Topics
Customer Identity and Access Management Data and Information Protection Fraud Prevention Identity Governance and Administration Identity Threat Detection and Response Non-Human Identity Zero Trust
Research
Leadership Compass Buyer's Compass Advisory Note Whitepaper Executive View Leadership Brief Rising Star Product Value Navigator Blog
Advisory
Advisory Services Meet our Advisors Strategy Navigator Success Stories
Events
IF Impact Day 2026 AI & NHI Impact Day 2026 CIAM Impact Day 2026 EIC 2027 EIC 2026 Upcoming Events Upcoming Webinars
Videos
All latest videos European Identity and Cloud Conference 2025 cyberevolution 2024 KuppingerCole Webinars KuppingerCole Analyst Chat
Membership
About Professional Expert Corporate
Company
About us Success Stories People Jobs Newsroom Cybersecurity Council Technology Providers Contact us
Customer Identity and Access Management
Data and Information Protection
Fraud Prevention
Identity Governance and Administration
Identity Threat Detection and Response
Non-Human Identity
Zero Trust
See All Topics
Research
[See all research\ \
\ \ May 19, 2026\ \ Identity Governance and Administration (IGA)\ \ \ This Leadership Compass Identity Governance and Administration (IGA) provides an overview of the IGA market and a compass to help you find a solution that best meets your needs. It examines solutions that provide both identity lifecycle management and access governance capabilities. Solutions have](/content/research/lc80864/identity-governance-and-administration-iga/index.html)
\ \ May 18, 2026\ \ Privileged Access Management (PAM)\ \ \ This KuppingerCole Leadership Compass provides an overview of the leading vendors in the Privileged Access Management (PAM) market, assessing their innovation, product capabilities, and market presence. PAM solutions enable organizations to control, manage, and monitor privileged access across](/content/research/lc81007/privileged-access-management-pam/index.html)
\ \ Apr 29, 2026\ \ Managed Detection and Response\ \ \ This KuppingerCole Analysts Leadership Compass provides an overview of the Managed Detection and Response (MDR) market in 2026. It examines services that detect, analyze, investigate, and respond to cyber threats across diverse environments, and evaluates the ability of vendors to deliver](/content/research/lc80871/managed-detection-and-response/index.html)
\ \ May 19, 2026\ \ Identity Governance and Administration (IGA)\ \ \ Modern access governance is strained by identity sprawl (including non-human identities), complex joiner/mover/leaver lifecycles, manual reviews at scale, and integration gaps that create blind spots. IGA platforms centralize identity/entitlement inventories, automate provisioning and](/content/research/bc81004/identity-governance-and-administration-iga/index.html)
\ \ May 18, 2026\ \ Privileged Access Management (PAM)\ \ \ Privileged access has expanded from admin accounts to high-impact actions across human, machine, application, and automated identities in dynamic hybrid/cloud environments. Key problems include action-based privilege definition, fragmented visibility, non-human identity risk, privilege sprawl, and](/content/research/bc81009/privileged-access-management-pam/index.html)
\ \ May 11, 2026\ \ Managed Detection and Response\ \ \ Escalating threats, alert overload, fragmented tooling, and scarce SOC skills drive slow detection and response. Managed Detection and Response (MDR) provides 24/7 monitoring, telemetry correlation, validated detection, and analyst-led investigation/response, augmented by automation and AI. Modern](/content/research/bc81061/managed-detection-and-response/index.html)
\ \ May 15, 2026\ \ Navigating the Agentic AI Security Landscape\ \ \ Enterprise AI deployments have passed a threshold that most security frameworks were not designed for. Agentic AI (autonomous, tool-using systems that chain actions, delegate to sub-agents, and operate continuously on behalf of users) is already in production across a growing number of](/content/research/an82020/navigating-the-agentic-ai-security-landscape/index.html)
\ \ Apr 22, 2026\ \ KuppingerCole 2nd Level Reference Architecture for CIAM\ \ \ The purpose of this document is to define the KuppingerCole Analysts 2nd Level Reference Architecture for CIAM, providing a structured and consistent model for designing, evaluating, and evolving Customer Identity and Access Management (CIAM) solutions.\ It focuses exclusively on capabilities](/content/research/an81080/kuppingercole-2nd-level-reference-architecture-for-ciam/index.html)
