp;A transactions shaping the UADP ecosystem part 2" title="Notable M&amp;A transactions shaping the UADP ecosystem part 2" srcset="https://substackcdn.com/image/fetch/$s_!VuP1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30f8b797-d68b-4200-8428-ff55eac4749c_1600x917.png 424w, https://substackcdn.com/image/fetch/$s_!VuP1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30f8b797-d68b-4200-8428-ff55eac4749c_1600x917.png 848w, https://substackcdn.com/image/fetch/$s_!VuP1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30f8b797-d68b-4200-8428-ff55eac4749c_1600x917.png 1272w, https://substackcdn.com/image/fetch/$s_!VuP1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30f8b797-d68b-4200-8428-ff55eac4749c_1600x917.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Analysis of Key M&amp;A</strong></h2><h3><strong>Palo Alto Networks &#8594; CyberArk (2026)</strong></h3><p>For Palo Alto, this acquisition resolves a structural gap that became increasingly difficult to defend as identity emerged as the primary attack surface in cloud and AI environments. Palo Alto&#8217;s platform had strong coverage across network, endpoint, and cloud infrastructure &#8212; but identity governance, privileged access, and machine identity management sat outside its control plane. CyberArk fills all three gaps simultaneously. The combined platform can now enforce security policy across users, privileged accounts, service accounts, and AI agent identities within a single architecture, eliminating the seam between infrastructure security and identity governance that attackers have increasingly exploited. The deal is significant because it demonstrates that the largest security platforms now treat identity not as an adjacent discipline but as a core enforcement layer - one that must be owned rather than integrated through partnership.</p><h3><strong>Google &#8594; Wiz (2025)</strong></h3><p>Google&#8217;s acquisition of Wiz is less about adding a capability and more about controlling the infrastructure layer where AI workloads, data pipelines, and enterprise applications increasingly run. Wiz&#8217;s risk graph connects cloud misconfigurations, workload vulnerabilities, and sensitive data exposure into a unified view, which is precisely the visibility foundation that any coherent security architecture requires before enforcement controls can operate effectively. Without knowing where sensitive data lives, which workloads have access to it, and what misconfigurations expose it, runtime controls and policy enforcement operate blind. The move signals that hyperscalers are not content to provide infrastructure and leave security to third parties. They intend to own the security control plane that sits on top of their infrastructure. For the broader market, this raises the competitive stakes for every vendor whose differentiation depends on cloud infrastructure visibility.</p><h3><strong>Veeam &#8594; Securiti AI (2025)</strong></h3><p>This deal is a directional signal about where resilience platforms must go to remain relevant. Backup and recovery vendors have historically operated after the fact &#8212; restoring systems once damage has occurred. But as AI systems begin interacting with large internal data stores, enterprises need to understand their sensitive data exposure before an incident, not after one. Securiti&#8217;s data governance and DSPM capabilities give Veeam the ability to identify what sensitive data exists, where it lives, and which AI workflows are touching it - converting a reactive recovery platform into a proactive data risk platform. The transaction reflects a broader pattern now visible across the security market: the data protection layer is attracting entrants from adjacent categories, including resilience, governance, and compliance, each of which is discovering that continuous data visibility has become a prerequisite for the products they already sell. Pure-play DSPM vendors face a market in which breadth expectations are rising not because buyers are demanding more features, but because the platforms surrounding them are absorbing the capability.</p><h3><strong>Cisco &#8594; Robust Intelligence (2024)</strong></h3><p>Cisco&#8217;s acquisition reflects a recognition that AI model security cannot be addressed solely through network controls or endpoint protection. It requires a dedicated layer that understands model behavior, adversarial inputs, and runtime integrity. What makes the deal strategically interesting is not the capability itself but what it reveals about where Cisco believes the enterprise security perimeter is moving. As large language models and agent-driven workflows become operational infrastructure, the attack surface shifts from network packets and endpoint processes toward prompts, tool calls, and model responses. Cisco is positioning to govern that surface before it becomes a default blind spot in enterprise security architectures, and the acquisition signals that traditional security vendors view AI model governance as a control problem that belongs inside the security stack rather than inside the AI development stack.</p><h3><strong>Check Point &#8594; Lakera (2025)</strong></h3><p>Check Point&#8217;s acquisition of Lakera targets the live interaction surface - the moment a prompt enters a model and a response leaves it. Lakera&#8217;s runtime protection detects prompt injection, jailbreak attempts, and adversarial inputs in real time, preventing models from being manipulated into exposing sensitive data or executing unintended actions. The distinction matters because AI runtime attacks are fundamentally different from traditional threats: they require no malware, no network intrusion, and no credential compromise, only a carefully constructed input. As enterprises embed copilots, AI assistants, and autonomous agents into production workflows, this attack surface grows proportionally with AI adoption rather than with infrastructure complexity, meaning it cannot be addressed through perimeter controls alone. Check Point&#8217;s move positions the company to govern model interactions directly within its broader security platform, defending a threat surface that most enterprise security architectures currently leave unaddressed.</p><h2><strong>UADP Convergence Wheel</strong></h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ohbL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49766112-2825-4351-a79f-37bcdad98855_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ohbL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49766112-2825-4351-a79f-37bcdad98855_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!ohbL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49766112-2825-4351-a79f-37bcdad98855_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!ohbL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49766112-2825-4351-a79f-37bcdad98855_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!ohbL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49766112-2825-4351-a79f-37bcdad98855_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ohbL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49766112-2825-4351-a79f-37bcdad98855_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/49766112-2825-4351-a79f-37bcdad98855_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1175253,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://softwareanalyst.substack.com/i/191571789?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49766112-2825-4351-a79f-37bcdad98855_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ohbL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49766112-2825-4351-a79f-37bcdad98855_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!ohbL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49766112-2825-4351-a79f-37bcdad98855_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!ohbL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49766112-2825-4351-a79f-37bcdad98855_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!ohbL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49766112-2825-4351-a79f-37bcdad98855_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>Interpreting Vendor Positioning in a Converging Market</strong></h3><p>Because the UADP architecture emerges from the convergence of several previously independent security markets, traditional vendor market share analysis is less meaningful at the aggregate level than within the underlying pillars. Vendor revenue today often reflects legacy strength in a single domain such as DLP, identity governance, or threat detection rather than alignment with the integrated architecture described in this report. As a result, presenting a consolidated market share table for the combined UADP market would risk overstating vendors concentrated in mature categories while understating the strategic positioning of vendors assembling broader security platforms.</p><p>The competitive landscape is therefore better understood through a convergence framework that illustrates how vendors participate across the five foundational pillars examined in this report: DSPM, DLP, AI security, non-human identity governance, and identity threat detection and response. The UADP convergence wheel visualizes this ecosystem by positioning specialist vendors within individual capability domains while highlighting platforms that integrate signals across multiple pillars.</p><h3><strong>Vendor Ecosystem and Platform Positioning</strong></h3><p>The architecture organizes around three convergence zones that reflect how enterprise security problems are increasingly experienced in practice rather than how security budgets have historically been structured.</p><p>The Data Security zone encompasses both DSPM and DLP - the disciplines responsible for knowing where sensitive data lives and preventing it from moving in ways that violate policy. These capabilities are increasingly inseparable. Effective enforcement requires classification context, and classification without enforcement produces visibility without control. Vendors in this zone include both established platforms with deep enterprise distribution - Microsoft, Palo Alto, Broadcom, Zscaler - and a generation of cloud-native specialists such as Cyera, Varonis, BigID, and Cyberhaven that were built specifically for environments where data moves continuously across SaaS, cloud storage, and browser-mediated workflows. The presence of vendors like Wiz, Rubrik, and Veeam reflects the broader pattern of adjacent platforms entering data security from cloud infrastructure and resilience rather than from traditional DLP lineages.</p><p>The Identity Security zone encompasses both ITDR and NHI which are the disciplines responsible for detecting compromised identities and governing the machine and workload identities that now outnumber human users in most enterprise environments. These two capabilities are converging for the same reason that DSPM and DLP are converging: the threat surface no longer respects the boundary between them. Attackers that compromise a service account, abuse a delegated token, or hijack an AI agent&#8217;s credentials are simultaneously an ITDR problem and an NHI problem. Vendors in this zone reflect the full spectrum of identity security lineages. PAM-rooted platforms such as CyberArk, BeyondTrust, and Delinea; cloud identity incumbents such as Okta and Microsoft; detection-first platforms such as CrowdStrike, SentinelOne, and Semperis; and a newer generation of NHI specialists including Astrix, Oasis, Entro, and Veza that were built specifically for the machine identity problem before larger platforms moved to address it.</p><p>AI Security sits at the center of the architecture, not because it is the largest pillar by current revenue, but because it is the surface where data security and identity security intersect at the point of live model interaction. When an AI agent accesses a sensitive data store under delegated credentials, the risk cannot be evaluated by data controls or identity controls independently. It requires both simultaneously. The vendors positioned in the AI Security zone reflect the range of approaches the market is currently exploring: runtime protection platforms such as HiddenLayer and Lakera focused on prompt and model interaction defense; AI governance platforms such as Noma and WitnessAI focused on model lifecycle and agent behavior; and broader security platforms including Microsoft, Palo Alto, CrowdStrike, Zscaler, and Netskope that are extending existing enforcement architectures into AI interaction surfaces.</p><h3><strong>Structural Convergence Toward Integrated Platforms</strong></h3><p>Vendors that appear across multiple zones in the convergence wheel - Microsoft, Palo Alto, CrowdStrike, Zscaler, and Netskope - represent the current candidates for platform-level UADP ownership. Their presence across data security, identity security, and AI security is not incidental. Each has made deliberate moves through acquisition, product development, or platform extension to extend its control plane beyond its original domain. What distinguishes these platforms from specialists is not depth in any single pillar but the ability to correlate signals across pillars - connecting data sensitivity context to identity behavior to AI runtime activity in ways that single-domain vendors cannot replicate without significant integration work on the buyer&#8217;s part.</p><p>The vendors anchored within a single zone represent a different strategic position. Some hold deep capability in one pillar and are valued precisely for that specialization. Buyers with mature programs in identity governance or data classification often prefer purpose-built tools over platform coverage that is broad but shallow. Others are earlier-stage platforms whose long-term positioning depends on either expanding their own surface area before platform vendors close the capability gap or becoming acquisition targets as larger platforms race to fill holes in their architectures. Both outcomes are already visible in the transaction record. Palo Alto acquiring CyberArk, Google acquiring Wiz, CrowdStrike acquiring SGNL, and Cyera acquiring Otterize each reflect a platform vendor identifying a zone it did not adequately control and moving to own it through acquisition rather than organic development. The specialists that remain independent will increasingly be evaluated by buyers and by acquirers on the same question of whether their single-pillar depth justify a separate deployment, or if a multi-zone platform now covers the use case well enough.</p><h2><strong>Potential headwinds</strong></h2><h3><strong>The organizational ownership problem may slow platform consolidation</strong></h3><p>The UADP architecture assumes that enterprises will increasingly evaluate data security, identity governance, and AI risk as a unified control problem. In practice, these disciplines are owned by different teams with different budgets, different reporting lines, and different procurement cycles. Data security typically sits within compliance or data governance functions. Identity security is owned by IAM or infrastructure teams. AI risk governance, where it exists at all, is frequently split between security, legal, and the office of the CTO. In most enterprises, no single buyer owns all three simultaneously.</p><p>This organizational fragmentation creates a structural friction that architectural logic alone cannot overcome. A vendor assembling a unified UADP platform still needs a buyer willing to consolidate across these internal boundaries &#8212; and that buyer does not yet consistently exist. Enterprises may recognize the value of integrated control planes in the abstract while continuing to purchase capabilities through the teams and procurement channels that already exist. The result is that UADP adoption may proceed pillar by pillar through existing buying centers rather than as a unified platform purchase, slowing the consolidation dynamic that drives the convergence premium in the growth model. Until enterprises either create a dedicated function responsible for AI-era security architecture or until a sufficiently dominant platform forces consolidation from the outside, organizational structure remains a more durable headwind than any technology gap.</p><h3><strong>Hyperscaler absorption may compress the independent market</strong></h3><p>Hyperscalers hold a position in the UADP architecture that no independent security vendor can fully replicate - control over the infrastructure layer where AI workloads run, the identity plane through which access is granted, and the productivity environment where enterprise data is created and shared. Each of these positions is a potential absorption point for UADP capabilities that currently generate independent market revenue.</p><p>The Microsoft scenario is the most consequential. Defender, Purview, Entra, and the broader Microsoft security stack already span DLP, DSPM, ITDR, and NHI governance within a single licensing framework. If Microsoft continues to deepen these capabilities and bundle them within E5 or successor licensing tiers, a meaningful portion of the addressable UADP market could be captured through license expansion rather than through discrete security purchases. Enterprises that already rely on Microsoft for identity, productivity, and compliance infrastructure face a low-friction path to absorbing UADP capabilities without engaging the independent vendor market at all. Google&#8217;s acquisition of Wiz signals a similar intent at the cloud infrastructure layer, and AWS&#8217;s native IAM and secrets management capabilities already provide infrastructure-layer NHI coverage that reduces the urgency of standalone NHI purchases for AWS-centric environments. If hyperscaler platforms absorb the baseline UADP use case, the independent market may be structurally smaller than the segment aggregation implies - concentrated in high-maturity environments, complex multi-cloud architectures, and use cases that require depth the hyperscaler platforms do not provide.</p><h3><strong>Some enterprises may prioritize control layer specialization over platform consolidation</strong></h3><p>While platform convergence offers operational advantages, some organizations may prefer specialized tools that provide deeper functionality within individual security domains. For example, a company with a mature identity program may continue to rely on dedicated identity governance or privileged access management vendors even if UADP platforms offer overlapping capabilities. Similarly, organizations with complex data protection requirements may retain specialized tools for discovery, classification, or encryption.</p><p>This dynamic can lead to hybrid environments where unified platforms coexist with specialized systems rather than replacing them entirely. As a result, the UADP market may develop gradually through integration across existing security domains rather than through rapid platform consolidation.</p><h1><strong>Conclusion</strong></h1><h2><strong>Summary of Projections</strong></h2><p>The UADP market is projected to grow from $8.30 billion in 2025 to $21.59 billion by 2030, representing a 21.08% CAGR. That growth is real, but the more consequential question is structural: whether convergence produces an independent category or is absorbed into platforms that already control identity, data, and infrastructure.</p><p>The near-term trajectory is clear. Each of the five foundational pillars, DSPM, DLP, AI security, NHI governance, and ITDR, continues to expand as organizations respond to rising data exposure, the proliferation of machine identities, and the operational deployment of AI. Current market size reflects spending distributed across distinct tools and buying centers. The unresolved question is whether that spend consolidates into a unified architecture or is captured through platform expansion.</p><p>The competitive dynamic is not whether convergence occurs, but which vendor category defines it. Identity vendors hold a control-plane advantage at authentication and enforcement. Data security vendors hold a classification advantage through visibility into sensitive data. AI security vendors hold a runtime advantage through insight into model behavior and agent activity.</p><p>Vendors most likely to define the architecture are those that combine at least two of these advantages at scale. Microsoft integrates identity and data control across a platform already embedded in enterprise workflows, positioning it as the default control plane, though increasingly &#8220;good enough&#8221; bundling may cap differentiation. Palo Alto Networks is assembling the most credible independent platform, but its success depends on turning acquisitions into a coherent policy and enforcement layer. CrowdStrike is the strongest challenger, with a unified detection fabric across endpoint and identity, but remains weaker on the data control layer that anchors policy decisions.</p><h2><strong>Category Formation Is Not Guaranteed</strong></h2><p>The structural drivers supporting convergence are real, but category formation is not inevitable. There is a credible scenario in which UADP does not emerge as a distinct market and is instead absorbed into adjacent control planes.</p><p>Microsoft already bundles capabilities across DSPM, DLP, ITDR, and NHI within a unified licensing model. Hyperscalers control the infrastructure where AI workloads, data pipelines, and applications operate. If these platforms continue expanding native capabilities, a meaningful portion of demand will be captured through license expansion rather than standalone purchases.</p><p>In this scenario, the architectural logic of UADP holds, but the economic expression is compressed. Demand exists, but it accrues to platform vendors rather than forming a discrete category. The independent UADP market becomes concentrated in high-complexity, multi-cloud environments where platform-native capabilities are insufficient.</p><h2><strong>What to Watch</strong></h2><p>The most important developments over the next 12 to 18 months are organizational, not technological. The formation of unified security functions that consolidate ownership of identity, data, and AI risk under a single budget is the clearest indicator of market acceleration.</p><p>If that consolidation occurs, the convergence premium embedded in current projections is conservative. If enterprises continue to operate through fragmented buying centers, adoption will proceed incrementally and growth will track individual categories rather than a unified platform model. In that case, platform absorption becomes more likely regardless of architectural merit.