\ \ Mar 23, 2026\ \ Make or Buy: Bringing Structure and Transparency to Strategic Decisions\ \ \ Make or buy decisions are a recurring challenge in Identity and Access Management (IAM) and beyond. While the question appears straightforward, the underlying decision is rarely simple. Organizations must balance multiple, often conflicting dimensions such as cost, functionality, technical](/content/research/an82018/make-or-buy/index.html)
\ \ Jun 01, 2026\ \ Application Inventory - Identify What to Protect. Are You Missing Critical Assets?\ \ \ This whitepaper examines Application Inventory Management (AIM) as a critical, yet often underestimated, enabler for Identity and Access Management (IAM). It shows how incomplete or poorly maintained application inventories undermine IAM initiatives by increasing manual effort, fragmentation, and](/content/research/wp81148/application-inventory-identify-what-to-protect-are/index.html)
\ \ May 13, 2026\ \ Governing Third-Party Privileged Access: Moving Beyond VPN-Based Collaboration\ \ \ Organizations rely on third parties that require remote access to internal systems and operational platforms. Managing this privileged third-party access creates operational and security challenges, particularly when external identities fall outside established governance processes. Many](/content/research/wp81146/governing-third-party-privileged-access/index.html)
\ \ Apr 22, 2026\ \ Access Fabric: Uniting Access Control across Endpoints, Networks and Identity\ \ \ Access Fabric presents a transformative approach in enhancing enterprise security frameworks by integrating identity, network, device, and business signals into a unified, context-aware system. It describes how this new model resolves the limitations of traditional, siloed security practices,](/content/research/wp81140/access-fabric/index.html)
\ \ May 11, 2026\ \ Tuebora\ \ \ Modern IGA struggles with manual governance, siloed identity data, and rising non-human identities (bots, service accounts, AI agents). Tuebora’s roadmap targets lower IGA TCO via dual AI vs deterministic operation, natural-language configuration in Tuebora Studio, a Neo4j-based Unified Identity](/content/research/ev81301/tuebora/index.html)
\ \ Mar 20, 2026\ \ NEXIS Platform - IVIP Capabilities\ \ \ Identity Visibility and Intelligence Platforms (IVIP) unify data from IGA, PAM, AM, and ITDR to resolve fragmented access visibility and enable analytics-driven governance. The NEXIS Platform delivers IVIP plus converged IAM/GRC: role management/mining, cross-application SoD, identity graphs,](/content/research/ev81145/nexis-platform-ivip-capabilities/index.html)
\ \ Jan 18, 2026\ \ Memority\ \ \ Identity Fabrics unify disparate IAM solutions, enabling secure, scalable identity management across complex environments. Leveraging microservices, API-centric design, and Zero Trust principles, these fabrics offer seamless integration and advanced analytics. Memority’s 360° Identity Factory,](/content/research/ev81445/memority/index.html)
\ \ May 28, 2026\ \ No API Security, No AI Security\ \ \ Every AI system acts through APIs: retrieving context, invoking tools, and chaining decisions across enterprise infrastructure. Yet most organizations govern API security, generative AI defense, and non-human identity management as separate disciplines, leaving the gaps unprotected. This Leadership](/content/research/lb80920/no-api-security-no-ai-security/index.html)
\ \ May 15, 2026\ \ Crypto-Agility: Managing Cryptographic Change in the Post-Quantum Era\ \ \ Crypto-agility has become an urgent enterprise requirement as post-quantum cryptography, expanding machine identity ecosystems, and growing regulatory expectations expose the risks of treating cryptographic infrastructure as static. This Leadership Brief examines why organizations struggle to](/content/research/lb80919/crypto-agility/index.html)
\ \ May 11, 2026\ \ Model Context Protocol: The API Security Problem Nobody Is Ready For\ \ \ The Model Context Protocol (MCP) has rapidly become the connective tissue of the agentic AI ecosystem, and it is being deployed at enterprise scale without a mature authentication baseline or reliable runtime enforcement. Security has not kept pace with adoption. This Leadership Brief examines MCP](/content/research/lb80918/model-context-protocol/index.html)
\ \ May 15, 2026\ \ Rising Star TechJutsu\ \ \ Contact Center Authentication strengthens voice and agent-assisted channels by replacing vulnerable knowledge-based questions with IdP-backed MFA. TechJutsu’s CallerVerify triggers verification from ITSM, collaboration, and IVR tools using Okta/Auth0 or Microsoft Entra factors. OrgVerify adds](/content/research/rs81153/rising-star-techjutsu/index.html)
\ \ May 11, 2026\ \ Rising Star Bare.ID\ \ \ Bare.ID is a self-funded Wiesbaden IAM vendor (founded 2022) focused on EMEA mid-market needs within Identity Fabrics. Its subscription offering extends Keycloak into a comprehensive package combining Access Management, IGA, and PAM, with strong UI/UX, open-standard APIs, self-service automation,](/content/research/rs81152/rising-star-bare-id/index.html)
\ \ Nov 18, 2025\ \ Rising Star AuthZed\ \ \ AuthZed provides scalable authorization solutions leveraging SpiceDB for global, fine-grained permissions. Supported by $15.8M funding, their cloud products optimize performance and deployment flexibility. With innovative Materialize technology, AuthZed enhances rapid permission checks. Despite](/content/research/rs81131/rising-star-authzed/index.html)
\ \ Mar 18, 2026\ \ ManageEngine PAM360\ \ \ Privileged Access Management (PAM) is a priority in hybrid environments where ransomware risk, misconfigurations, and audit expectations are rising. Buyers need rapid, practical governance that fits existing identity and monitoring ecosystems, but must still verify modernization, extensibility, and](/content/research/pv81149/manageengine-pam360/index.html)
\ \ Jun 03, 2026\ \ From the Floor, Not the Stage: An Advisory View on EIC 2026\ \ \ AI was the headline at EIC 2026, but the real story was the gap between hype and the unfinished plumbing of identity. In hallway conversations and unfiltered case studies, the same theme kept surfacing: teams can’t govern agents they can’t yet govern users, apps, and access. Here’s what surfaced](/content/blog/schuetze/advisory-view-on-eic-2026/index.html)
\ \ Jun 02, 2026\ \ Your AI Agent Has a Supply Chain Problem\ \ \ Learn how MCP can quietly turn agentic AI into a Log4Shell-like dependency blind spot, and how to get ahead of it. You’ll leave with a practical checklist to inventory MCP endpoints, harden provenance and review of manifests/configs, avoid “valid token = safe code” thinking, and add runtime](/content/blog/balaganski/your-ai-agent-has-a-supply-chain-problem/index.html)
\ \ Jun 01, 2026\ \ Securing and Governing AI: Why AI Security Requires a Fabric, not a Category\ \ \ AI isn’t “just another app,” and your security stack can’t pretend it is. Prompts can be poisoned, retrieval can be manipulated, and agents can take actions across systems faster than reviews can keep up. The answer isn’t a new category, it’s a connected fabric of identity, data, policy, runtime](/content/blog/gardiner/securing-and-governing-ai/index.html)
Events
[See past events\ \
Identity Fabric Impact Day 2026
Identity Fabric Impact Day is a focused, one-day, practice-oriented event for IAM professionals, security leaders, and solution providers seeking hands-on guidance on Identity Fabrics - modular, flexible, and scalable architectures that address identity and access needs across the enterprise. Identity Fabrics enable secure, seamless access for employees, customers, partners, and machines, while improving efficiency, supporting compliance, and strengthening security across hybrid and multi-cloud environments.
To the\ Event [Call for Speakers\ \
AIdentity & Non-Human Identity Impact Day 2026
Join the leading event dedicated to securing and governing non-human identities at scale and learn about AIdentity. Explore how dynamic credentials, automated governance, and Identity Fabric architectures transform how organizations secure workloads, APIs, and services across multi-cloud environments. Connect with experts shaping the future of identity automation, where governance meets agility, and ownership is non-negotiable.
To the\ Event [Call for Speakers\ \
Customer Identity & Access Management (CIAM) Impact Day 2026
This event is dedicated to transforming Customer Identity & Access Management (CIAM) into the next era of digital engagement. Explore how EUDI Wallets, verifiable credentials, decentralized identity, and passwordless authentication reshape customer experiences, trust, and digital safety. Connect with identity innovators, security leaders, and business strategists defining how organizations authenticate, protect, and understand their customers in a global, omnichannel world.
To the\ Event [Call for Speakers\ \
European Identity and Cloud Conference 2027
Join Europe’s leading event on Digital Identity, Security, Privacy, and Governance in an AI-driven world. Connect with a vibrant community and dive into the technologies shaping the future.