</p><h2><strong>Strategic Implications</strong></h2><p><strong>For vendors,</strong> the competitive question is no longer whether to integrate across pillars, but how quickly and through what mechanism. Organic expansion is increasingly insufficient given the pace of market consolidation. Recent activity, including Palo Alto Networks acquiring CyberArk, Google acquiring Wiz, and CrowdStrike acquiring SGNL and Seraphic, reflects the speed at which platforms are assembling cross-domain capabilities. Vendors that remain anchored in a single pillar face a narrowing window before adjacent capabilities are absorbed by larger platforms.</p><p>The strategic priority is to identify the highest-value adjacent domain that aligns with existing distribution and installed base, and to move into that domain before competitors close the gap. Identity security vendors are best positioned to expand into AI runtime governance, where access control and execution risk converge. Data security vendors must incorporate identity behavior context to move from visibility to enforcement. AI security vendors, in turn, need to anchor runtime protections in data classification and access policy frameworks. Vendors that delay expansion until the architecture stabilizes are likely to find that the most defensible positions have already been claimed.</p><p><strong>For investors,</strong> the most important distinction is between genuine architectural integration and portfolio aggregation. Multi-pillar positioning alone is not sufficient. Prior transitions such as XDR and CNAPP demonstrated that valuation premiums ultimately accrue to vendors that deliver unified detection and enforcement, rather than those that simply assemble adjacent products. The same dynamic is likely to apply in UADP. Vendors where cross-domain signal correlation is already visible, where identity risk informs data access decisions or AI runtime violations feed back into identity controls, are more likely to sustain long-term platform value.</p><p>Conversely, vendors that present a broad portfolio but continue to operate each pillar independently represent integration risk rather than platform premium. In these cases, the absence of a unified control layer limits both differentiation and defensibility. On the specialist side, the highest-value acquisition targets are vendors in AI security and NHI governance that combine deep technical differentiation with limited distribution. These vendors are difficult to replicate organically and can be scaled effectively through an acquirer&#8217;s existing enterprise relationships.</p><p><strong>For enterprise security leaders,</strong> the immediate priority is not platform selection but organizational alignment. The primary constraint on UADP adoption is not the availability of technology, but the fragmentation of ownership across data security, identity governance, and AI risk functions. As long as these domains operate under separate budgets, tools, and reporting structures, the value of unified control planes cannot be fully realized.</p><p>Security leaders should begin by identifying where policy decisions require coordination across teams. These coordination points represent the clearest opportunities for consolidation and the most immediate sources of operational efficiency. In parallel, AI governance must be treated as an operational security discipline rather than a compliance exercise. The runtime risks introduced by autonomous systems are already present, and delaying implementation of controls until standards mature introduces avoidable exposure during the period of fastest adoption.</p><div><hr></div><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Software Analyst Cyber Research! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/p/the-rise-of-uadp-market-share-growth/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/p/the-rise-of-uadp-market-share-growth/comments"><span>Leave a comment</span></a></p><div class="directMessage button" data-attrs="{&quot;userId&quot;:6770950,&quot;userName&quot;:&quot;SACR&quot;,&quot;canDm&quot;:null,&quot;dmUpgradeOptions&quot;:null,&quot;isEditorNode&quot;:true}" data-component-name="DirectMessageToDOM"></div><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&quot;,&quot;text&quot;:&quot;Share Software Analyst Cyber Research&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share Software Analyst Cyber Research</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Runtime Security for AI Agents: An Identity Governance Perspective ]]></title><description><![CDATA[From Deterministic Access to Intent-Aware Governance: A Framework for Managing Non-Human Identities, Behavioral Risk, and MCP-Driven Execution in the Agentic Enterprise]]></description><link>https://softwareanalyst.substack.com/p/runtime-security-for-ai-agents-an</link><guid isPermaLink="false">https://softwareanalyst.substack.com/p/runtime-security-for-ai-agents-an</guid><dc:creator><![CDATA[SACR]]></dc:creator><pubDate>Wed, 18 Mar 2026 19:01:12 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!4MJw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d0df82d-dca8-4282-9da2-020178e3129b_1920x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2><strong>About Authors</strong></h2><ul><li><p><strong><a href="https://www.linkedin.com/in/kevinhe0125/">Kevin He</a></strong><a href="https://www.linkedin.com/in/kevinhe0125/"> </a>is a Principal at MVP Ventures, where he leads infrastructure software and cybersecurity investments from Seed through Series B. He previously helped build the cybersecurity investing practice at WestCap, was an investor at Redpoint Ventures, and served as a Product Manager at Horizon3.ai. Earlier in his career, he began in investment banking at Goldman Sachs. He is currently pursuing his MBA at Stanford GSB and holds dual degrees in Business and Data Science from UC Berkeley.</p></li><li><p><strong><a href="https://www.linkedin.com/in/laurenplace/">Lauren Place</a></strong> is an MBA candidate at Stanford Graduate School of Business. She previously launched and scaled zero-to-one products at Wiz, from $100M to over $700M ARR, and at Snyk, from $100M to over $300M. Lauren holds a B.S. from Northwestern University.</p></li><li><p><strong><a href="https://www.linkedin.com/in/shachar-ram/">Shachar Ram</a></strong> is an MBA candidate at Stanford Graduate School of Business, where she is conducting research on cybersecurity and identity security as part of her studies. She previously served in Israeli intelligence in cybersecurity and later worked at Cyera, where she helped grow the company from a $500M to a $6B valuation. She holds a degree in Computer Science.</p></li></ul><div><hr></div><h2><strong>The Market Map of Runtime Identity and Governance for AI Agents</strong></h2><p>The market for securing AI agents is emerging rapidly, but it is not forming as a single, unified category. Instead, it is fragmenting across multiple layers of control, each addressing a different part of the runtime problem. Traditional identity access controls provide the foundation, enforcing what agents are allowed to do. </p><p>Today&#8217;s report finds that deterministic governance builds on this by adding policy-driven enforcement, bringing structure and predictability to agent behavior. As agents become more non-deterministic, new vendors are building around a new layer. New systems are being designed to understand intent, monitor behavior in real time, and dynamically intervene when risk emerges. </p><p>There is a big landscape with a stacked ecosystem of capabilities. Vendors are positioning themselves across these layers: some focusing on identity and access primitives, others on observability and behavioral analysis, and a smaller group pushing into true runtime, intent-aware governance. The following market map reflects how this ecosystem is taking shape today. </p><p><strong>Note</strong>: <strong>This market map is representative of the broader market. It is not an exhaustive list but a case study of vendor categories across this market. </strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4MJw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d0df82d-dca8-4282-9da2-020178e3129b_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4MJw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d0df82d-dca8-4282-9da2-020178e3129b_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!4MJw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d0df82d-dca8-4282-9da2-020178e3129b_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!4MJw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d0df82d-dca8-4282-9da2-020178e3129b_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!4MJw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d0df82d-dca8-4282-9da2-020178e3129b_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4MJw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d0df82d-dca8-4282-9da2-020178e3129b_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6d0df82d-dca8-4282-9da2-020178e3129b_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:879727,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://softwareanalyst.substack.com/i/191396308?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d0df82d-dca8-4282-9da2-020178e3129b_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!4MJw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d0df82d-dca8-4282-9da2-020178e3129b_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!4MJw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d0df82d-dca8-4282-9da2-020178e3129b_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!4MJw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d0df82d-dca8-4282-9da2-020178e3129b_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!4MJw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d0df82d-dca8-4282-9da2-020178e3129b_1920x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Software Analyst Cyber Research! Subscribe for free to receive in-depth research reports on identity and agent security.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><div><hr></div><h2><strong>Executive Summary</strong></h2><p><strong>AI agents have moved from experimentation to production deployment across the Fortune 500.</strong> With over 3 million agents operating globally and organizations creating thousands per week, the security challenge has shifted from whether to deploy agents to how to secure them at runtime, or the moment an agent decides to act, calls a tool, and touches enterprise data.</p><p>This report builds on SACR&#8217;s earlier <em><a href="https://softwareanalyst.substack.com/p/emerging-agentic-identity-access">Emerging Agentic Identity &amp; Access Platforms (AIAP)</a></em> report, which mapped the agent identity landscape according to the four-phase security framework of discovery, authorization, credential brokering, and runtime enforcement. This follow-up paper focuses specifically on the runtime enforcement piece, or examining governance capabilities for AI agents in production.</p><p>We have identified a three-layer model that reflects how the most advanced identity security platforms are thinking about securing agents at runtime:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hGyn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b20aca7-a008-49a1-8616-b4651177b2dd_1600x900.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hGyn!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b20aca7-a008-49a1-8616-b4651177b2dd_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!hGyn!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b20aca7-a008-49a1-8616-b4651177b2dd_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!hGyn!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b20aca7-a008-49a1-8616-b4651177b2dd_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!hGyn!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b20aca7-a008-49a1-8616-b4651177b2dd_1600x900.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hGyn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b20aca7-a008-49a1-8616-b4651177b2dd_1600x900.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9b20aca7-a008-49a1-8616-b4651177b2dd_1600x900.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;A three-layer model of AI agent identity security at runtime&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="A three-layer model of AI agent identity security at runtime" title="A three-layer model of AI agent identity security at runtime" srcset="https://substackcdn.com/image/fetch/$s_!hGyn!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b20aca7-a008-49a1-8616-b4651177b2dd_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!hGyn!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b20aca7-a008-49a1-8616-b4651177b2dd_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!hGyn!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b20aca7-a008-49a1-8616-b4651177b2dd_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!hGyn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b20aca7-a008-49a1-8616-b4651177b2dd_1600x900.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Beyond agent discovery, the first layer of securing agentic identities is <strong>deterministic governance:</strong> a policy engine that defines what an agent can and cannot access. This layer is table stakes, and every vendor in this report has built it. But deterministic governance alone is insufficient. Agents fundamentally display non-deterministic behavior, and an agent can stay within its permitted access boundaries while still doing something unexpected, harmful, or misaligned with its original intent.</p><p>The second layer is <strong>non-deterministic behavioral analysis,</strong> or visibility into agents&#8217; actions and intent. This means understanding not just what resources an agent accessed, but why, and whether that behavior represents a meaningful deviation from the norm. This includes both behavioral tracking and anomaly detection, which surfaces unusual patterns in agent activity over time, and continuous observability, which answers the present-tense question of what an agent is doing right now and whether it should be allowed to continue. This layer provides the visibility and real-time data that make non-deterministic governance possible. Things such as a continuously updated risk score reflecting the agent&#8217;s current behavior, intent drift, and access patterns are the raw material that non-deterministic governance consumes to make decisions.</p><p>The third layer is <strong>non-deterministic governance</strong>, or using those real-time signals to make dynamic policy decisions. This means evaluating agent intent at the moment of an access request, acting on live risk scores that shift as agent behavior evolves, and triggering escalation or human review not on a fixed schedule but in direct response to what the agent is actually doing. Within this layer we identified intent-based authorization and dynamic control and escalation as the two key dimensions.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!r9g2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a53053f-c82d-499e-a0c4-dd9fb0894947_1600x900.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!r9g2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a53053f-c82d-499e-a0c4-dd9fb0894947_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!r9g2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a53053f-c82d-499e-a0c4-dd9fb0894947_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!r9g2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a53053f-c82d-499e-a0c4-dd9fb0894947_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!r9g2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a53053f-c82d-499e-a0c4-dd9fb0894947_1600x900.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!r9g2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a53053f-c82d-499e-a0c4-dd9fb0894947_1600x900.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1a53053f-c82d-499e-a0c4-dd9fb0894947_1600x900.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Dimensions of non-deterministic behavior and non-deterministic governance&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Dimensions of non-deterministic behavior and non-deterministic governance" title="Dimensions of non-deterministic behavior and non-deterministic governance" srcset="https://substackcdn.com/image/fetch/$s_!r9g2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a53053f-c82d-499e-a0c4-dd9fb0894947_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!r9g2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a53053f-c82d-499e-a0c4-dd9fb0894947_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!r9g2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a53053f-c82d-499e-a0c4-dd9fb0894947_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!r9g2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a53053f-c82d-499e-a0c4-dd9fb0894947_1600x900.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>Note:</em> choosing not to implement this third layer is not necessarily a gap. It can be a deliberate architectural decision. Non-deterministic governance introduces its own risks including false positives that block legitimate agent actions and erode trust in the system, and false negatives that create a false sense of security. Some vendors have made a conscious choice to keep their governance layer simple, deterministic, and predictable, accepting that limitation in exchange for a system that behaves reliably and does not introduce new failure modes. This is a reasonable position, particularly for organizations in early stages of agent deployment.</p><p>A dedicated case study examines <strong>MCP (Model Context Protocol)</strong> as a proving ground for these challenges. MCP&#8217;s adoption has outpaced its security maturity: 53% of public MCP servers use static secrets, only 8.5% implement OAuth, and tool poisoning attacks succeed at a 72.8% rate in benchmark testing. Four risk layers: Supply chain integrity, Communication Security, Authorization Granularity, and Credential Management, make MCP the most visible attack surface in the agentic identity stack.</p><p>Vendors are taking two distinct approaches to <strong>MCP runtime security.</strong></p><ul><li><p>The <strong>gateway approach</strong> routes all agent-to-tool traffic through a centralized proxy that validates requests, enforces policy, and injects credentials, enabling deterministic and, in advanced implementations, dynamic policy enforcement. The limitation is visibility: a gateway sees requests and responses, but lacks the deeper context needed to evaluate agent intent.</p></li><li><p>The <strong>direct-access approach</strong> inverts this: by integrating natively with underlying systems, it gains rich visibility into agent behavior and why actions are being taken. The limitation is control: observing behavior is not the same as enforcing policy.</p></li></ul><p>Neither approach is sufficient alone. Comprehensive MCP runtime security requires both: a gateway layer for enforcement, and a direct-access layer for the contextual intelligence that makes enforcement decisions meaningful.</p><p><strong>Finally for CISO recommendations</strong>, the practical implication of this analysis is that there is no single vendor today that fully solves the runtime security problem for AI agents across deterministic governance, non-deterministic behavioral analysis, and non-deterministic governance capabilities.</p><p>Selecting a platform based solely on its deterministic governance capabilities, which is how most security procurement decisions in this space are currently being made, leaves the most dangerous attack surface unaddressed. The questions worth asking of any vendor are not just what can you block, but what can you see, how do you build risk context over time, and how does that context change what you allow. As agent deployments move from pilot to production and from simple single-step tasks to complex autonomous workflows, the organizations that have invested in all three layers will be meaningfully better positioned to detect, respond to, and contain the security failures that are inevitable at scale.</p><h2><strong>The Challenge with Securing AI Agent Identities at Runtime</strong></h2><p>As AI agents gain access to sensitive data and production systems, security gaps become most dangerous during execution&#8212;when an agent is actively acting on behalf of a user or system. Unlike traditional non-human or workload identities, agents are non-deterministic: their decisions can&#8217;t be fully predicted in advance, so legacy security tools built around predictable behavior fall short. Runtime identity security solutions built specifically for agents address this by evaluating an agent&#8217;s intent, context, and access rights in real time. This paper examines how the market is responding, what a complete runtime security posture looks like, and how leading vendors are approaching each layer.</p><h3><strong>Why Runtime Identity Security Is Critical for AI Agents</strong></h3><p>Traditional security asks: <em>is this person authorized to run this code</em>? Runtime identity security for agents asks a harder question: <em>should this code run, even if this agent is authorized?</em> This shift, from access control to intent evaluation and behavioral analysis, is what makes deterministic governance alone insufficient.</p><p><strong>Intent, and not just authorization, must be evaluated at runtime.</strong> Agents behave distinctly different from humans and human identities. For example, when a human deletes a file, it&#8217;s a conscious act. When an agent deletes a file, it can be responding to a prompt, following a reasoning chain, or recovering from a tool error. The same API call carries different risks depending on whether a human directed it or an agent decided it autonomously.</p><p><strong>Intent must be evaluated with each individual action at runtime</strong>, not only once when a policy is first defined. When an agent updates a database record, for example, a misinterpreted instruction or prompt injection attack could turn a routine write into data corruption. Catching that requires continuous visibility into what the agent is doing and why. That observability generates the context needed to assess intent, calculate risk, and make dynamic access decisions in real time, enabling organizations to grant least-privilege access while continuously verifying that agent behavior stays aligned with declared goals.</p><p><strong>Intent is not static, and so an agent&#8217;s behavior must be evaluated continuously</strong> throughout its entire lifecycle. An agent that begins by performing simple data retrieval could later execute complex workflows or combine actions in unexpected ways, especially as it chains reasoning steps, integrates new tools, or responds to updated prompts. A one-time grant of even least-privilege access is therefore insufficient. Continuous runtime evaluation is required to ensure that each action remains aligned with current intent and organizational policy, and to trigger dynamic responses when it does not.</p><p>The runtime identity security problem for AI agents is magnified by the 144:1 ratio of NHI credentials to human users in typical enterprises. Organizations maintain roughly one human user per 144 machine identities, including service accounts, API keys, application credentials, and workload identities. Each agent requires its own credentials to access resources, and a single human operator can provision multiple agents, each with distinct identities and permissions. When shadow agents or ephemeral instances are included, the number of active identities can quickly reach thousands per team. At this scale, manual oversight or one-time access grants are impossible, making automated, continuous runtime security not just important but essential.</p><h3><strong>AI Agent Types and Security Considerations</strong></h3><p>Not all agents present the same security challenges. The enterprise agent landscape breaks into three distinct categories, each with different identity risks, enforcement requirements, and visibility gaps. Understanding which agent types dominate an organization&#8217;s environment is the first step in selecting the right runtime controls.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!nO9O!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8748e6c-73f4-4826-ac51-1cdf5b3c18df_1600x900.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!nO9O!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8748e6c-73f4-4826-ac51-1cdf5b3c18df_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!nO9O!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8748e6c-73f4-4826-ac51-1cdf5b3c18df_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!nO9O!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8748e6c-73f4-4826-ac51-1cdf5b3c18df_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!nO9O!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8748e6c-73f4-4826-ac51-1cdf5b3c18df_1600x900.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!nO9O!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8748e6c-73f4-4826-ac51-1cdf5b3c18df_1600x900.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b8748e6c-73f4-4826-ac51-1cdf5b3c18df_1600x900.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;AI Agent Types including Homegrown, SaaS Platforms, and Local Workforce Tools&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="AI Agent Types including Homegrown, SaaS Platforms, and Local Workforce Tools" title="AI Agent Types including Homegrown, SaaS Platforms, and Local Workforce Tools" srcset="https://substackcdn.com/image/fetch/$s_!nO9O!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8748e6c-73f4-4826-ac51-1cdf5b3c18df_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!nO9O!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8748e6c-73f4-4826-ac51-1cdf5b3c18df_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!nO9O!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8748e6c-73f4-4826-ac51-1cdf5b3c18df_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!nO9O!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8748e6c-73f4-4826-ac51-1cdf5b3c18df_1600x900.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><ol><li><p><strong>Homegrown agents</strong> are custom-built by engineering teams using cloud services like AWS Bedrock or GCP Vertex, data platforms, or open-source frameworks like LangChain. They run in managed infrastructure and give security teams the most architectural control, but the primary risk is scale: engineering teams can spin up hundreds of agents across multiple repositories and cloud accounts, creating sprawl that outpaces centralized governance.</p></li><li><p><strong>SaaS agent platforms</strong> like Microsoft Copilot Studio, Salesforce Agentforce, and ServiceNow allow non-technical employees to build and deploy agents through low-code interfaces. This is where the maker identity problem becomes acute: when a business user creates an agent using their own credentials, every subsequent user&#8217;s actions execute under the creator&#8217;s identity, meaning the agent inherits standing access that downstream users may not be entitled to.</p></li><li><p><strong>Local and agentic workforce tools</strong> represent the fastest-growing and least-visible category. Developer tools like Cursor, Claude Code, and Windsurf run directly on employee workstations, connecting to community MCP servers that may never touch enterprise infrastructure. These agents are effectively invisible to cloud-based security controls: they do not route through corporate proxies, do not register in cloud IAM, and often store credentials in plaintext configuration files on the endpoint. This category represents the largest blind spot in most enterprise agent security programs today.</p></li></ol><p>The security implications differ across all three categories, but the underlying principles are consistent: organizations need to discover agents wherever they run, understand whose identity they operate under, enforce least-privilege access dynamically rather than statically, and monitor behavior at runtime for drift and anomalies.</p><h3><strong>Four Runtime Dimensions</strong></h3><p>Beyond the baseline of deterministic access control that every vendor in this report implements, we identified four dimensions that define a complete runtime security posture, organized into two categories. The first is analysis of non-deterministic behavior, which encompasses <strong>Continuous Observability</strong> and <strong>Behavioral Tracking</strong>. These dimensions provide the visibility and risk context that make meaningful runtime decisions possible. The second category is non-deterministic governance, which encompasses <strong>Intent-Based Authorization</strong> and <strong>Control &amp; Escalation</strong>.</p><h4>1. Continuous Observability</h4><p>When something goes wrong with an AI agent, the first question security teams ask is what happened and why. Continuous observability provides the infrastructure to answer that question. Beyond simple logging, this dimension captures session-level telemetry that records not just what an agent did, but the reasoning behind each action, the context it was operating in, and the user or system that initiated the session. That attribution chain is critical. Security and compliance teams need to be able to trace any agent action back to a specific user, a specific intent, and a specific moment in time. Without it, investigating an incident becomes guesswork. This contextual data is also what feeds the non-deterministic governance layer. As organizations deploy more agents across more workflows, observability becomes the foundation for accountability across the entire agent workforce, ensuring that autonomous and user-driven agents alike leave a clear and reconstructable record of every decision they made.</p><h4>2. Behavioral Tracking</h4><p>Agents are not static programs. Their behavior shifts based on context, instructions, and the tools available to them, which means traditional signature-based security controls will miss a significant class of threats. Behavioral tracking addresses this by establishing a baseline of what normal looks like for a given agent: how frequently it calls APIs, how much data it moves, which tools it typically uses, and in what sequence. When an agent deviates from that baseline, such as suddenly reading thousands of files, calling an external API it has never used before, or moving an unusual volume of data, the system has a meaningful signal to work with. Even without non-deterministic governance in place, that signal is useful: security teams can receive alerts, get recommendations for tightening existing policies, and use behavioral data to refine access rules over time. For organizations that do implement the non-deterministic governance layer, behavioral tracking becomes the essential input: a real-time risk score is only as good as the behavioral data behind it, and dynamic escalation policies can only respond meaningfully to drift if there is an established baseline to drift from.</p><h4>3. Intent-Based Authorization</h4><p>Traditional security controls ask whether an agent is allowed to perform an action. Intent-based authorization asks why. Even when an agent has the technical credentials to call an API or access a system, its reasoning must stay within the boundaries defined for a given task. This is the first dimension of non-deterministic governance, and it depends directly on the observability and behavioral data generated by the two preceding dimensions. Without a continuous picture of what the agent is doing and how its behavior compares to its baseline, intent evaluation has no context to work with. In practice, vendors implementing this capability evaluate the agent&#8217;s stated intent in real time, dynamically granting or withholding specific privileges for that session rather than relying on static access rules set at deployment. An agent instructed to retrieve a customer record has a different intent than one instructed to export all customer records, even if both actions are technically within its permissions. Intent-based authorization is what makes that distinction enforceable at runtime, shifting the security model from a one-time permissions check to a continuous audit of whether the agent&#8217;s reasoning remains aligned with its authorized purpose.</p><h4>4. Control &amp; Escalation</h4><p>Control and escalation is the dimension that closes the loop on the entire three-layer model. Where intent-based authorization makes dynamic access decisions, control and escalation takes dynamic action when those decisions are not enough. This means pausing an agent mid-execution, routing a pending action to a human for approval, or terminating a session entirely based on what the agent is doing right now. What makes this dimension distinct from static circuit breakers is that the escalation thresholds themselves are dynamic. Rather than hardcoding which actions always require approval, teams can configure thresholds that adapt based on the agent&#8217;s current risk score, the sensitivity of the resource being accessed, or drift flagged by behavioral tracking. An agent whose risk score has been climbing across a session is treated differently than one performing its first anomalous action. When thresholds are crossed, the agent halts and waits for human review. If no approval comes, or if the situation warrants immediate action, the session is terminated.</p><p>No vendor provides equal strength across all four dimensions. Understanding where each vendor excels and where they fall short is essential for CISOs building a runtime security strategy.</p><h1><strong>The MCP Security Case Study: A Deep Dive</strong></h1><h3><strong>What Is MCP?</strong></h3><p>The Model Context Protocol (MCP) defines a standardized interface for AI models to request contextual information from external systems. Rather than hardcoding credentials, connection strings, and API logic into model prompts, MCP externalizes these capabilities into servers that the model can query. This architectural separation has become the primary protocol for agent-to-resource communication in developer platforms like Cursor and Claude Code.</p><p>MCP is not inherently insecure. The protocol itself includes mechanisms for authentication, authorization, and credential isolation. However, the barrier to deploying MCP servers has become so low that a significant portion of the public MCP ecosystem (the Smithery registry and similar repositories) contains servers written without baseline security practices.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!By-t!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F680371c6-e2c8-4899-92fb-48481c4c66a2_1600x896.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!By-t!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F680371c6-e2c8-4899-92fb-48481c4c66a2_1600x896.png 424w, https://substackcdn.com/image/fetch/$s_!By-t!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F680371c6-e2c8-4899-92fb-48481c4c66a2_1600x896.png 848w, https://substackcdn.com/image/fetch/$s_!By-t!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F680371c6-e2c8-4899-92fb-48481c4c66a2_1600x896.png 1272w, https://substackcdn.com/image/fetch/$s_!By-t!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F680371c6-e2c8-4899-92fb-48481c4c66a2_1600x896.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!By-t!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F680371c6-e2c8-4899-92fb-48481c4c66a2_1600x896.png" width="1456" height="815" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/680371c6-e2c8-4899-92fb-48481c4c66a2_1600x896.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:815,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Diagram showing the flow of MCP Model Context Protocol between agents and external systems&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Diagram showing the flow of MCP Model Context Protocol between agents and external systems" title="Diagram showing the flow of MCP Model Context Protocol between agents and external systems" srcset="https://substackcdn.com/image/fetch/$s_!By-t!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F680371c6-e2c8-4899-92fb-48481c4c66a2_1600x896.png 424w, https://substackcdn.com/image/fetch/$s_!By-t!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F680371c6-e2c8-4899-92fb-48481c4c66a2_1600x896.png 848w, https://substackcdn.com/image/fetch/$s_!By-t!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F680371c6-e2c8-4899-92fb-48481c4c66a2_1600x896.png 1272w, https://substackcdn.com/image/fetch/$s_!By-t!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F680371c6-e2c8-4899-92fb-48481c4c66a2_1600x896.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>The MCP Security Landscape</strong></h3><p>Plaintext credentials are endemic. 53% of publicly available MCP servers rely on insecure static secrets hardcoded into configuration or source code. The Smithery registry has documented instances of PostgreSQL passwords, API keys, and AWS credentials stored as plaintext in repository commits. Organizations that instantiate these servers inherit the credential exposure without knowing it.</p><p>Tool poisoning attacks have high success rates. The MCPTox benchmark demonstrated a 72.8% success rate for tool poisoning attacks, where malicious MCP servers inject false results or manipulated outputs to influence agent decisions. Most agents do not validate tool responses for plausibility, making them vulnerable to poisoned data from compromised MCP servers.</p><p>Credential practices at scale are insecure. Only 8.5% of MCP servers use OAuth, leaving the vast majority reliant on insecure credential practices. This includes hardcoded secrets, unencrypted configuration files, and credentials passed through environment variables without access controls.</p><h3><strong>MCP Inventory, Discovery, and Governance</strong></h3><p>Before organizations can secure MCP usage at runtime, they need a reliable way to inventory and govern MCP servers and tools. In practice, this means maintaining a registry of approved MCP servers, knowing which servers and tools are being used by which agents, and enforcing centralized policies for allow/deny decisions, permissions, and lifecycle management. The emerging MCP ecosystem is already moving in this direction: the official MCP Registry is designed as a standardized metadata layer for discovering servers, while enterprise control planes increasingly treat MCP servers and tools as governable resources rather than ad hoc developer-side integrations. In other words, MCP security is not only about blocking malicious tool calls; it is also about ensuring that unapproved servers are never introduced silently, that approved servers are onboarded through a review process, and that tool access can be centrally audited, updated, or revoked as organizational policy changes.</p><h3><strong>Why MCP Security Matters for Agent Runtime</strong></h3><p><strong>MCP security matters because MCP is increasingly one of the primary ways agents operate at runtime</strong>. In many modern agent deployments, the most consequential actions an agent takes during execution, such as retrieving enterprise context, querying data sources, invoking external tools, and taking action in downstream systems happen through MCP servers. In other words, MCP is not just a configuration convenience or developer abstraction; it is often the operational interface between the agent and the outside world. That makes MCP security a runtime problem in the most direct sense: if an MCP server is malicious, overprivileged, poorly authenticated, or loosely governed, the agent&#8217;s live behavior can be compromised even if the model itself is functioning as intended.</p><p>Within runtime, if mismanaged, MCPs introduces a wild west ecosystem where agents can dynamically discover and use third-party tools, creating several critical risks across the following four layers:</p><p><strong>Supply Chain Risks:</strong> Because the MCP environment is largely unregulated, organizations face the risk of &#8220;tool poisoning&#8221; or backdoors in community-developed servers. Malicious or untrusted MCP servers can be intentionally designed to hijack an agent&#8217;s reasoning or exfiltrate sensitive credentials. Organizations are not equipped to audit every MCP server dependency in the same way they audit software dependencies.</p><p><strong>Communication Security Risks:</strong> During runtime, the communication channel between an agent and an MCP server is vulnerable to indirect prompt injection. This occurs when an agent reads data that contains instructions to override the agent&#8217;s original goals. Without a &#8220;firewall&#8221; layer, this can lead to sensitive data leakage as the agent is tricked into transmitting internal PII to an external, untrusted MCP tool.</p><p><strong>Authorization Risks:</strong> Traditional security often grants agents overly broad &#8220;standing access&#8221; to MCP servers, enabling them to perform any action the tool allows. This lacks the granular control needed to distinguish between safe actions (reading a file) and dangerous ones (deleting a production database).</p><p><strong>Credential Management Risks:</strong> MCP servers overwhelmingly rely on long-lived static secrets (API keys, tokens) rather than modern credential exchange protocols like OAuth. When an agent authenticates to an MCP server using a static credential, that secret is often embedded in configuration files, shared across sessions, and never rotated. If any single MCP server is compromised, the attacker gains persistent access to every downstream resource that credential unlocks. This is compounded by the &#8220;maker identity&#8221; problem, where an agent operates under its creator&#8217;s static token rather than the end user&#8217;s scoped session, meaning a compromised credential exposes not just one user&#8217;s data but potentially an entire team&#8217;s.</p><h3><strong>The Architectural Question: Gateway vs. Direct-Access Monitoring</strong></h3><p>Two enforcement approaches emerged for managing MCP-layer risk:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!uTVj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57d089c2-31b0-44f4-b10c-7dd42743a9c7_1600x898.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!uTVj!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57d089c2-31b0-44f4-b10c-7dd42743a9c7_1600x898.png 424w, https://substackcdn.com/image/fetch/$s_!uTVj!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57d089c2-31b0-44f4-b10c-7dd42743a9c7_1600x898.png 848w, https://substackcdn.com/image/fetch/$s_!uTVj!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57d089c2-31b0-44f4-b10c-7dd42743a9c7_1600x898.png 1272w, https://substackcdn.com/image/fetch/$s_!uTVj!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57d089c2-31b0-44f4-b10c-7dd42743a9c7_1600x898.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!uTVj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57d089c2-31b0-44f4-b10c-7dd42743a9c7_1600x898.png" width="1456" height="817" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/57d089c2-31b0-44f4-b10c-7dd42743a9c7_1600x898.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:817,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Architecture diagram of an MCP Gateway showing centralized traffic routing&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Architecture diagram of an MCP Gateway showing centralized traffic routing" title="Architecture diagram of an MCP Gateway showing centralized traffic routing" srcset="https://substackcdn.com/image/fetch/$s_!uTVj!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57d089c2-31b0-44f4-b10c-7dd42743a9c7_1600x898.png 424w, https://substackcdn.com/image/fetch/$s_!uTVj!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57d089c2-31b0-44f4-b10c-7dd42743a9c7_1600x898.png 848w, https://substackcdn.com/image/fetch/$s_!uTVj!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57d089c2-31b0-44f4-b10c-7dd42743a9c7_1600x898.png 1272w, https://substackcdn.com/image/fetch/$s_!uTVj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57d089c2-31b0-44f4-b10c-7dd42743a9c7_1600x898.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>MCP Gateway:</strong> Agents do not directly connect to MCP servers. Instead, all MCP communication flows through a centralized gateway that validates server responses, enforces policies, and prevents credential exposure. This architecture provides centralized control and the ability to inspect tool results for poisoning while preventing access to unapproved MCP servers. However, it requires significant architectural changes, introduces a single point of failure, and adds latency to every tool call within the agent&#8217;s reasoning cycle.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!N3Ma!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42c7d687-d336-453e-9ddd-10fd30cb31c9_1600x887.