To the\ Event [Call for Speakers\ \
European Identity and Cloud Conference 2026
To the\ Event [Agenda Overview\ \
\ \ Sep 09, 2026\ \ Identity Fabric Impact Day 2026\ \ \ Identity Fabric Impact Day is a focused, one-day, practice-oriented event for IAM professionals, security leaders, and solution providers seeking hands-on guidance on Identity Fabrics - modular, flexible, and scalable architectures that address identity and access needs across the enterprise.](/content/events/ifid2026/index.html)
\ \ Oct 06, 2026\ \ AIdentity & Non-Human Identity Impact Day 2026\ \ \ Join the leading event dedicated to securing and governing non-human identities at scale and learn about AIdentity.\ Explore how dynamic credentials, automated governance, and Identity Fabric architectures transform how organizations secure workloads, APIs, and services across multi-cloud](/content/events/nhiid2026/index.html)
\ \ Nov 18, 2026\ \ Customer Identity & Access Management (CIAM) Impact Day 2026\ \ \ This event is dedicated to transforming Customer Identity & Access Management (CIAM) into the next era of digital engagement.\ Explore how EUDI Wallets, verifiable credentials, decentralized identity, and passwordless authentication reshape customer experiences, trust, and digital safety. Connect](/content/events/ciamid2026/index.html)
\ \ Jun 16, 2026\ \ Navigating B2B IAM: Leadership Compass Results Revealed\ \ \ As B2B ecosystems grow more complex, managing identities across organizational boundaries has become a strategic priority. In this webinar, KuppingerCole unveils the first results from its Leadership Compass on B2B Identity and Access Management, offering a preview of the Leader chart, key market](/content/events/2026/06/navigating-b2b-iam/index.html)
\ \ Jun 17, 2026\ \ Rethinking Privileged Access\ \ \ Historically, privileged access was associated primarily with human administrators responsible for maintaining servers, networks, and enterprise applications. That model no longer reflects how organizations operate today. This webinar draws on a Leadership Compass covering over 35 vendors to](/content/events/2026/06/rethinking-pam/index.html)
\ \ Jun 24, 2026\ \ Redefining MDR: From Alert Handling to Outcome‑Focused Security Operations\ \ \ Cyber threats continue to target organizations across endpoints, networks, cloud environments, identity systems, and connected devices, while many security teams still struggle with skills shortages, operational complexity, and the challenge of maintaining effective 24x7 monitoring and response. In](/content/events/2026/06/redefining-mdr/index.html)
Videos
European Identity and Cloud Conference 2025
[See all videos\ \
\ \ Jun 15, 2026\ \ B2B Identity & Access Management: A New Market Unpacked\ \ \ Business relationships are complex and traditional IAM wasn't built for them. In this episode, Matthias Reinwarth sits down with Principal analyst John Tolbert, author of KuppingerCole Analysts' first-ever B2B IAM Leadership Compass, to explore why Business-to-Business Identity and Access](/content/watch/b2b-iam-new-market-unpacked/index.html)
\ \ Jun 12, 2026\ \ Is Your CDN Secure? CDN vs. DDoS Mitigation Unpacked with Qrator Labs\ \ \ Speed and security are no longer separate concerns. In this videocast, Osman Celik sits down with Andrey Leskin, CTO of Qrator Labs, to break down what Content Delivery Networks really are in 2026 and why they've become a critical piece of modern security infrastructure, not just a performance](/content/watch/videocast-qrator-secure-cdn/index.html)
\ \ Jun 10, 2026\ \ From SAP IDM to Modern IGA: Closing the AD Lifecycle Gap Before 2027\ \ \ SAP Identity Management reaches end of mainstream maintenance in December 2027, and every IGA vendor is offering a replacement. But most migration guidance misses a critical gap: organizations following SAP's recommended path to Microsoft Entra will still lack proper Active Directory lifecycle](/content/watch/sap-idm-to-modern-iga/index.html)
\ \ May 09, 2025\ \ PANEL: The REAL Business Case for Decentralized Identity & EU DI Wallet\ \ \ While the promise of decentralized identity (DID) and the EU Digital Identity Wallet (EUDI Wallet) is often framed in terms of privacy and user control, the real driver for widespread adoption will be compelling business value. This panel will move beyond the hype to examine what truly makes](/content/watch/panel-the-real-business-case-eic25/index.html)
\ \ May 09, 2025\ \ PANEL: Delegation with Boundaries: Ownership, Accountability, and Trust in B2B Federations\ \ \ As digital ecosystems become more interconnected, organizations increasingly rely on federated identity and access models to collaborate across business boundaries. Yet this reliance raises a crucial question: How much control should be retained internally, and how much can be safely delegated to](/content/watch/panel-delegation-with-boundaries-eic25/index.html)
[
\
\
May 09, 2025\
\
AI at your Service [Intermediate]\
\
\
Imagine a future where AI seamlessly handles Identity Governance and Administration (IGA) tasks—whether you’re an administrator, a helpdesk agent, or an end user. Instead of navigating complex workflows and esoteric User Interfaces, AI will be at your service, executing tasks through](/content/watch/ai-at-your-service-eic25/index.html)
\ \ Dec 05, 2024\ \ Transforming Ecosystem Partner Security Risk Management: Lessons Learned and Insights for DORA Implementation\ \ \ As organizations face increasing regulatory demands and evolving cyber threats, effective Ecosystem Partner security risk management has become a critical priority. This session will explore a successful transformation journey in Ecosystem Partner security risk management, highlighting the](/content/watch/transforming-ecosystem-partner-security-risk-management-cre24/index.html)
\ \ Dec 05, 2024\ \ In der digitalen Arena: Digitalisierung bei Bayern München - aber sicher](/content/watch/arena-digitalisierung-bayern-munchen-cre24/index.html)
\ \ Dec 05, 2024\ \ Enhancing Cyber Resilience: Integrating Identity Management, Multi-Cloud Strategies, and Advanced Threat Detection](/content/watch/enhancing-cyber-resilience-cre24/index.html)
\ \ Jun 04, 2026\ \ Unified Governance Across SAP and Business Applications\ \ \ As organizations expand beyond SAP into hybrid ecosystems of SaaS and LoB applications, governance becomes fragmented and inconsistent. Traditional access control approaches no longer suffice, requiring a shift toward holistic Business Application Risk Management that leverages integrated](/content/watch/heterogeneous-it/index.html)
\ \ May 28, 2026\ \ Beyond SOAR: The Rise of the AI SOC\ \ \ The AI SOC market is expanding rapidly as security vendors race to deliver security automation systems that help deliver smarter triage, improved investigations, and faster responses. But not every AI claim translates into meaningful operational improvement. \ This webinar examines what is](/content/watch/rise-of-ai-soc/index.html)
\ \ Jun 08, 2026\ \ PAM Is No Longer a Vault: The New Identity Security Layer\ \ \ Privileged Access Management has outgrown the vault. In this episode, Matthias sits down with lead analyst Alejandro Leal, author of KuppingerCole's newly released PAM Leadership Compass, to explore how the definition of privilege itself has changed, what NHIs and agentic AI mean for PAM, and why](/content/watch/pam-no-longer-a-vault/index.html)
\ \ Jun 01, 2026\ \ Know Your Attack Surface: ASM, DRP & Brand Protection\ \ \ Not all cyber threats target your systems, some target your reputation, your customers, and your brand. In this episode, Matthias Reinwarth sits down with research analyst Osman Celik to unpack three closely related but distinct markets: Attack Surface Management (ASM), Digital Risk Protection](/content/watch/know-your-attack-surface/index.html)
Advisory
Advisory Services Success stories IAM Maturity Assessment Identity Fabric & Reference Architecture
Advisory Services
KuppingerCole's Advisory stands out due to our regular communication with vendors and key clients, providing us with in-depth insight into the issues and knowledge required to address real-world challenges.
[See Advisory Services\ \
Contact our advisors
E-mail info@kuppingercole.com
[Meet our Advisors\ \
Boehringer Ingelheim, a leading pharmaceutical company, sought to enhance its Identity and Access Management (IAM) capabilities in the digital age. We collaborated to develop a strategic IAM roadmap in just five months, aligning their IT infrastructure with their global leadership position.
Global chemical company revamped its Identity and Access Management with KuppingerCole's IAM strategy: guidance, assessment, roadmap. Enhanced security and efficiency.
IAM Maturity Assessment
Discover your IAM maturity level across key areas, benchmarked against KuppingerCole’s Reference Architecture, and receive a personalized report with expert recommendations.
[Get Started\ \
Identity Fabric & Reference Architecture
Explore how to unify, modernize, and scale your IAM ecosystem with a consistent architectural foundation.
[Learn More\ \
Membership
About Professional Expert Corporate
Your gateway to Identity Security excellence
Unlock the power of industry-leading insights and expertise. Gain access to our extensive knowledge base, vibrant community, and tailored analyst sessions—all designed to keep you at the forefront of identity security.
[Learn More\ \
Stay ahead of industry trends and make informed decisions
Access essential knowledge at your fingertips with KuppingerCole's extensive resources. From in-depth reports to concise one-pagers, leverage our complete security library to inform strategy and drive innovation.
[Learn More\ \
Elevate your expertise and expand your professional network
Gain access to comprehensive resources, personalized analyst consultations, and exclusive events – all designed to enhance your decision-making capabilities and industry connections.
[Learn More\ \
Empower your team with the knowledge and connections to drive change
Gain a true partner to drive transformative initiatives. Access comprehensive resources, tailored expert guidance, and networking opportunities.
[Learn More\ \
Company
About us Success Stories People Career Opportunities Newsroom Cybersecurity Council Technology Providers Contact us
Discover Our Passion for Advancing Identity and Security
We are specialized in the strategic management of digital identities, privileges, authentication, and access control as well as cybersecurity and business resilience.