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!N3Ma!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42c7d687-d336-453e-9ddd-10fd30cb31c9_1600x887.png 424w, https://substackcdn.com/image/fetch/$s_!N3Ma!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42c7d687-d336-453e-9ddd-10fd30cb31c9_1600x887.png 848w, https://substackcdn.com/image/fetch/$s_!N3Ma!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42c7d687-d336-453e-9ddd-10fd30cb31c9_1600x887.png 1272w, https://substackcdn.com/image/fetch/$s_!N3Ma!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42c7d687-d336-453e-9ddd-10fd30cb31c9_1600x887.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!N3Ma!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42c7d687-d336-453e-9ddd-10fd30cb31c9_1600x887.png" width="1456" height="807" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/42c7d687-d336-453e-9ddd-10fd30cb31c9_1600x887.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:807,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Architecture diagram of Direct-Access Monitoring for MCP security&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Architecture diagram of Direct-Access Monitoring for MCP security" title="Architecture diagram of Direct-Access Monitoring for MCP security" srcset="https://substackcdn.com/image/fetch/$s_!N3Ma!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42c7d687-d336-453e-9ddd-10fd30cb31c9_1600x887.png 424w, https://substackcdn.com/image/fetch/$s_!N3Ma!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42c7d687-d336-453e-9ddd-10fd30cb31c9_1600x887.png 848w, https://substackcdn.com/image/fetch/$s_!N3Ma!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42c7d687-d336-453e-9ddd-10fd30cb31c9_1600x887.png 1272w, https://substackcdn.com/image/fetch/$s_!N3Ma!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42c7d687-d336-453e-9ddd-10fd30cb31c9_1600x887.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Direct-Access Monitoring:</strong> Agents connect directly to MCP servers, but MCP server credentials are managed centrally (vaults, rotated regularly, scoped to specific tasks). Post-execution monitoring detects anomalies and credential misuse. Direct-Access Monitoring preserves agent autonomy and minimizes latency by avoiding a single point of failure in the communication path, yet it remains fundamentally reactive since post-execution monitoring may only identify poisoned tool responses or credential misuse after an unauthorized action has already occurred.</p><p>Currently, the majority of vendors have implemented the <strong>MCP Gateway</strong> approach, as it offers a familiar &#8220;choke point&#8221; for enforcing security policies. However, a distinct group of vendors argues that this method lacks the deep execution context, such as the agent&#8217;s internal reasoning or the specific user session history, needed to make highly accurate security decisions. Consequently, these vendors are pursuing <strong>Direct-Access Monitoring</strong>, favoring a strategy that integrates more closely with the agent&#8217;s runtime environment to capture richer context, even if it requires more sophisticated detection capabilities.</p><p>The difference between these two approaches maps directly onto the three-layer framework. The gateway approach is fundamentally a governance mechanism: it sits in the communication path and enforces deterministic policy, and in more advanced implementations it can apply dynamic controls based on real-time risk signals. What it lacks on its own is the deep visibility into agent behavior and intent that the observability layer requires. It can block or allow a request, but without access to the raw reasoning and context behind that request, it has limited ability to build the behavioral baselines and risk intelligence that non-deterministic governance depends on.</p><p>The direct-access approach inverts this: by integrating natively with the underlying systems, it gains rich contextual data about what agents are doing and why, generating exactly the kind of signal that feeds meaningful intent evaluation and behavioral analysis. But observing behavior is not the same as controlling it. Direct-access monitoring is inherently reactive, identifying poisoned tool responses or credential misuse after the fact rather than intercepting them in real time.</p><p>Neither approach eliminates MCP-layer risk on its own.</p><h3><strong>Critiques of MCP Gateways</strong></h3><p>MCP gateways face several structural limitations that may constrain their long-term effectiveness as the sole enforcement point for agentic runtime security.</p><p><strong>The Shadow Agent Problem:</strong> MCP gateways operate as inline proxies: they can only enforce policy on traffic that routes through them. In practice, most enterprises have no reliable mechanism to guarantee that every agent in the organization communicates exclusively through a designated gateway. Shadow agents, those built ad hoc by developers, spun up in notebooks, or deployed through SaaS platforms without security team oversight bypass the gateway entirely. This is analogous to the limitations of traditional network firewalls before the rise of endpoint detection: if the traffic never hits the chokepoint, the chokepoint is irrelevant. As one vendor noted during our research, organizations are already discovering tens of thousands of agents in their first visibility scans, many of which were unknown to security teams. A gateway that secures only the agents it knows about provides a false sense of coverage.</p><p><strong>Lack of Session Context:</strong> MCP gateways typically evaluate each tool call in isolation, inspecting the request payload, applying allow/deny rules, and forwarding or blocking. What they cannot do is reason about the broader context of an agent&#8217;s session: what instructions the agent was given, what actions it has taken so far in the current conversation, or how this request compares to the agent&#8217;s historical behavior patterns. There are some workarounds, but they provide limited visibility. This is a critical gap. A file deletion request may be perfectly legitimate in one session context (a user-directed cleanup task) and deeply suspicious in another (an agent that has been hijacked via indirect prompt injection mid-conversation). Without access to conversation history, agent instructions, and identity provider integrations, a gateway is making authorization decisions with incomplete information, effectively enforcing static rules against a dynamic, context-dependent threat surface.</p><p><strong>Protocol Obsolescence Risk:</strong> Perhaps the most consequential challenge facing MCP gateways is the possibility that the MCP protocol itself becomes a transitional technology rather than a permanent standard. Developers are already beginning to shift toward &#8220;skills&#8221;-based architectures, where agents communicate directly with downstream APIs (e.g., calling the Notion API, Salesforce API, or GitHub API natively) rather than routing through the MCP protocol layer. Skills-based approaches avoid the performance overhead and cost associated with MCP&#8217;s intermediary step, and major platforms are actively investing in these direct-integration models. If agents increasingly bypass MCP in favor of native API calls, an MCP gateway secures a diminishing share of agent-to-tool communication. It becomes, as one security architect described it, a lock on a door that fewer agents walk through each quarter.</p><h2><strong>Recommendations for CISOs</strong></h2><p>The central decision every CISO faces when building a runtime security program for AI agents is not which vendor to buy, but which layer of the framework to implement and when. The following recommendations are intended to guide that decision.</p><p><strong>Start with deterministic governance, but do not stop there.</strong> Every organization deploying agents needs a policy engine that controls what agents can and cannot access. This is the baseline, and without it nothing else works. But CISOs should be clear-eyed that deterministic governance alone will not catch the threats that matter most with AI agents. An agent operating entirely within its permitted scope can still cause significant damage if its intent drifts, if it is subject to prompt injection, or if it combines permitted actions in ways that produce unauthorized outcomes. Plan for the layers above from the beginning, even if you do not implement them immediately.</p><p><strong>Invest in observability before governance.</strong> The quality of every dynamic decision in the third layer is determined by the quality of the data generated in the second. Before evaluating vendors on their intent-based authorization or escalation capabilities, ask what their observability layer actually captures: does it record agent reasoning and not just actions? Can it attribute every action to a specific user, intent, and moment in time? Can it build behavioral baselines that are specific enough to distinguish meaningful drift from normal variability? A strong governance layer built on weak observability will produce unreliable decisions at scale.</p><p><strong>Make an explicit decision about non-deterministic governance.</strong> Introducing dynamic, intent-based policy decisions into your security architecture is not a default next step. It is a deliberate choice with real tradeoffs. Non-deterministic governance reduces the risk of agents acting outside their intended purpose, but it also introduces false positives that can disrupt legitimate agent workflows and false negatives that can create a false sense of security. CISOs should assess their organization&#8217;s tolerance for both before committing to this layer. For organizations in early stages of agent deployment, a mature observability layer with human-reviewed recommendations may be the more prudent starting point.</p><p><strong>Assess your agent archetypes before selecting a vendor.</strong> The right runtime security architecture depends heavily on where your agents are running. Homegrown agents in cloud infrastructure have different visibility and enforcement requirements than SaaS platform agents or local developer tools like Cursor and Claude Code. Many vendors have strong coverage for one archetype and limited coverage for others. Map your current and anticipated agent population before evaluating platforms, and prioritize vendors whose enforcement surface matches where your agents actually operate.</p><p><strong>Treat MCP security as a distinct requirement.</strong> Evaluate whether your vendor of choice takes a gateway approach, a direct-access approach, or both, and understand the tradeoffs of each. Organizations standardizing on MCP should explicitly require coverage of supply chain risk, hard-coded credential detection, and cross-tool exfiltration detection as part of any runtime security evaluation.</p><h2><strong>Vendor Deep Dives</strong></h2><p>The remainder of the report grounds this architecture in real-world implementation patterns through case studies and representative vendors. We&#8217;ve partnered with 15 vendors who are leading innovation in this new ecosystem. They include the following:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!GA02!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F245a372d-e8ae-444a-87ba-dca8fdef3d0e_1324x766.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!GA02!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F245a372d-e8ae-444a-87ba-dca8fdef3d0e_1324x766.png 424w, https://substackcdn.com/image/fetch/$s_!GA02!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F245a372d-e8ae-444a-87ba-dca8fdef3d0e_1324x766.png 848w, https://substackcdn.com/image/fetch/$s_!GA02!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F245a372d-e8ae-444a-87ba-dca8fdef3d0e_1324x766.png 1272w, https://substackcdn.com/image/fetch/$s_!GA02!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F245a372d-e8ae-444a-87ba-dca8fdef3d0e_1324x766.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!GA02!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F245a372d-e8ae-444a-87ba-dca8fdef3d0e_1324x766.png" width="1324" height="766" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/245a372d-e8ae-444a-87ba-dca8fdef3d0e_1324x766.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:766,&quot;width&quot;:1324,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Logos of the 15 vendors featured in the deep dive&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Logos of the 15 vendors featured in the deep dive" title="Logos of the 15 vendors featured in the deep dive" srcset="https://substackcdn.com/image/fetch/$s_!GA02!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F245a372d-e8ae-444a-87ba-dca8fdef3d0e_1324x766.png 424w, https://substackcdn.com/image/fetch/$s_!GA02!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F245a372d-e8ae-444a-87ba-dca8fdef3d0e_1324x766.png 848w, https://substackcdn.com/image/fetch/$s_!GA02!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F245a372d-e8ae-444a-87ba-dca8fdef3d0e_1324x766.png 1272w, https://substackcdn.com/image/fetch/$s_!GA02!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F245a372d-e8ae-444a-87ba-dca8fdef3d0e_1324x766.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>Aembit</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!J_jU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5bbf5a8a-db3a-456c-84b2-62e9297b352b_1600x905.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!J_jU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5bbf5a8a-db3a-456c-84b2-62e9297b352b_1600x905.png 424w, https://substackcdn.com/image/fetch/$s_!J_jU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5bbf5a8a-db3a-456c-84b2-62e9297b352b_1600x905.png 848w, https://substackcdn.com/image/fetch/$s_!J_jU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5bbf5a8a-db3a-456c-84b2-62e9297b352b_1600x905.png 1272w, https://substackcdn.com/image/fetch/$s_!J_jU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5bbf5a8a-db3a-456c-84b2-62e9297b352b_1600x905.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!J_jU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5bbf5a8a-db3a-456c-84b2-62e9297b352b_1600x905.png" width="1456" height="824" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5bbf5a8a-db3a-456c-84b2-62e9297b352b_1600x905.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:824,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Aembit vendor profile and security model diagram&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Aembit vendor profile and security model diagram" title="Aembit vendor profile and security model diagram" srcset="https://substackcdn.com/image/fetch/$s_!J_jU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5bbf5a8a-db3a-456c-84b2-62e9297b352b_1600x905.png 424w, https://substackcdn.com/image/fetch/$s_!J_jU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5bbf5a8a-db3a-456c-84b2-62e9297b352b_1600x905.png 848w, https://substackcdn.com/image/fetch/$s_!J_jU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5bbf5a8a-db3a-456c-84b2-62e9297b352b_1600x905.png 1272w, https://substackcdn.com/image/fetch/$s_!J_jU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5bbf5a8a-db3a-456c-84b2-62e9297b352b_1600x905.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Overview:</strong> Aembit approaches agent security as a runtime identity and access-control problem. Its core model is built around replacing static credentials with identity-based, policy-driven access in which applications, workloads, and agents receive short-lived credentials at runtime rather than storing secrets directly. In this architecture, the agent does not need to manage or retain the credential itself; Aembit verifies identity, evaluates policy, brokers the appropriate access, and centralizes the resulting audit trail. The platform is therefore best understood as a runtime enforcement layer for non-human identity (NHI) access across workloads, services, and agentic systems.</p><p><strong>Discovery:</strong> Aembit defines a non&#8209;human identity for each AI agent and optionally binds upstream user context. Policies then enforce least&#8209;privilege access based on the combined agent and human attributes. Blended identity is important because users do not want agents to inherit all their rights; rights should be task&#8209;specific.</p><p>At the architectural level, Aembit&#8217;s secretless model is designed to reduce both the operational burden and the attack surface associated with static secrets. The platform intercepts outbound access requests, cryptographically attests the workload or agent identity based on the underlying runtime or infrastructure, applies authorization policy, and then issues or retrieves a short-lived credential for the target system. That credential is delivered only for the specific interaction and is not intended to persist in developer-managed workflows or long-lived application configuration. In environments where dynamic credentialing is supported, this materially reduces direct credential handling by developers and operators while creating a more centralized and auditable access path.</p><p><strong>Deterministic Governance:</strong> Using our runtime-security framework as an analytical lens, Aembit appears strongest at the <strong>deterministic governance</strong> layer, and in <strong>control and escalation</strong> and <strong>continuous observability</strong>. At the deterministic governance layer, its architecture is well aligned to enforcing runtime access boundaries around agent-to-service and agent-to-tool interactions by brokering credentials only at the moment of use and by inserting an identity-aware gateway into MCP request flows. The platform&#8217;s emphasis on short-lived access, centralized policy, and circuit-breaker controls maps naturally to control and escalation, particularly in environments where security teams want an immediate mechanism for revoking or halting agent access. Its centralized logging and blended-identity model also support continuous observability by creating a clear record of which user, agent, and service were involved in a given transaction.</p><p>One of Aembit&#8217;s clearest strengths is the conceptual clarity of its model. Rather than beginning with discovery or post hoc monitoring, it starts from the premise that non-human access should be governed through identity, short-lived authorization, policy evaluation, and centralized control. That framework is especially compelling for organizations that already view agent security as an extension of the broader workload and non-human identity problem. The same architectural principles can be applied across traditional workloads, scripts, cloud services, MCP-connected agents, and other machine-driven access patterns, making the platform well suited to enterprises looking for a unified runtime access layer rather than a point solution focused only on agents.</p><p><strong>MCP Security:</strong> Aembit extends this model into MCP-mediated agent workflows through a dedicated control plane. Its MCP architecture introduces an identity gateway between agents and MCP-connected services, along with an authorization service that combines workload identity and human identity into what the company describes as a blended identity. This enables access decisions and audit trails to reflect both the software entity and the user operating behind it, which is especially important for user-driven agents acting on behalf of a person. Within this model, Aembit emphasizes separation between agent identity, MCP server identity, and downstream service credentials, with the goal of improving control and traceability across MCP-based interactions.</p><p><strong>Analyst recommendation:</strong> Aembit is particularly well positioned for organizations seeking to modernize runtime access around agents without forcing developers to handle credentials directly. Its model of cryptographic attestation, ephemeral access, policy-based authorization, and centralized auditability provides a strong foundation for securing agent interactions with sensitive systems and services. For enterprises approaching agent security through the broader lens of non-human identity and runtime access management, Aembit offers a coherent and architecturally consistent approach.</p><h3><strong>Apono</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!KkIU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4440ceaf-7c96-43d4-8564-14b3e9cb91f0_1600x633.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!KkIU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4440ceaf-7c96-43d4-8564-14b3e9cb91f0_1600x633.png 424w, https://substackcdn.com/image/fetch/$s_!KkIU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4440ceaf-7c96-43d4-8564-14b3e9cb91f0_1600x633.png 848w, https://substackcdn.com/image/fetch/$s_!KkIU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4440ceaf-7c96-43d4-8564-14b3e9cb91f0_1600x633.png 1272w, https://substackcdn.com/image/fetch/$s_!KkIU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4440ceaf-7c96-43d4-8564-14b3e9cb91f0_1600x633.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!KkIU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4440ceaf-7c96-43d4-8564-14b3e9cb91f0_1600x633.png" width="1456" height="576" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4440ceaf-7c96-43d4-8564-14b3e9cb91f0_1600x633.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:576,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Apono vendor profile highlighting intent-based access models&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Apono vendor profile highlighting intent-based access models" title="Apono vendor profile highlighting intent-based access models" srcset="https://substackcdn.com/image/fetch/$s_!KkIU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4440ceaf-7c96-43d4-8564-14b3e9cb91f0_1600x633.png 424w, https://substackcdn.com/image/fetch/$s_!KkIU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4440ceaf-7c96-43d4-8564-14b3e9cb91f0_1600x633.png 848w, https://substackcdn.com/image/fetch/$s_!KkIU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4440ceaf-7c96-43d4-8564-14b3e9cb91f0_1600x633.png 1272w, https://substackcdn.com/image/fetch/$s_!KkIU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4440ceaf-7c96-43d4-8564-14b3e9cb91f0_1600x633.