[Read more about our philosophy\ \
Success Stories
\ \ KuppingerCole Success Story - Chemical Industry\ \ \ Global chemical company revamped IAM with KuppingerCole's IAM strategy: guidance, assessment, roadmap. Enhanced security and efficiency.](/content/success-story-leading-chemical-company/index.html)
\ \ Futurae Technologies AG\ \ \ Futurae Technologies AG, founded in 2016 as a spin-off from ETH Zurich, is a Swiss cybersecurity company specializing in user-centric multi-factor authentication and transaction signing solutions. Their platform combines strong security with seamless user experience, serving banks, insurers, and](/content/success-story-futurae/index.html)
\ \ sharelock.ai Success Story\ \ \ Discover how sharelock.ai, an innovative ITDR startup, refined its market positioning and strategy with KuppingerCole’s guidance—unlocking clarity, differentiation, and readiness for growth in the identity security space.](/content/success-story-sharelock/index.html)
[View All Success Stories\ \
Analysts & Advisors
Meet our team of analysts and advisors who are highly skilled and experienced professionals dedicated to helping you make informed decisions and achieve your goals.
Business Team
Meet our business team committed to helping you achieve success. We understand that running a business can be challenging, but with the right team in your corner, anything is possible.
[Meet the Team\ \
Career Opportunities
\ \ Events\ \ Wiesbaden\ \ Ausbildung zum Veranstaltungskaufmann/-frau (m/w/d)\ \ \ Die KuppingerCole Analysts AG ist ein IT-Analystenunternehmen mit Hauptsitz in Wiesbaden und weiteren Standorten rund um die Welt. Insgesamt beschäftigen wir aktuell rund 50 Mitarbeiter. KuppingerCole unterstützt seine Kunden mit Leistungen in den Bereichen Events, Advisory und Research.](/content/jobs/62/index.html)
[View All Job Offers\ \
Latest Press Releases
\ \ Press Release\ \ May 22,\ 2026\ \ KuppingerCole Analysts Wraps Up EIC 2026: Europe’s Leading Identity Conference Explores Digital Trust Through Intelligent Identity\ \ \ The European Identity and Cloud Conference (EIC) 2026 concluded in Berlin after four days of discussions on digital trust, AI-driven identity, authorization, governance, and the future of intelligent identity systems. Hosted by KuppingerCole Analysts, the event gathered over 1,500 attendees, 250+](/content/press-release/eic-2026-wrapped/index.html)
\ \ Press Release\ \ March 18,\ 2026\ \ KuppingerCole Analysts Launches Product Value Navigator to Validate the Business Impact of Technology Investments\ \ \ Product Value Navigator is a new research framework from KuppingerCole Analysts designed to validate the economic value of enterprise technology solutions. By combining independent technical evaluation with financial modelling and open-source intelligence data, it provides transparent insight into](/content/press-release/product-value-navigator/index.html)
\ \ Press Release\ \ February 19,\ 2026\ \ KuppingerCole Analysts and Forum INCYBER Enter Strategic Partnership to Strengthen European Cybersecurity Market Intelligence\ \ \ KuppingerCole Analysts and Forum INCYBER announce a strategic partnership to strengthen European cybersecurity market intelligence, thought leadership, and cross-regional collaboration across France, Benelux, and DACH.](/content/press-release/kuppingercole-analysts-forum-incyber/index.html)
Cybersecurity Council
With the Cybersecurity Council, we bring together world-class information security professionals in leading positions from across many industries and schools of thought to exchange and discuss how to secure the rapidly growing cyber economy. The results of these fruitful discussions will flow into every of our services.
[Learn more\ \
Services for Technology Providers
You're building the future in a crowded, skeptical market. KuppingerCole Analysts helps you stand out with neutral credibility, market insights, and direct access to key decision-makers. We empower technology providers with the visibility, insights, and analyst-backed influence to win in a competitive market.
[Learn more\ \
Basic contact information
KuppingerCole Analysts AG
Wilhelmstr. 20-22
65185 Wiesbaden
Germany
[See all locations\ \
Use AI-powered search to answer my question
Use AI-powered search to answer my question
In order to watch this video, you have to log in or create an account, if you don't have one yet.
[Log in\ \ [Register\ \ [Choose your membership package\ \
Event Recording
Like this?
Don't like this?
Log in to make your opinion count! We will also use your feedback to tune your personal recommendations.
Log in to hear your voice heard. We'll also make sure to update your personal recommendations.