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Overview:</strong> Apono&#8217;s primary differentiator is the depth of its intent-based access model. Where most platforms treat intent as a signal to inform policy, Apono makes it the central control mechanism. The platform requires agents to declare intent before acting, evaluates that declaration against real-time context including resource attributes, data sensitivity, and environment state, and provisions credentials specifically for that declared operation. The access cycle is continuous: declare intent, evaluate context, grant temporary authority, enforce during execution, revoke, and log.</p><p><strong>Deterministic Governance:</strong> The architectural foundation reflects a deliberate choice to move beyond static access management. Traditional IAM uses fixed policies that cannot adapt to non-deterministic agents operating at machine speed. Apono&#8217;s dynamic policy engine evaluates user context, resource attributes, and environment state in real time, which is the same shift cloud infrastructure required when moving from static server configurations to dynamic provisioning. The on-premises component reinforces this architecture: rather than sitting in the network path, Apono installs a component directly in the customer environment that handles secrets and access grants locally. Customer credentials never touch third-party infrastructure, which matters for regulated industries where data residency is a hard constraint and also avoids the latency and bottleneck risks that proxy-based architectures can introduce at scale.</p><p><strong>MCP Security:</strong> The Apono MCP gateway wraps all MCP tool interactions, injecting dynamic secrets, scopes, and intent parameters at runtime so agents never possess credentials directly. Policies can be configured at the tool level to allow certain operations while escalating others, giving security teams granular control over what each agent can actually do within a granted session. The platform also provides managed tools for resources like Postgres, Kubernetes, and AWS, offering safe access pathways that sit within the intent and policy framework.</p><p><strong>Analysis of Non-Deterministic Behavior:</strong> For <strong>continuous observability</strong>, AI-generated session summaries translate raw audit logs into readable accounts of what an agent did and why, making the audit trail actionable for security teams who cannot realistically parse event-level logs across large numbers of concurrent agent sessions.</p><p>Apono recently launched <a href="https://agentprivilegelab.ai/">Agent Privilege Lab</a>, which maps agent-specific attack patterns to established frameworks like OWASP and MITRE, and includes an intent-based access control simulator for testing guardrails. A capture the flag environment is also in the works, where practitioners can attempt to socially engineer agents and experience firsthand how agents can be manipulated to cause harm. These resources reflect genuine investment in the broader practitioner community beyond the product itself.</p><p>Apono acknowledges one open challenge on their roadmap: translating non-deterministic agent intent into deterministic enforceable scopes. The intent analyzer is itself an agent, which introduces some of the same unpredictability it is trying to govern. This is a hard problem the industry has not solved, and Apono is candid that deeper intent translation is ongoing work.</p><p><strong>Non-Deterministic Governance:</strong> <strong>Intent-based authorization</strong> is the core of the platform. Rather than simply blocking actions that fall outside declared intent, Apono evaluates the risk level of the privileges being requested. Low-risk operations proceed uninterrupted, while high-risk privileges that could lead to destructive actions trigger a <strong>control and escalation</strong> response: a human-in-the-loop challenge that pauses execution until a human approves or rejects the request. This distinction matters because it means agents can complete more work autonomously, with humans brought into the loop only when the stakes warrant it. The platform dynamically provisions the lowest-risk privileges sufficient to complete a given task, ensuring least privilege is enforced not as a static policy but as a continuous, context-aware calculation. This makes control and escalation a natural extension of the intent model rather than a blunt interrupt mechanism.</p><p><strong>Analyst Recommendation:</strong> Apono is a strong fit for organizations that want intent as the primary control layer rather than a secondary signal, and particularly for those already managing human and non-human access through Apono, where extending the same policy engine to agents is architecturally natural and operationally straightforward. The platform&#8217;s approach reflects a broader philosophy of making security teams enablers of the business.</p><h3><strong>Astrix</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Q56r!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82e2bca9-a09b-4a4b-b996-c41ca4ea2aae_1600x898.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Q56r!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82e2bca9-a09b-4a4b-b996-c41ca4ea2aae_1600x898.png 424w, https://substackcdn.com/image/fetch/$s_!Q56r!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82e2bca9-a09b-4a4b-b996-c41ca4ea2aae_1600x898.png 848w, https://substackcdn.com/image/fetch/$s_!Q56r!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82e2bca9-a09b-4a4b-b996-c41ca4ea2aae_1600x898.png 1272w, https://substackcdn.com/image/fetch/$s_!Q56r!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82e2bca9-a09b-4a4b-b996-c41ca4ea2aae_1600x898.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Q56r!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82e2bca9-a09b-4a4b-b996-c41ca4ea2aae_1600x898.png" width="1456" height="817" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/82e2bca9-a09b-4a4b-b996-c41ca4ea2aae_1600x898.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:817,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Astrix Security vendor profile and threat detection capabilities&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Astrix Security vendor profile and threat detection capabilities" title="Astrix Security vendor profile and threat detection capabilities" srcset="https://substackcdn.com/image/fetch/$s_!Q56r!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82e2bca9-a09b-4a4b-b996-c41ca4ea2aae_1600x898.png 424w, https://substackcdn.com/image/fetch/$s_!Q56r!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82e2bca9-a09b-4a4b-b996-c41ca4ea2aae_1600x898.png 848w, https://substackcdn.com/image/fetch/$s_!Q56r!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82e2bca9-a09b-4a4b-b996-c41ca4ea2aae_1600x898.png 1272w, https://substackcdn.com/image/fetch/$s_!Q56r!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82e2bca9-a09b-4a4b-b996-c41ca4ea2aae_1600x898.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Overview:</strong> Astrix has been building in the non-human identity space for five and a half years, starting with app-to-app security before the NHI category had a name. That history gives their ML threat detection models a competitive advantage that newer entrants cannot easily replicate: training data from millions of real NHI behaviors across years of production deployments, covering a range of environments, access patterns, and attack types that take time to accumulate.</p><p><strong>Discovery:</strong> Astrix uses fingerprinting to identify agents already running in cloud platforms such as Bedrock agents and custom GPTs, integrates with existing endpoint tools like Defender and CrowdStrike to find local MCP servers without deploying a new agent, and maps third-party integrations for supply chain risk.</p><p><strong>Deterministic Governance:</strong> Rule-based access policies combined with ephemeral credential provisioning ensure agents operate within defined boundaries without holding persistent credentials. The Agent Control Plane lets developers register agents via Terraform and exchange existing tokens such as Kubernetes OIDC for specifically scoped temporary tokens that expire automatically when the agent is undeployed, improving security without creating a new bottleneck in the development workflow.</p><p><strong>Analysis of Non-Deterministic Behavior:</strong> <strong>Behavioral tracking</strong> is where Astrix is strongest. Years of real NHI training data mean the detection models have genuine signal, distinguishing meaningful anomalies from noise in a way that requires time and data volume to build. For <strong>continuous observability</strong>, an identity graph maps operator-to-agent-to-resource relationships, giving teams the relational context needed to reconstruct what happened during any session and understand how privilege flowed across the agent ecosystem.</p><p><strong>MCP Security:</strong> Astrix combines both approaches identified in the framework. An MCP gateway provides enforcement and traffic-level control, while hook-based integrations with Cursor and Claude hooks add direct-access observability for local agent environments. Supply chain risk mapping across third-party MCP integrations adds ecosystem-level visibility, and discovery of local MCP servers through existing endpoint tooling means coverage does not depend entirely on routing traffic through a proxy.</p><p><strong>Analyst Recommendation:</strong> Astrix is a strong fit for security and identity teams that want ML-backed behavioral detection with genuine training depth, and a developer-friendly path to ephemeral access governance that reduces the credential hygiene problems that tend to accumulate quietly in fast-moving engineering organizations.</p><h3><strong>ConductorOne</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!aD48!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feac9c832-0494-4419-9dd2-b0006b22224f_1524x1214.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!aD48!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feac9c832-0494-4419-9dd2-b0006b22224f_1524x1214.png 424w, https://substackcdn.com/image/fetch/$s_!aD48!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feac9c832-0494-4419-9dd2-b0006b22224f_1524x1214.png 848w, https://substackcdn.com/image/fetch/$s_!aD48!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feac9c832-0494-4419-9dd2-b0006b22224f_1524x1214.png 1272w, https://substackcdn.com/image/fetch/$s_!aD48!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feac9c832-0494-4419-9dd2-b0006b22224f_1524x1214.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!aD48!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feac9c832-0494-4419-9dd2-b0006b22224f_1524x1214.png" width="1456" height="1160" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/eac9c832-0494-4419-9dd2-b0006b22224f_1524x1214.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1160,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;ConductorOne vendor profile emphasizing identity governance&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="ConductorOne vendor profile emphasizing identity governance" title="ConductorOne vendor profile emphasizing identity governance" srcset="https://substackcdn.com/image/fetch/$s_!aD48!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feac9c832-0494-4419-9dd2-b0006b22224f_1524x1214.png 424w, https://substackcdn.com/image/fetch/$s_!aD48!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feac9c832-0494-4419-9dd2-b0006b22224f_1524x1214.png 848w, https://substackcdn.com/image/fetch/$s_!aD48!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feac9c832-0494-4419-9dd2-b0006b22224f_1524x1214.png 1272w, https://substackcdn.com/image/fetch/$s_!aD48!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feac9c832-0494-4419-9dd2-b0006b22224f_1524x1214.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Overview:</strong> ConductorOne approaches agent security from the perspective of identity governance and access management. Its core thesis is that the same primitives enterprises already use to govern human access, such as access graphs, entitlement models, certification workflows, self-service requests, and approval policies can be extended to govern agentic access. Rather than treating agents as a separate security category, ConductorOne positions them as another class of principal within a broader access-control system. The company frames the enterprise AI challenge around three related gaps: visibility, governance, and adoption, arguing that visibility alone is insufficient without governed workflows to translate discovery into controlled access distribution.</p><p><strong>Discovery</strong>: ConductorOne&#8217;s platform is designed not just to show where agents and tools exist, but to translate that visibility into requestable entitlements, approval paths, and governed access distribution. With more than 300 prebuilt connectors and over 3,000 prebuilt MCPs already generated for the platform, the company provides broad catalog-level access to tools out of the box.. The same connector-generation techniques developed for broader identity integrations are used to scale MCP coverage, allowing agent-facing tools to slot into an existing governance fabric.</p><p><strong>Deterministic Governance:</strong> Administrators can register MCP servers, select and approve specific tools, and bundle those tools into profiles that function as governed entitlements. A profile such as a read-only GitHub package can be requested through the same self-service workflow used for human access, routed through approval policies, and granted in a controlled way. This turns MCP tool access into a governable access-management problem. Credentials are managed centrally rather than stored on user endpoints, reducing the need for end users to maintain local secrets.</p><p><strong>Non-Deterministic Behavioral Analysis:</strong> The platform logs MCP tool usage and exposes audit trails that can be streamed into downstream monitoring systems, making each tool call visible as part of a broader access-governance record.</p><p><strong>Non-Deterministic Governance:</strong> The same approval machinery used for human access applies to agentic access, with policy-driven approvals, request workflows, and kill-switch controls at the tool, server, or tenant level. ConductorOne argues agent governance should focus on governing privileged operations directly, what an agent is allowed to do, under what policy, and when a human should be pulled into the loop with each discrete MCP tool call treated as a governable action.</p><p><strong>MCP Security:</strong> ConductorOne&#8217;s MCP proxy model is its most distinctive technical element. Approved tools are bundled into profiles functioning as governed entitlements, requested and granted through existing self-service workflows. This reduces the need for employees to source, configure, and connect MCPs independently, shifting connection risk and configuration burden away from individual users and into a centrally governed model.</p><p><strong>Analyst Recommendation:</strong> ConductorOne&#8217;s strongest fit is for organizations that see agent security primarily as a governed access problem. Its heritage in identity governance gives it a natural advantage in turning agentic access into something requestable, policy-driven, and reviewable using systems enterprises already understand. The MCP proxy model and prebuilt catalog of over 3,000 MCPs offer one of the most operationally ready paths to governed tool access discussed in these briefings. For buyers approaching the agentic transition through the lens of entitlement management, self-service enablement, and access governance, ConductorOne offers a notably coherent path.</p><h3><strong>Cyata (Acquired by Check Point)</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!FH6y!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd478c7c-332b-49a2-aaa8-37eca4363ded_694x532.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!FH6y!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd478c7c-332b-49a2-aaa8-37eca4363ded_694x532.png 424w, https://substackcdn.com/image/fetch/$s_!FH6y!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd478c7c-332b-49a2-aaa8-37eca4363ded_694x532.png 848w, https://substackcdn.com/image/fetch/$s_!FH6y!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd478c7c-332b-49a2-aaa8-37eca4363ded_694x532.png 1272w, https://substackcdn.com/image/fetch/$s_!FH6y!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd478c7c-332b-49a2-aaa8-37eca4363ded_694x532.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!FH6y!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd478c7c-332b-49a2-aaa8-37eca4363ded_694x532.png" width="694" height="532" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bd478c7c-332b-49a2-aaa8-37eca4363ded_694x532.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:532,&quot;width&quot;:694,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Cyata vendor profile showing broad-surface agent discovery&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Cyata vendor profile showing broad-surface agent discovery" title="Cyata vendor profile showing broad-surface agent discovery" srcset="https://substackcdn.com/image/fetch/$s_!FH6y!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd478c7c-332b-49a2-aaa8-37eca4363ded_694x532.png 424w, https://substackcdn.com/image/fetch/$s_!FH6y!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd478c7c-332b-49a2-aaa8-37eca4363ded_694x532.png 848w, https://substackcdn.com/image/fetch/$s_!FH6y!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd478c7c-332b-49a2-aaa8-37eca4363ded_694x532.png 1272w, https://substackcdn.com/image/fetch/$s_!FH6y!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd478c7c-332b-49a2-aaa8-37eca4363ded_694x532.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Overview:</strong> Cyata approaches agent security as a control-plane problem for agentic identity, built around the view that agents operate across multiple enterprise surfaces simultaneously and require a unified layer for discovery, governance, and runtime control. Its platform discovers and secures agents across endpoints, browsers, SaaS environments, and cloud infrastructure, reflecting a broader surface area than vendors focused on a single runtime or protocol layer. Cyata&#8217;s acquisition by Check Point positions the technology within a broader AI defense platform rather than as a standalone point product.</p><p><strong>Discovery:</strong> A major strength is the breadth and depth of Cyata&#8217;s discovery layer, spanning endpoint-based developer tools, browser-based AI usage, SaaS agent platforms, and cloud-native agent deployments, with attribution back to the human owner of each agent. The platform also reconstructs historical agent activity from artifacts, journals, and existing telemetry, including for agents already operating before security controls were deployed without requiring a proxy in the data path. This retrospective visibility is especially valuable in environments where agents may already be in use but poorly documented.</p><p><strong>Deterministic Governance:</strong> Cyata provides tool-level governance and policy enforcement across endpoints and browsers through a single control plane that can define and enforce rules across all agent surfaces. MCP risk handling and static policy controls govern which agent capabilities are permitted across the full operating environment.</p><p><strong>Non-Deterministic Behavioral Analysis:</strong> Cyata&#8217;s most differentiated capability is its focus on compound or &#8220;toxic&#8221; combinations of risk. Rather than treating each finding in isolation, the platform identifies dangerous combinations of posture conditions, agent configurations, credentials, and runtime behaviors that together create materially higher risk, such as agents operating with untrusted MCP servers, static credentials, autonomous configurations without oversight, and privilege inheritance patterns creating escalation risk.</p><p><strong>Non-Deterministic Governance:</strong> Cyata&#8217;s guardian-agent approach is particularly notable: within its MCP proxy flow, the platform requires the agent to provide justification for tool usage and evaluates that justification before allowing the action to proceed. This intent-aware pattern governs not just access but the rationale behind access. Human-in-the-loop approval is also available as an alternative enforcement mode.</p><p><strong>MCP Security:</strong> Cyata&#8217;s MCP proxy model evaluates agent tool requests before execution through either the guardian agent or human-in-the-loop approval. This adds an intent-check layer to tool invocation, making it one of the more explicit examples of AI-mediated intent control in the current market, a meaningful distinction from simpler allow-or-block proxy models.</p><p><strong>Analyst Recommendation:</strong> Cyata&#8217;s strongest fit is for organizations that want broad-surface discovery, rich observability, and context-aware runtime enforcement across agents already dispersed across endpoints, browsers, SaaS platforms, and cloud systems. The toxic-combination detection model offers one of the most distinctive analytical approaches in these briefings, and the guardian-agent intent-aware proxy gives Cyata a stronger claim to true runtime decisioning than static policy models. Its single control plane across surfaces and Check Point integration make it especially compelling for enterprises seeking agent security within a broader security platform rather than as an isolated niche tool.</p><h3><strong>Descope</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Hjsx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84981fbc-7382-48b5-a851-9cc91d9302fc_1014x576.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Hjsx!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84981fbc-7382-48b5-a851-9cc91d9302fc_1014x576.png 424w, https://substackcdn.com/image/fetch/$s_!Hjsx!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84981fbc-7382-48b5-a851-9cc91d9302fc_1014x576.png 848w, https://substackcdn.com/image/fetch/$s_!Hjsx!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84981fbc-7382-48b5-a851-9cc91d9302fc_1014x576.png 1272w, https://substackcdn.com/image/fetch/$s_!Hjsx!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84981fbc-7382-48b5-a851-9cc91d9302fc_1014x576.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Hjsx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84981fbc-7382-48b5-a851-9cc91d9302fc_1014x576.png" width="1014" height="576" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/84981fbc-7382-48b5-a851-9cc91d9302fc_1014x576.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:576,&quot;width&quot;:1014,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Descope vendor profile and no-code identity provider model&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Descope vendor profile and no-code identity provider model" title="Descope vendor profile and no-code identity provider model" srcset="https://substackcdn.com/image/fetch/$s_!Hjsx!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84981fbc-7382-48b5-a851-9cc91d9302fc_1014x576.png 424w, https://substackcdn.com/image/fetch/$s_!Hjsx!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84981fbc-7382-48b5-a851-9cc91d9302fc_1014x576.png 848w, https://substackcdn.com/image/fetch/$s_!Hjsx!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84981fbc-7382-48b5-a851-9cc91d9302fc_1014x576.png 1272w, https://substackcdn.com/image/fetch/$s_!Hjsx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84981fbc-7382-48b5-a851-9cc91d9302fc_1014x576.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Overview:</strong> Descope is a no-code identity provider whose core business is issuing and managing identities, extended to AI agents through the Agentic Identity Hub. Unlike most vendors in this report, Descope approaches agent security from the developer and builder side: its primary users are teams building MCP servers and AI agents, not security teams deploying runtime controls after the fact.</p><p><strong>Deterministic Governance:</strong> The value proposition is organized around three distinct users. For teams building MCP servers, Descope acts as the dedicated authorization server, handling user authentication, consent management, client registration, and scope-based access control at the tool level. For teams building AI agents internally using frameworks like LangChain or CrewAI, Descope manages the full credential lifecycle for over 70 out-of-the-box tools including HubSpot, Notion, and GitHub, issuing short-lived scoped credentials so development teams do not have to build their own auth infrastructure. For security and IT teams, Descope&#8217;s position as the identity layer enables runtime policy enforcement: a legal team member using Claude to access Salesforce can be restricted to read-only operations on contracts without being able to modify deals, enforced at the identity layer rather than through a separate security tool.</p><p><strong>Non-Deterministic Behavioral Analysis:</strong> Each agent gets a unique agent ID combining client ID and associated user ID, creating the identity chain of custody that Descope sees as the central problem to solve: when something goes wrong, you need to be able to trace the action back to the agent and the delegating user.</p><p><strong>MCP Security:</strong> When an agent connects to an MCP server, Descope applies no-code registration controls: accepting only verified clients like Claude or Cloudflare agents, checking originating IP addresses against abuse databases, filtering by geography, and assigning scopes based on verification status. Consent screens surface scope requests to end users before access is granted, with consent stored and time-bounded to the session.</p><h3><strong>Entro</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!gdpt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c48b2e-1670-4f62-8f86-e3503bc5fcb2_1333x673.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gdpt!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c48b2e-1670-4f62-8f86-e3503bc5fcb2_1333x673.png 424w, https://substackcdn.com/image/fetch/$s_!gdpt!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c48b2e-1670-4f62-8f86-e3503bc5fcb2_1333x673.png 848w, https://substackcdn.com/image/fetch/$s_!gdpt!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c48b2e-1670-4f62-8f86-e3503bc5fcb2_1333x673.png 1272w, https://substackcdn.com/image/fetch/$s_!gdpt!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c48b2e-1670-4f62-8f86-e3503bc5fcb2_1333x673.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gdpt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c48b2e-1670-4f62-8f86-e3503bc5fcb2_1333x673.png" width="1333" height="673" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e2c48b2e-1670-4f62-8f86-e3503bc5fcb2_1333x673.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:673,&quot;width&quot;:1333,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Entro Security vendor profile featuring protocol-agnostic credential control&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Entro Security vendor profile featuring protocol-agnostic credential control" title="Entro Security vendor profile featuring protocol-agnostic credential control" srcset="https://substackcdn.com/image/fetch/$s_!gdpt!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c48b2e-1670-4f62-8f86-e3503bc5fcb2_1333x673.png 424w, https://substackcdn.com/image/fetch/$s_!gdpt!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c48b2e-1670-4f62-8f86-e3503bc5fcb2_1333x673.png 848w, https://substackcdn.com/image/fetch/$s_!gdpt!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c48b2e-1670-4f62-8f86-e3503bc5fcb2_1333x673.png 1272w, https://substackcdn.com/image/fetch/$s_!gdpt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c48b2e-1670-4f62-8f86-e3503bc5fcb2_1333x673.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Overview:</strong> Entro&#8217;s core thesis is protocol-agnostic: agents will always need credentials to access enterprise resources, making the identity layer a universal control surface that works regardless of whether agents use MCP, direct APIs, local tools, or browser automation. This is a direct architectural counter to gateway-based approaches, which only see traffic that flows through them. If an agent needs enterprise access, it needs a non-human identity, and that credential becomes both the discovery signal and the enforcement point.</p><p><strong>Discovery:</strong> Rather than deploying a new sensor or routing traffic through a proxy, Entro maps agents across multiple surfaces simultaneously: endpoint detection identifies agents running on managed devices, cloud IAM enumeration finds agents operating through cloud identities, SaaS interrogation discovers agents configured inside tools like GitHub, Datadog, and Slack, and network fingerprinting identifies agents by their connection patterns. Every discovered agent is tied back to the human operator who provisioned it, which is the attribution chain that makes every subsequent layer of runtime security possible.</p><p><strong>Deterministic Governance:</strong> Entro&#8217;s most distinctive capability at this layer is the permissionless agent model. Rather than granting credentials that an agent holds persistently, permissions are provisioned on the fly based on policy and automatically revoked after use. Custom policies control which resources an agent can access, and expiration dates can be set on credentials so that time-bounded access is enforced by design. There are no standing credentials to steal or misuse.</p><p><strong>Analysis of Non-Deterministic Behavior:</strong> For <strong>behavioral tracking</strong>, the platform detects anomalies against established NHI access patterns, flagging deviations such as access from untrusted locations or mass data encryption attempts. For <strong>continuous observability</strong>, every credential usage event is logged and tied to the agent, the operator, and the resource accessed. Entro recently launched <a href="https://entro.security/blog/mcp-audit-claude-code-plugin-entro/">intent analysis and logging for Claude Code</a>, providing visibility into why an agent is taking an action and creating an auditable record of agent reasoning.</p><p><strong>MCP Security:</strong> Entro takes a direct-access rather than proxy-based approach. It uses native integrations to monitor and control agent activity, which means strong observability and contextual intelligence with governance enforced through the identity layer rather than through traffic interception.</p><p><strong>Analyst Recommendation:</strong> Entro is a strong fit for organizations building runtime security on top of an existing NHI program, or for those starting with discovery and deterministic access governance before layering in deeper runtime controls. It is particularly well suited for heterogeneous agent environments where a gateway would only provide partial visibility, and where permissionless just-in-time access is a security priority.</p><h3><strong>Keycard</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!BvdL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fe304ce-becc-4a77-855a-62ef6e0e5308_1600x827.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!BvdL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fe304ce-becc-4a77-855a-62ef6e0e5308_1600x827.png 424w, https://substackcdn.com/image/fetch/$s_!BvdL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fe304ce-becc-4a77-855a-62ef6e0e5308_1600x827.png 848w, https://substackcdn.com/image/fetch/$s_!BvdL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fe304ce-becc-4a77-855a-62ef6e0e5308_1600x827.png 1272w, https://substackcdn.com/image/fetch/$s_!BvdL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fe304ce-becc-4a77-855a-62ef6e0e5308_1600x827.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!BvdL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fe304ce-becc-4a77-855a-62ef6e0e5308_1600x827.png" width="1456" height="753" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3fe304ce-becc-4a77-855a-62ef6e0e5308_1600x827.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:753,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Keycard vendor profile detailing credential issuance enforcement&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Keycard vendor profile detailing credential issuance enforcement" title="Keycard vendor profile detailing credential issuance enforcement" srcset="https://substackcdn.com/image/fetch/$s_!BvdL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fe304ce-becc-4a77-855a-62ef6e0e5308_1600x827.png 424w, https://substackcdn.com/image/fetch/$s_!BvdL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fe304ce-becc-4a77-855a-62ef6e0e5308_1600x827.png 848w, https://substackcdn.com/image/fetch/$s_!BvdL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fe304ce-becc-4a77-855a-62ef6e0e5308_1600x827.png 1272w, https://substackcdn.com/image/fetch/$s_!BvdL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fe304ce-becc-4a77-855a-62ef6e0e5308_1600x827.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Overview:</strong> Keycard is a developer-centric vendor building runtime security infrastructure for agents, with a primary focus on making credential issuance itself the enforcement point. Rather than layering controls on top of tokens that were minted at service-account creation time, Keycard issues credentials at the moment of tool calls, when the agent has full context about what it is doing and why.</p><p><strong>Discovery:</strong> Keycard&#8217;s discovery capability is framed as a dependency of its runtime controls, not a standalone product. The platform builds an estate model of the customer environment, a unified data model of agents, their tool inventories, and the resources they can reach. This model is enriched in real time from external sources including SIEM platforms, DSPM providers (such as BigID and Sciera), and supply chain security tooling. The result is a continuously updated map of what agents exist, what tools they use, and what the current risk posture of those tools is, including whether a CLI, MCP server, or package has known vulnerabilities. The design philosophy here is that discovery and enforcement that fires without a sufficient data model produces noise rather than signal, policies must be enforced from a unified data model and estate. For Keycard, discovery is not a box to check at deployment. It is the substrate on which runtime decisions are made.</p><p><strong>Deterministic Governance:</strong> Keycard aims to support both human-in-the-loop and autonomous operation models, and the platform is designed to navigate the tension between them. The team explicitly identifies consent fatigue as a design constraint: excessive approval requests dilute the signal for decisions that genuinely require human judgment. The system is built to learn over time where approvals have historically been granted, and to surface only the approval requests that carry real decision value, eventually proposing autonomous policy updates for patterns that have been consistently approved.</p><p>Dynamic termination and revocation capabilities are in active development. The target state allows the platform to pause a session mid-execution, revoke access to a specific sub-session or reasoning branch, or terminate entirely based on real-time risk signals. Staged policy rollouts, impact analysis against historical resolution patterns, and rollback mechanisms are also on the near-term roadmap.</p><p>In terms of <strong>agent observability</strong>, Keycard captures two complementary audit streams at the point of credential issuance: the agent&#8217;s own explanation of its intent (what it believes it is doing and why), and the full lifecycle trajectory of tool calls leading to that moment. These streams are combined into a session-level record that attributes every access decision to a specific agent, session, and reasoning chain. The architecture provides the audit trail that compliance and incident investigation teams require, and it forms the input layer for Keycard&#8217;s authorization logic.</p><p>Session hierarchy is explicit in the platform. Keycard maintains a tree structure of agent sessions and sub-sessions, which is particularly relevant for long-running multi-agent chains where specialized agents hand off to one another. This enables selective action, security teams can revoke a specific reasoning branch or sub-session without terminating the parent workflow</p><p><strong>Non-Deterministic Behavioral Analysis:</strong> Keycard sees behavioral analysis as a key part in building its non-deterministic governance layer. The current architecture captures the inputs needed for behavioral baseline construction: session trajectories, tool call sequences, credential request patterns, with a focus on autonomous drift detection and risk scoring are near-term development priorities rather than current capabilities.</p><p><strong>Non-Deterministic Governance:</strong> This is Keycard&#8217;s primary differentiation. At tool call time, the platform evaluates authorization using dual context: the agent&#8217;s stated reasoning and the cumulative trajectory of its session. An agent that has retrieved a single customer record presents a materially different risk profile than one whose session history shows progressive lateral movement, even if both actions are within its nominal permissions. Keycard&#8217;s policy engine evaluates this combined signal to dynamically grant or withhold credentials for that specific tool call, rather than relying on static scopes set at deployment.</p><p>Policy authorship is layered across stakeholders. Agent builders can introduce guardrails scoped to their specific agents. End users can impose constraints such as budget limits. Security teams define organizational risk posture. All layers are resolved before credential issuance, with evaluation flowing from resource level up through user level. Notably, Keycard is designing its policy language to be readable and writable by agents themselves, reflecting an expectation that at agentic scale, autonomous policy management becomes necessary.</p><p><strong>MCP Security:</strong> Keycard addresses MCP security through two mechanisms. First, its supply chain integration can block tool calls to MCP servers with known vulnerabilities, using data ingested from security tooling at the estate modeling layer. Second, because credential issuance happens at the tool call boundary, the enforcement point is MCP-aware by design, the same intent evaluation and lifecycle audit that governs any tool call applies directly to MCP server interactions. This is a structural approach rather than an MCP-specific feature layer, meaning coverage extends naturally as the MCP ecosystem grows without requiring vendor-specific integrations for each server.</p><p><strong>Analyst Recommendation:</strong> Keycard is best suited for organizations who want to instrument the credential layer for agents from the ground up, rather than retrofitting controls onto existing token architectures. The platform is developer-first in its UX and instrumentation (accessible via CLI or UI), which makes it a practical fit for teams where developers and security engineers work in close collaboration. The current product is most relevant to security and identity engineering teams who are designing agent infrastructure at early stages and want the enforcement point to be correct before scale.</p><h3><strong>Microsoft (Entra Agent ID / Agent 365)</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!gGdx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca0e5f68-6789-42c5-90cf-92bc055549ed_791x447.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gGdx!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca0e5f68-6789-42c5-90cf-92bc055549ed_791x447.png 424w, https://substackcdn.com/image/fetch/$s_!gGdx!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca0e5f68-6789-42c5-90cf-92bc055549ed_791x447.png 848w, https://substackcdn.com/image/fetch/$s_!gGdx!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca0e5f68-6789-42c5-90cf-92bc055549ed_791x447.png 1272w, https://substackcdn.com/image/fetch/$s_!gGdx!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca0e5f68-6789-42c5-90cf-92bc055549ed_791x447.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gGdx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca0e5f68-6789-42c5-90cf-92bc055549ed_791x447.png" width="791" height="447" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ca0e5f68-6789-42c5-90cf-92bc055549ed_791x447.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:447,&quot;width&quot;:791,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:130749,&quot;alt&quot;:&quot;Microsoft Entra Agent ID profile highlighting scale and directory integration&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Microsoft Entra Agent ID profile highlighting scale and directory integration" title="Microsoft Entra Agent ID profile highlighting scale and directory integration" srcset="https://substackcdn.com/image/fetch/$s_!gGdx!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca0e5f68-6789-42c5-90cf-92bc055549ed_791x447.png 424w, https://substackcdn.com/image/fetch/$s_!gGdx!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca0e5f68-6789-42c5-90cf-92bc055549ed_791x447.png 848w, https://substackcdn.com/image/fetch/$s_!gGdx!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca0e5f68-6789-42c5-90cf-92bc055549ed_791x447.png 1272w, https://substackcdn.com/image/fetch/$s_!gGdx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca0e5f68-6789-42c5-90cf-92bc055549ed_791x447.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Overview:</strong> Microsoft approaches agent security from a position no other vendor can easily replicate: it is building for an internal environment where agent deployment is already occurring at enormous scale, with visibility into 500,000 agents. Entra Agent ID gives agents a first-class identity inside the Microsoft Entra directory, allowing them to participate in the same identity, access, governance, and protection workflows enterprises already use for human and application identities. Agents are represented as unique identity objects, OAuth-compatible, supporting both autonomous flows and on-behalf-of-user flows.</p><p><strong>Discovery:</strong> Because agents live in the same Entra directory as users and applications, Microsoft provides directory-native discovery across agent populations. The blueprint model acts as reusable templates for creating and governing categories of agents consistently, allowing organizations to define baseline permissions, access boundaries, and management rules for a class of agents rather than configuring each one independently. Every agent is expected to have a sponsor, with governance workflows tracking sponsorship, managing orphaned agents, and automating reassignment or containment as ownership changes.</p><p><strong>Deterministic Governance:</strong> Agents can be included in conditional access policies, governance workflows, lifecycle automation, and audit systems natively within the directory plane. Its Blueprints architecture acts as reusable templates for creating and governing categories of agents consistently, allowing organizations to define the baseline permissions, access boundaries, and management rules for a class of agents rather than configuring each one independently. Access-package approval flows, sponsorship lifecycle management, and just-in-time consent provide layered deterministic controls.</p><p><strong>Non-Deterministic Behavioral Analysis:</strong> Entra audit trails, directory-native metadata, and the ability to distinguish agent activity from other identity activity support continuous observability. In addition, Microsoft&#8217;s roadmap includes ML-driven agent risk detection to deepen behavioral analysis capabilities over time.</p><p><strong>Non-Deterministic Governance:</strong> Conditional access for agents, real-time policy controls, and risk-based enforcement enable dynamic governance decisions. The platform uses a shared policy engine informed by risk signals across identities, devices, networks, and activity, with the ability to contain or quarantine risky agents based on live conditions.</p><p><strong>MCP Security:</strong> Current capabilities center on server-level discovery and network blocking through Agent 365&#8217;s MCP discovery features. Microsoft also applies secure web and AI gateway controls for URL filtering, threat-intelligence filtering, file-transfer restrictions, and prompt-injection protection on agent traffic. The roadmap aims to bring tool-level MCP controls into the same policy engine.</p><p><strong>Analyst Recommendation:</strong> Microsoft&#8217;s strongest differentiation is building agent security as a native extension of a very large existing identity and security platform. The blueprint model offers one of the clearest governance-at-scale approaches discussed in these briefings, and the sponsorship lifecycle model provides a direct answer to enterprise accountability requirements. For organizations already invested in Microsoft 365, Azure, Entra, Defender, and Purview, agent identity, governance, protection, and network controls come together in one operational model, making Microsoft especially compelling where scale and platform consolidation are priorities.