Don't have a KC account yet? Join Now
Why don't you like this?
This isn't relevant for me
I don't like the content
SubmitCancel
0
Save
Bookmarks
Save your favorite items in your personal watch list so that you can read them later and find them again easily.
Don't have a KC account yet? Join Now
[LinkedIn [Facebook [X / Twitter%20Jungle:%20EDR,%20EPDR,%20XDR,%20NDR,%20MDR,%20ITDR)Copy URL
Navigate the DR (Detection & Response) Jungle: EDR, EPDR, XDR, NDR, MDR, ITDR
\ \ Martin Kuppinger\ \ Distinguished Analyst\ \ KuppingerCole Analysts](/content/speakers/96/index.html)
Posted on May 11, 2023
Close
ITDR: Is this really something new, given that around 80% of the cyberattacks are identity-related, from password phishing to bypassing MFA? Is it a separate discipline or just a part of XDR (Extended Detection and Response)? Or a new name for what Access Management and FRIP already do?
As always, there is something new and relevant in this. The fundamental question for many organizations will be on how to address the identity threat challenge best. Does it require new or different tools, or just a different use of what is already there? What to look for specifically? And how to reduce the risk of identity-based attacks? Is ITDR the core, or better identity protection? These questions will be answered in this session to help you navigating through the buzzword jungle.
[Log in to download presentations\ \
Video Description
Short Summary
Interesting Facts
Recommendations
Takeaways
Lorem ipsum odor amet, consectetuer adipiscing elit. Luctus fames rutrum metus habitasse donec quis turpis.
Nibh porta tristique sociosqu eleifend condimentum sapien ultricies. Dapibus rhoncus urna elit commodo blandit ut vestibulum tristique. Ante parturient morbi maecenas leo ac est dolor aliquam iaculis.
Leo vehicula vivamus ipsum lacinia cubilia torquent accumsan! Viverra a dictumst dapibus; nam consequat felis mus. Euismod semper iaculis congue mauris nullam.
Sign up and get more insights
Become a member of the KuppingerCole Community to access this and thousands of other publications.
[Log in or register\ \
Lorem ipsum odor amet, consectetuer adipiscing elit. Luctus fames rutrum metus habitasse donec quis turpis.
Leo vehicula vivamus ipsum lacinia cubilia torquent accumsan! Viverra a dictumst dapibus; nam consequat felis mus. Euismod semper iaculis congue mauris nullam.
Sign up and get more insights
Become a member of the KuppingerCole Community to access this and thousands of other publications.
[Log in or register\ \
Lorem ipsum odor amet, consectetuer adipiscing elit. Luctus fames rutrum metus habitasse donec quis turpis.
Leo vehicula vivamus ipsum lacinia cubilia torquent accumsan! Viverra a dictumst dapibus; nam consequat felis mus. Euismod semper iaculis congue mauris nullam.
Sign up and get more insights
Become a member of the KuppingerCole Community to access this and thousands of other publications.
[Log in or register\ \
Lorem ipsum odor amet, consectetuer adipiscing elit. Luctus fames rutrum metus habitasse donec quis turpis.
Leo vehicula vivamus ipsum lacinia cubilia torquent accumsan! Viverra a dictumst dapibus; nam consequat felis mus. Euismod semper iaculis congue mauris nullam.
Sign up and get more insights
Become a member of the KuppingerCole Community to access this and thousands of other publications.
[Log in or register\ \
Top related content
\ \ Leadership Compass](/content/research/lc80923/extended-detection-and-response-xdr/index.html)
eXtended Detection and Response (XDR)
Dec 05, 2024
\ \ Executive View](/content/research/ev81352/tata-communications-mdr/index.html)
Tata Communications MDR
Dec 19, 2023
\ \ Blog](/content/blog/tolbert/identity-security/index.html)
Identity Security
Jul 05, 2024
\ \ Buyer's Compass](/content/research/bc80779/endpoint-protection-detection-response-epdr/index.html)
Endpoint Protection Detection & Response (EPDR)
Oct 09, 2024
\ \ Buyer's Compass](/content/research/bc80872/extended-detection-and-response-xdr/index.html)
eXtended Detection and Response (XDR)
Jan 08, 2025
\ \ Whitepaper](/content/research/wp81267/enhancing-security-frameworks-through-zero-trust-and-identity-threat-detection-and-response-itdr/index.html)
Enhancing Security Frameworks through Zero Trust and Identity Threat Detection and Response (ITDR)
Aug 27, 2024
\ \ Whitepaper](/content/research/wp81137/the-future-of-cloud-security/index.html)
The Future of Cloud Security
Dec 19, 2025
\ \ Blog](/content/blog/small/threat-detection-and-incident-response/index.html)
Threat Detection and Incident Response
Jan 15, 2024
\ \ Blog](/content/blog/tolbert/what-enterprise-security-can-learn/index.html)
What Enterprise Security Can Learn from Consumer Fraud Prevention
Mar 20, 2026
\ \ Leadership Compass](/content/research/lc80829/network-detection-and-response-ndr/index.html)
Network Detection and Response (NDR)
Oct 14, 2024
\ \ Leadership Compass](/content/research/lc81209/identity-threat-detection-and-response-itdr/index.html)
Identity Threat Detection and Response (ITDR)
Nov 06, 2025
\ \ Buyer's Compass](/content/research/bc82021/network-detection-and-response-ndr/index.html)
Network Detection and Response (NDR)
May 06, 2026
Hide Transcript
Show Transcript
Thank you, Osman. I see you skipped the introduction for me and don't explain who I am. So probably some people in the room have, have seen me before, even while yesterday evening, have been asked by, by someone. Western's my first time at eic.