</p><h3><strong>Noma</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!dx7o!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0ac083c-9edd-4cb3-914a-03fd201016ee_1020x520.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!dx7o!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0ac083c-9edd-4cb3-914a-03fd201016ee_1020x520.png 424w, https://substackcdn.com/image/fetch/$s_!dx7o!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0ac083c-9edd-4cb3-914a-03fd201016ee_1020x520.png 848w, https://substackcdn.com/image/fetch/$s_!dx7o!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0ac083c-9edd-4cb3-914a-03fd201016ee_1020x520.png 1272w, https://substackcdn.com/image/fetch/$s_!dx7o!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0ac083c-9edd-4cb3-914a-03fd201016ee_1020x520.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!dx7o!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0ac083c-9edd-4cb3-914a-03fd201016ee_1020x520.png" width="1020" height="520" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b0ac083c-9edd-4cb3-914a-03fd201016ee_1020x520.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:520,&quot;width&quot;:1020,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Noma Security vendor profile and runtime instrumentation hooks&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Noma Security vendor profile and runtime instrumentation hooks" title="Noma Security vendor profile and runtime instrumentation hooks" srcset="https://substackcdn.com/image/fetch/$s_!dx7o!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0ac083c-9edd-4cb3-914a-03fd201016ee_1020x520.png 424w, https://substackcdn.com/image/fetch/$s_!dx7o!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0ac083c-9edd-4cb3-914a-03fd201016ee_1020x520.png 848w, https://substackcdn.com/image/fetch/$s_!dx7o!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0ac083c-9edd-4cb3-914a-03fd201016ee_1020x520.png 1272w, https://substackcdn.com/image/fetch/$s_!dx7o!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0ac083c-9edd-4cb3-914a-03fd201016ee_1020x520.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Overview:</strong> Noma Security approaches agent security from the premise that effective enforcement cannot rely solely on protocol-layer choke points such as MCP gateways. Its core argument is that a meaningful portion of agent activity occurs outside of MCP altogether, whether through direct API calls, cloud-native service integrations, or increasingly through skills-based execution patterns that do not traverse an MCP control plane. From that perspective, Noma positions runtime instrumentation and hooks-based enforcement as the more durable control layer, particularly for organizations operating across a mix of homegrown agents, SaaS agent platforms, and workforce-facing agent tools.</p><p>A useful aspect of Noma&#8217;s framing is its segmentation of the market into three agent categories: homegrown agents built by internal engineering teams, SaaS agent platforms where business users can create and share agents, and local or workforce-facing agents used directly by employees. This taxonomy is practical because the identity and control problems differ across each category even when the underlying security principles remain consistent. In SaaS agent platforms, for example, Noma places particular emphasis on what it describes as the maker&#8217;s identity problem: an agent created with static access tied to its creator can continue to operate with that creator&#8217;s privileges even when shared more broadly. That makes creator identity, delegated access, and agent ownership central to the governance model.</p><p><strong>Discovery:</strong> Noma&#8217;s discovery and visibility layer is designed to capture not only agents themselves, but also the surrounding context that determines their risk. The platform inventories agents, models, tools, MCP servers, data sources, triggers, users, and agent-to-agent relationships, with an emphasis on showing how these elements connect rather than presenting them as isolated artifacts. It also appears to draw on a broad integration footprint across cloud services, code repositories, notebook environments, SaaS agent platforms, and endpoint telemetry. That contextual approach is important to Noma&#8217;s broader positioning: the company is not simply trying to enumerate agents, but to understand how they are constructed, what they can reach, who can invoke them, and how they interact with other systems.</p><p><strong>Deterministic Governance:</strong> At the <strong>deterministic governance</strong> layer, Noma&#8217;s focus on controlling tools, MCP usage, and skills-based execution paths makes it well positioned for environments where static allow-or-deny rules are too blunt to preserve usability. Noma&#8217;s layered behavioral signals are precisely the kind of data that non-deterministic governance depends on, meaning the platform is well positioned to feed dynamic policy decisions as organizations mature into the third layer of the framework.</p><p>Noma&#8217;s strongest differentiation appears in runtime enforcement. Its model operates across three analytical layers: content, context, and behavior. At the content level, the platform evaluates whether a given action is inherently risky or sensitive. At the context level, it evaluates whether the action is consistent with the agent&#8217;s stated purpose and current session context. At the behavior level, it compares the session against historical patterns to detect drift, anomaly, or combinations of actions that create risk over time. This layered structure is particularly well suited to agent security because many meaningful failures do not arise from a single obviously malicious action, but from an accumulation of individually permissible steps that together produce an unsafe outcome.</p><p>Noma also appears to benefit from strong market momentum and ecosystem validation. Its partnerships with major cloud and platform providers, along with its visibility in large-enterprise deployments, reinforce the view that the company is being treated as a serious platform in the emerging agent-security market rather than as a narrow point solution. Just as importantly, the company&#8217;s broader platform architecture appears designed to let posture, runtime, and context enrich one another over time. That bidirectional contextualization, using posture data to inform runtime decisions and runtime data to improve posture recommendations, gives the platform a coherent structure for scaling as organizations move from early agent experimentation to much larger agent populations and more complex agent-to-agent systems.</p><p><strong>Non-Deterministic Behavioral Analysis:</strong> For <strong>behavioral tracking</strong>, the platform compares each session against historical baselines to detect drift, anomaly, or combinations of actions that individually look permissible but together produce an unsafe outcome. For <strong>continuous observability</strong>, the platform captures session-level context including instructions, tool usage, and behavioral history, giving teams a detailed picture of what an agent is doing and why at any point in time.</p><p><strong>MCP Security:</strong> Another notable aspect of Noma&#8217;s positioning is its critique of MCP gateway-centric architectures. The company&#8217;s argument is not simply that gateways are incomplete, but that they operate too far from the agent&#8217;s actual reasoning context to support high-quality runtime decisions. By contrast, hooks-based enforcement allows the platform to observe more of the session itself, including instructions, tool usage, contextual signals, and behavioral history. That deeper visibility enables more dynamic controls and, in Noma&#8217;s framing, allows organizations to be more permissive where appropriate because enforcement can be based on richer context rather than static policy alone.</p><p><strong>Analyst recommendation:</strong> Overall, Noma&#8217;s strength lies in treating agent security as a runtime control problem that must account for purpose, behavior, and execution context rather than just protocol mediation or static identity assignment. For organizations with meaningful exposure to developer agents, workforce-facing agent tools, or heterogeneous agent environments where not all activity will route through MCP, Noma offers a runtime architecture that appears well matched to how agent behavior is actually evolving.</p><h3><strong>Oasis</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!RpAn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8720f650-b14f-4ca4-b3c5-39df4f93fea6_971x543.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!RpAn!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8720f650-b14f-4ca4-b3c5-39df4f93fea6_971x543.png 424w, https://substackcdn.com/image/fetch/$s_!RpAn!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8720f650-b14f-4ca4-b3c5-39df4f93fea6_971x543.png 848w, https://substackcdn.com/image/fetch/$s_!RpAn!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8720f650-b14f-4ca4-b3c5-39df4f93fea6_971x543.png 1272w, https://substackcdn.com/image/fetch/$s_!RpAn!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8720f650-b14f-4ca4-b3c5-39df4f93fea6_971x543.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!RpAn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8720f650-b14f-4ca4-b3c5-39df4f93fea6_971x543.png" width="971" height="543" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8720f650-b14f-4ca4-b3c5-39df4f93fea6_971x543.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:543,&quot;width&quot;:971,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Oasis Security profile showcasing MCP gateway enforcement&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Oasis Security profile showcasing MCP gateway enforcement" title="Oasis Security profile showcasing MCP gateway enforcement" srcset="https://substackcdn.com/image/fetch/$s_!RpAn!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8720f650-b14f-4ca4-b3c5-39df4f93fea6_971x543.png 424w, https://substackcdn.com/image/fetch/$s_!RpAn!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8720f650-b14f-4ca4-b3c5-39df4f93fea6_971x543.png 848w, https://substackcdn.com/image/fetch/$s_!RpAn!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8720f650-b14f-4ca4-b3c5-39df4f93fea6_971x543.png 1272w, https://substackcdn.com/image/fetch/$s_!RpAn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8720f650-b14f-4ca4-b3c5-39df4f93fea6_971x543.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Overview:</strong> Oasis is built on a specific architectural thesis: MCP is becoming the standard protocol through which agents access enterprise resources, which makes the MCP gateway the optimal enforcement point. Rather than monitoring identity signals at the perimeter, Oasis sits directly in the communication path between agents and the resources they consume. Instead of following the credentials, Oasis intercepts the conversation.</p><p><strong>Deterministic Governance:</strong> The platform analyzes incoming access requests, applies least-privilege policies, and generates temporary identities scoped to each session without relying on standing credentials. Those identities are decommissioned automatically when the session ends. Policies are enforced using OPA, producing auditable decisions rather than probabilistic ones. A hybrid deployment model keeps the customer-side component within the organization&#8217;s own perimeter, addressing data residency requirements without sacrificing centralized policy control.</p><p><strong>Analysis of Non-Deterministic Behavior:</strong> For <strong>behavioral tracking</strong>, the platform tracks sequences of actions across tools and builds a contextual picture of agent activity across a session. For <strong>continuous observability</strong>, full session-level logging of every brokered connection is built into the gateway layer, capturing what the agent accessed, when, and under what context.</p><p><strong>Non-Deterministic Governance:</strong> This is where Oasis introduces one of the more novel concepts in the market: the MCP firewall. Unlike traditional firewalls that make binary allow-or-deny decisions based on static rules, the MCP firewall uses behavioral and intent signals accumulated during the session to make dynamic access decisions. If an agent reads confidential data from Salesforce and then requests access to Gmail, the firewall identifies that sequence as a potential exfiltration risk based on data classification and blocks it, even though each individual action would have been permitted in isolation. This cross-tool, sequence-aware enforcement is something static policy models structurally cannot do, and it represents a meaningful step toward genuinely non-deterministic governance at the MCP layer. For <strong>intent-based authorization</strong>, Oasis performs analysis of agent intent as part of each request evaluation, providing context about why an agent is making a request alongside the access decision. <strong>Control and escalation</strong> through human-in-the-loop approval flows for high-risk actions is on the near-term roadmap.</p><p><strong>MCP Security:</strong> Oasis detects hard-coded secrets in MCP server configurations and identifies supply chain risks within the broader MCP ecosystem, reflecting a complete view of how MCP threats materialize in practice.</p><p><strong>Analyst Recommendation:</strong> Oasis is a strong fit for organizations standardizing on MCP as their agent-to-resource protocol, particularly where cross-tool data exfiltration is a primary concern and where deterministic, auditable policy enforcement is a compliance requirement.</p><h3><strong>Okta</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!R4gU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa67780be-2f9a-4fcf-878a-ad1917105716_992x528.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!R4gU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa67780be-2f9a-4fcf-878a-ad1917105716_992x528.png 424w, https://substackcdn.com/image/fetch/$s_!R4gU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa67780be-2f9a-4fcf-878a-ad1917105716_992x528.png 848w, https://substackcdn.com/image/fetch/$s_!R4gU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa67780be-2f9a-4fcf-878a-ad1917105716_992x528.png 1272w, https://substackcdn.com/image/fetch/$s_!R4gU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa67780be-2f9a-4fcf-878a-ad1917105716_992x528.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!R4gU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa67780be-2f9a-4fcf-878a-ad1917105716_992x528.png" width="992" height="528" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a67780be-2f9a-4fcf-878a-ad1917105716_992x528.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:528,&quot;width&quot;:992,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Okta vendor profile integrating agents into the existing identity fabric&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Okta vendor profile integrating agents into the existing identity fabric" title="Okta vendor profile integrating agents into the existing identity fabric" srcset="https://substackcdn.com/image/fetch/$s_!R4gU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa67780be-2f9a-4fcf-878a-ad1917105716_992x528.png 424w, https://substackcdn.com/image/fetch/$s_!R4gU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa67780be-2f9a-4fcf-878a-ad1917105716_992x528.png 848w, https://substackcdn.com/image/fetch/$s_!R4gU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa67780be-2f9a-4fcf-878a-ad1917105716_992x528.png 1272w, https://substackcdn.com/image/fetch/$s_!R4gU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa67780be-2f9a-4fcf-878a-ad1917105716_992x528.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Overview:</strong> Okta&#8217;s approach to agentic security operates from a fundamentally different starting position than every other vendor in this report: it is already the identity provider. With 19,000 customers managing human and service-based account workloads, Okta is not building a new security layer but extending the existing identity fabric to treat agents as first-class identities alongside human users. The technical centerpiece is the Identity Assertion Grant (ID-JAG), an open standard Okta co-developed with other identity providers for agentic workflows, ensuring an agent&#8217;s permissions are always bound by the specific user&#8217;s existing access rights.</p><p><strong>Discovery:</strong> A dashboard accessible through Okta Identity Security Posture Management (ISPM), now generally available, ensures discoverability across all AI agent platforms. The Secure Access Monitor (SAM) plugin, currently in Early Access, monitors the user&#8217;s browser for new OAuth grants, capturing Claude Code and all calls to MCP servers that require an OAuth grant. Additionally, Okta will soon have the ability to intercept and secure traffic from MCP clients like Claude Code and Cursor, providing end-to-end coverage.</p><p><strong>Deterministic Governance:</strong> Authorization operates at three tiers. User context constrains the agent to the permissions of the human operator. Coarse-grained scopes define what categories of actions the agent can perform. Fine-grained authorization through fga.dev enables policy-level control over individual resources and operations. The certification campaign capability enables proactive review of agent access rights, applying the same governance rigor to agents that organizations already apply to human entitlements.</p><p><strong>Non-Deterministic Behavioral Analysis:</strong> Full audit trails capture every agent authorization event with actor ID, user context, and authorization outcomes, giving security teams a complete record of what every agent accessed and under what permissions. ISPM provides continuous posture visibility across agent populations.</p><p><strong>Non-Deterministic Governance:</strong> CIBA-based human-in-the-loop workflows programmatically trigger approval via app or email before specific tool calls execute, and global token revocation provides a hard stop on risky or compromised agent behavior. A roadmap item extends this further with the ability to hard-stop individual agents based on policy triggers, adding more granular termination capability.</p><p><strong>MCP Security:</strong> Through SAM and the upcoming traffic interception capability, Okta is extending its coverage to MCP clients and servers that require OAuth grants. The ID-JAG model ensures that when agents interact with MCP servers across domains, cross-domain trust is established between the Okta IDP and the authorization server, with scoped access tokens issued for each agent&#8217;s API calls.</p><p><strong>Analyst Recommendation:</strong> Okta&#8217;s strongest differentiation is consolidation. For organizations already running Okta as their identity provider, agentic identity management becomes an extension of existing infrastructure rather than a new point product. The three-tier authorization model and ID-JAG open standard offer one of the most architecturally rigorous approaches to delegated agent permissions discussed in these briefings. The single control plane vision eliminates tool sprawl across identity types, and the combination of ISPM, SAM, and upcoming MCP traffic interception positions Okta to cover the full spectrum from enterprise API-accessing agents through to developer-workstation MCP clients.</p><h3><strong>Runlayer</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!b4GQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee53628c-ffbb-43a3-9f8d-4bcc14e3e03e_1600x1138.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!b4GQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee53628c-ffbb-43a3-9f8d-4bcc14e3e03e_1600x1138.png 424w, https://substackcdn.com/image/fetch/$s_!b4GQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee53628c-ffbb-43a3-9f8d-4bcc14e3e03e_1600x1138.png 848w, https://substackcdn.com/image/fetch/$s_!b4GQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee53628c-ffbb-43a3-9f8d-4bcc14e3e03e_1600x1138.png 1272w, https://substackcdn.com/image/fetch/$s_!b4GQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee53628c-ffbb-43a3-9f8d-4bcc14e3e03e_1600x1138.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!b4GQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee53628c-ffbb-43a3-9f8d-4bcc14e3e03e_1600x1138.png" width="1456" height="1036" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ee53628c-ffbb-43a3-9f8d-4bcc14e3e03e_1600x1138.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1036,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Runlayer vendor profile showing its control plane for AI agent infrastructure&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Runlayer vendor profile showing its control plane for AI agent infrastructure" title="Runlayer vendor profile showing its control plane for AI agent infrastructure" srcset="https://substackcdn.com/image/fetch/$s_!b4GQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee53628c-ffbb-43a3-9f8d-4bcc14e3e03e_1600x1138.png 424w, https://substackcdn.com/image/fetch/$s_!b4GQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee53628c-ffbb-43a3-9f8d-4bcc14e3e03e_1600x1138.png 848w, https://substackcdn.com/image/fetch/$s_!b4GQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee53628c-ffbb-43a3-9f8d-4bcc14e3e03e_1600x1138.png 1272w, https://substackcdn.com/image/fetch/$s_!b4GQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee53628c-ffbb-43a3-9f8d-4bcc14e3e03e_1600x1138.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Overview: </strong>Runlayer positions itself as the control plane for AI agent infrastructure, providing runtime security, governance, and observability across every AI integration in the enterprise. The platform connects 300+ AI clients (Claude, Cursor, ChatGPT, VS Code, OpenAI Codex) to 18,000+ enterprise tools, with every connection secured by a three-layer security architecture: static and dynamic scanning at the perimeter, AI-powered runtime threat detection at inference time, and deterministic policy enforcement for access control. Runlayer is backed by Khosla Ventures and Felicis, with David Soria Parra, co-creator of MCP at Anthropic, as a close technical advisor.</p><p><strong>Discovery: </strong>Runlayer Watch provides shadow AI discovery across devices, detecting unauthorized MCP servers, OpenClaw installs, Skills, and agents. It operates in two modes: Detect mode runs scheduled scans to discover and inventory shadow AI across Cursor, VS Code, Claude Desktop, Claude Code, Windsurf, Goose, Zed, and OpenCode, classifying each server as managed or shadow. Enforce mode intercepts tool calls from shadow MCPs in real-time and applies security policies before execution. Deployment is supported via MDM (Jamf, Intune, CrowdStrike, Carbon Black, SentinelOne).</p><p><strong>Deterministic Governance: </strong>The policy engine supports RBAC, ABAC, and PBAC, with policies evaluated at the organization, server, tool, and resource level. Policies are evaluated in strict order: Global Deny, server-level, user/group/role, Agent Account, with the result always being the least-privilege intersection. Tools are labeled as internal or external to prevent data exfiltration, and ABAC conditions can be set on any attribute of the MCP server, client, user session, or payload.</p><p><strong>Non-Deterministic Behavioral Analysis: </strong>ToolGuard is a set of proprietary, non-LLM security models purpose-built for AI integration attack vectors, running at 50&#8211;100ms inference latency. It covers tool poisoning, prompt injection, data exfiltration, command injection, and encoded payloads. A patent-pending semantic alignment analysis detects when AI agent tool calls misalign with user intent, catching data aggregation risks and exfiltration patterns that keyword filters miss.</p><p><strong>Non-Deterministic Governance: </strong>Violation handling follows a four-step process: block, log, alert, and escalate, with configurable actions including block_self_approve (deny unless user self-approves). The security dashboard provides real-time visibility into security events, policy denials, and violations with full input/output context.</p><p><strong>MCP Security: </strong>Runlayer&#8217;s gateway proxies all MCP traffic, applying static scanning at tool registration and dynamic scanning at every tool invocation. Token masking detects and masks sensitive credentials (GitHub tokens, API keys, AWS credentials, SSH keys) flowing through the platform. PII detection provides regex-based blocking with configurable confidence thresholds. OBO token exchange via OAuth 2.1 ensures agents authenticate with delegated credentials whose permissions never exceed either party&#8217;s policies.</p><p><strong>Analyst Recommendation: </strong>Runlayer&#8217;s strongest differentiation is the depth of its MCP-native security architecture. The three-layer model: pattern-based scanning, ML-powered threat detection via ToolGuard, and fine-grained policy enforcement provides one of the most comprehensive inline protection stacks discussed in these briefings. Shadow AI discovery through Runlayer Watch, with MDM-based deployment and both detect and enforce modes, gives it especially strong coverage of the developer-endpoint surface area. For organizations where MCP adoption is accelerating across developer tools and enterprise integrations, Runlayer offers a purpose-built control plane that combines runtime threat detection, granular access governance, and broad client compatibility in a single platform.</p><h3><strong>Silverfort</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!AjhG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffbd60b6-5f8f-413e-a3cb-614d39949f47_1067x577.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!AjhG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffbd60b6-5f8f-413e-a3cb-614d39949f47_1067x577.png 424w, https://substackcdn.com/image/fetch/$s_!AjhG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffbd60b6-5f8f-413e-a3cb-614d39949f47_1067x577.png 848w, https://substackcdn.com/image/fetch/$s_!AjhG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffbd60b6-5f8f-413e-a3cb-614d39949f47_1067x577.png 1272w, https://substackcdn.com/image/fetch/$s_!AjhG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffbd60b6-5f8f-413e-a3cb-614d39949f47_1067x577.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!AjhG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffbd60b6-5f8f-413e-a3cb-614d39949f47_1067x577.png" width="1067" height="577" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ffbd60b6-5f8f-413e-a3cb-614d39949f47_1067x577.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:577,&quot;width&quot;:1067,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:321279,&quot;alt&quot;:&quot;Silverfort profile focusing on unified identity graph and centralized policy&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Silverfort profile focusing on unified identity graph and centralized policy" title="Silverfort profile focusing on unified identity graph and centralized policy" srcset="https://substackcdn.com/image/fetch/$s_!AjhG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffbd60b6-5f8f-413e-a3cb-614d39949f47_1067x577.png 424w, https://substackcdn.com/image/fetch/$s_!AjhG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffbd60b6-5f8f-413e-a3cb-614d39949f47_1067x577.png 848w, https://substackcdn.com/image/fetch/$s_!AjhG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffbd60b6-5f8f-413e-a3cb-614d39949f47_1067x577.png 1272w, https://substackcdn.com/image/fetch/$s_!AjhG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffbd60b6-5f8f-413e-a3cb-614d39949f47_1067x577.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Overview:</strong> Silverfort places agents inside a broader identity-security platform that already spans human identities, privileged users, non-human identities, and machine identities. This gives the platform a unified graph of relationships across users, agents, credentials, permissions, and target systems. The company&#8217;s core architectural principle is that policy decisioning and policy enforcement should remain separable; authorization logic is centralized and informed by identity, context, posture, and risk, while enforcement occurs through multiple downstream mechanisms depending on where the agent operates.</p><p><strong>Discovery:</strong> Silverfort is positioned both in cloud identity environments and, importantly, on-premises identity infrastructure such as Active Directory and domain controllers. This hybrid visibility gives it a vantage point into authentication traffic and authorization patterns that many cloud-first vendors do not naturally see. A particularly important part of this model is tracing the full authorization chain behind an agent action: identifying the human associated with the agent, the non-human identities connected to it, and the downstream resources those identities can reach.</p><p><strong>Deterministic Governance:</strong> Silverfort&#8217;s Runtime Access Protection (RAP) provides a real-time policy decision when an identity system is about to grant access, returning an allow, block, or step-up action such as MFA. The platform maps agents to the humans from whom they derive access and applies enforcement in the channel most appropriate to the runtime environment, whether through an MCP gateway, a native agentic platform integration, or a traditional identity control point.</p><p><strong>Non-Deterministic Behavioral Analysis:</strong> Silverfort&#8217;s unified identity graph and storyline-style tracing capabilities provide a foundation for reconstructing how an agent action occurred and which user, permissions, and systems were involved. That identity context becomes the basis for both visibility and runtime decisioning.</p><p><strong>Non-Deterministic Governance:</strong> The centralized policy engine enables real-time allow, block, and step-up decisions informed by identity, context, posture, and risk, applying dynamic enforcement actions in direct response to evolving conditions rather than relying solely on static rules.</p><p><strong>MCP Security:</strong> Silverfort frames MCP as important but only one enforcement methodology among several. The company described native integration work with a major agentic platform, reinforcing its view that enterprises will operate across multiple runtimes. A unified policy layer above those platforms allows organizations to apply consistent identity-based controls without redesigning governance for every new runtime or standard.</p><p><strong>Analyst Recommendation:</strong> Silverfort&#8217;s strongest value appears in environments where organizations want one policy and control layer spanning users, non-human identities, agents, SaaS, cloud, and on-premises infrastructure. Its separable policy-decisioning and enforcement architecture enables runtime access protection without requiring changes to existing identity providers or applications, a significant advantage for enterprises with complex hybrid estates. Identity-chain tracing delivers clear lineage from human to service account to agent action, making Silverfort particularly well-suited for regulated industries where auditability across the full identity stack is a compliance requirement.</p><h3><strong>Token</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0lLa!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda48d4ce-812a-4629-8025-8ca4fa57eef1_1448x812.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0lLa!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda48d4ce-812a-4629-8025-8ca4fa57eef1_1448x812.png 424w, https://substackcdn.com/image/fetch/$s_!0lLa!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda48d4ce-812a-4629-8025-8ca4fa57eef1_1448x812.png 848w, https://substackcdn.com/image/fetch/$s_!0lLa!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda48d4ce-812a-4629-8025-8ca4fa57eef1_1448x812.png 1272w, https://substackcdn.com/image/fetch/$s_!0lLa!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda48d4ce-812a-4629-8025-8ca4fa57eef1_1448x812.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0lLa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda48d4ce-812a-4629-8025-8ca4fa57eef1_1448x812.png" width="1448" height="812" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/da48d4ce-812a-4629-8025-8ca4fa57eef1_1448x812.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:812,&quot;width&quot;:1448,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Token Security vendor profile with broad integration catalogs&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Token Security vendor profile with broad integration catalogs" title="Token Security vendor profile with broad integration catalogs" srcset="https://substackcdn.com/image/fetch/$s_!0lLa!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda48d4ce-812a-4629-8025-8ca4fa57eef1_1448x812.png 424w, https://substackcdn.com/image/fetch/$s_!0lLa!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda48d4ce-812a-4629-8025-8ca4fa57eef1_1448x812.png 848w, https://substackcdn.com/image/fetch/$s_!0lLa!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda48d4ce-812a-4629-8025-8ca4fa57eef1_1448x812.png 1272w, https://substackcdn.com/image/fetch/$s_!0lLa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda48d4ce-812a-4629-8025-8ca4fa57eef1_1448x812.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Ftm5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e940da3-582c-4090-965d-22dea9074a58_1600x879.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Ftm5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e940da3-582c-4090-965d-22dea9074a58_1600x879.png 424w, https://substackcdn.com/image/fetch/$s_!Ftm5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e940da3-582c-4090-965d-22dea9074a58_1600x879.png 848w, https://substackcdn.com/image/fetch/$s_!Ftm5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e940da3-582c-4090-965d-22dea9074a58_1600x879.png 1272w, https://substackcdn.com/image/fetch/$s_!Ftm5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e940da3-582c-4090-965d-22dea9074a58_1600x879.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Ftm5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e940da3-582c-4090-965d-22dea9074a58_1600x879.png" width="1456" height="800" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7e940da3-582c-4090-965d-22dea9074a58_1600x879.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:800,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Token Security context graph diagram for agent intent analysis&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Token Security context graph diagram for agent intent analysis" title="Token Security context graph diagram for agent intent analysis" srcset="https://substackcdn.com/image/fetch/$s_!Ftm5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e940da3-582c-4090-965d-22dea9074a58_1600x879.png 424w, https://substackcdn.com/image/fetch/$s_!Ftm5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e940da3-582c-4090-965d-22dea9074a58_1600x879.png 848w, https://substackcdn.com/image/fetch/$s_!Ftm5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e940da3-582c-4090-965d-22dea9074a58_1600x879.png 1272w, https://substackcdn.com/image/fetch/$s_!Ftm5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e940da3-582c-4090-965d-22dea9074a58_1600x879.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Overview:</strong> Token Security started from non-human identity three years ago and has built toward a broader thesis: the real risk emerges when agents are given access to enterprise systems, not simply when a model generates unsafe text. An agent without access is still largely a chatbot; an agent with access becomes a meaningful security subject. The platform follows a discover, understand, enforce progression, with particular emphasis on breadth of coverage across the environments agents actually operate in.</p><p><strong>Discovery:</strong> Token&#8217;s most distinctive capability at the discovery layer is the breadth of its integration catalog, spanning identity providers, databases, SaaS platforms, secrets managers, and cloud services. The argument is straightforward: coverage is foundational to whether a platform can actually secure the environments customers use. Every discovered agent is attached to its owner user, and a connection graph maps the relationships between agents, identities, and the resources they can reach.</p><p><strong>Deterministic Governance:</strong> Policies are enforced through automations tied to identity events rather than manual escalation workflows. Token&#8217;s orientation is proactive: organizations define the right state for agents before problems occur, with compound policy conditions tied to department, role, agent type, and ownership triggering enforcement actions automatically across identity systems and endpoints.</p><p><strong>Analysis of Non-Deterministic Behavior:</strong> For behavioral tracking, Token builds a context graph for each agent that correlates system prompts, tool sets, connected identities, and permissions to determine the agent&#8217;s intended purpose. This intent analysis is used to surface whether the access an agent holds makes sense given what it was created to do: a deal-preparation agent may reasonably need Salesforce access, but that does not imply it should be able to delete rows or take administrative actions. For continuous observability, the platform provides detailed auditing of agent activity including what queries were run, what systems were accessed, and what actions were taken, tied back to the agent&#8217;s owner and its declared purpose.</p><p><strong>MCP Security:</strong> Token takes a more skeptical position on MCP than most vendors in this report. The company believes MCP is being gradually replaced by CLI tools and serialized agentic access patterns, and does not currently prioritize MCP-specific controls as a result.</p><p><strong>Analyst Recommendation:</strong> Token is a strong fit for organizations that want broad integration coverage across heterogeneous environments and intent-aware visibility into what agents are doing relative to their declared purpose. The roadmap includes a real-time endpoint response solution that will move the platform toward dynamic intent-based decisions, and an extensible reporting layer that lets customers generate tailored dashboards and governance views directly on the platform.</p><h2><strong>Summary and Conclusions</strong></h2><p><strong>Agentic identity is emerging as one of the defining security problems of the next enterprise software cycle.</strong>Traditional identity and access management systems were designed for two primary actors: humans and deterministic machine identities. AI agents fit neither model cleanly. They are non-human actors, but unlike traditional service accounts, they are dynamic, non-deterministic, increasingly autonomous, and capable of interacting with a broad and changing set of tools, systems, and data sources at runtime. As a result, organizations cannot secure agents simply by extending existing IAM, PAM, or IGA controls without adaptation.</p><p><strong>This paper argues that effective agent security must be understood as a runtime problem</strong>. What matters is not only which permissions an agent holds statically, but how it reasons, which tools it invokes, what context it accesses, how its behavior changes over time, and whether security teams can interrupt or audit its actions when something goes wrong. That is why the paper organizes the market around five runtime dimensions: Intent-Based Authorization, Tool &amp; Skill Guardrails, Behavioral Tracking, Control &amp; Escalation, and Continuous Observability. Together, these dimensions provide a practical framework for evaluating whether a vendor is truly securing agent behavior in motion rather than simply cataloging agents after the fact.</p><p><strong>One of the clearest insights from the market is that no vendor today owns the full stack equally well.</strong> Some vendors are strongest at identity-layer governance, approval workflows, and entitlement management. Others are strongest at runtime enforcement, tool mediation, or behavioral anomaly detection. Still others bring differentiated visibility across endpoint, browser, SaaS, and cloud environments. This fragmentation is not a weakness of the framework; it reflects the reality that agent security is still early, and that the underlying attack surface is broader than any one product category. For CISOs, the practical implication is that agent security strategy will likely require architectural layering rather than dependence on a single control.</p><p><strong>A second major conclusion is that MCP security is not a niche protocol issue.</strong> It is increasingly central to agent runtime security itself. MCP matters because it is becoming one of the primary ways agents access external context, tools, and downstream systems during execution. That makes MCP not just an integration standard, but a live control surface for agent behavior. The paper&#8217;s MCP case study shows that the ecosystem is currently immature: plaintext credentials are common, OAuth adoption remains limited, tool poisoning attacks are highly effective, and many organizations lack even basic inventory of which MCP servers and tools are in use. As a result, MCP security must be approached across multiple layers: inventory and governance, supply chain validation, communication security, authorization, and credential management. Organizations that ignore MCP security will leave a large part of their runtime attack surface effectively unmanaged.</p><p><strong>A third conclusion is that governance at scale will become the central operational challenge of the agentic enterprise.</strong> Today, many organizations are still asking first-order visibility questions: how many agents do we have, who owns them, and what can they access? But as deployments mature, those questions will quickly evolve into scaling questions: how should agents be classified, how should privileges be templated, how should approvals be automated, how should orphaned agents be handled, and how can policies be applied consistently across thousands or millions of agents? The vendors most likely to endure will be those that can connect runtime enforcement with scalable governance primitives rather than treating every agent as a bespoke exception.</p><p><strong>Finally, we suggest that there is a new security design principle: agents must be treated as first-class identities, but secured as runtime actors</strong>. Identity is necessary, but not sufficient. Registry, sponsorship, access graphs, and directory integration all matter. But so do intent evaluation, dynamic authorization, behavioral controls, kill switches, and auditability. Security leaders will need both layers. The winning architectures will be those that can tie accountability and governance at the identity layer to context-aware decisioning and control at the runtime layer.</p><p>The transition to the agentic enterprise is already underway. In many organizations, it is happening faster than the control plane required to secure it. The core challenge for the next several years will not be whether enterprises adopt agents, but whether they can do so with enough visibility, governance, and runtime control to preserve trust in the systems those agents touch. That is the central problem of agentic identity, and increasingly, one of the central security problems of the AI era.</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Software Analyst Cyber Research! Subscribe for free to receive new in-depth research reports and analysis on the future of cybersecurity.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/p/runtime-security-for-ai-agents-an?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading Software Analyst Cyber Research! This post is public, so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/p/runtime-security-for-ai-agents-an?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/p/runtime-security-for-ai-agents-an?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/p/runtime-security-for-ai-agents-an/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/p/runtime-security-for-ai-agents-an/comments"><span>Leave a comment</span></a></p><div class="directMessage button" data-attrs="{&quot;userId&quot;:6770950,&quot;userName&quot;:&quot;SACR&quot;,&quot;canDm&quot;:null,&quot;dmUpgradeOptions&quot;:null,&quot;isEditorNode&quot;:true}" data-component-name="DirectMessageToDOM"></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://softwareanalyst.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://softwareanalyst.substack.com/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item></channel></rss>