Yeah, I I said not, not exactly. So it happens every now and then. I want to give you a very quick talk about ed, dr the detect detection response triangle with all these dr, so to speak.
So, so we have, we have quite, quite a number of these and I, I would, I will put a bit more emphasis on the it d r part. So we are at an identity conference. So the identity threat detection response will be a bit of a major part of what I'm talking about. And so when we look at this entire thing, I, I wanna start with a bit of a bigger picture. And so protect, detect response, so like an E P D R endpoint protection detection response, they are core parts of the security cycle.
So when we look at this, so we have this, and there are different varies from NIST and others where we identify risks, where we prepare for, for, for protecting and, and detecting and responding and what I might personally believe, most importantly, recovering from things that go wrong because at the end of the day, it's realistic. At some point some attacks will succeed. And then we need to be able to recover.
And I think this is something which is sometimes a bit underestimated and we talk more about the three highlighted product detect, respond, and we also need to improve, and this is something which is about preparing and about responding when we take a bit of bigger perspective here, which is powered by a lot of tools. I took some of these, but I'll touch more other tools, the, all the ones with the DR in today. But it's also about processes we have in place. So we need adequate processes. We need to think not just about tools.
We need to think about GRC processes, where we identify where we handle risks, attack surface management, incident response, business continuity management, business impact analysis, something which is always a very interesting thing to do by the way. So, so what is commonly in a manufacturing organization, the, the most critical system, it's the software that controls the high bay rec storage. Because if that fails, you don't find the parts for your production anymore, you're lost and you frequent don't think about it.
And, and you need to involve the people, the management, security, identity, everyone in cybersecurity to enable them. And by the way, we had some interesting discussions around deepfake these days. I I think it's also a part of education, understanding when do you need, so when do you need to be alerted?
Like, like we are alerted by certain types of males. Yeah. If you're in large organization, depending on your top level, it might not be very likely that your CEO calls you. It's not very likely that your CEO sends you an email and saying, Hey, you need to to ensure that this 1 billion financial transaction takes place. So usually it's, it's also a bit of human sense. So look at, let's look at the terminology, the various sort of PDRs here. So we have endpoint, we have endpoint protection, detection response, which is a bit broader approach.
We have network, we have identities, threats, detection, response. It's just probably the newest area here. We have extended detection response. We have managed detection response, at least there might be more around here. And we have, we have things where a bit of p and D and R is in, even while they don't have this, don't carry this name like cloud native application protection platforms, which then include things like cloud security, poster management. I dare to say that this acronym thing is a bit over the top and making a bit too complicated, but that's totally separate discussions.
There's another Analyst firm which creates most of the acronyms. So we are not guilty for most of these at least. And vendors are also very good, specifically the marketing departments of vendors as we know. So what does it mean to zero trusts? So zero trusts is something which encompasses the entire it. So we have identity. So Martin uses a device communicates via network to a system where an APPLIC application runs on that manages data. So a system application could be as a SaaS service and is there's software and we need to protect everything here.
And we have IT tdr, which looks at the identity. We have edr, E P D R for the device, NDR for the network.
Oh, again, a bit of endpoint stuff when it goes more to the servers as endpoints and ITRs when it comes to systems applications, we have a bit of a blank space more when it comes to data and software. So we are not, we could say, okay, there's data security, et cetera, but it's not that much in, in the sense of really a packaged solution for for detection response yet. And same for software. So there are security solutions, et cetera. XDR is in some way the integrating technology across the various DR technologies, but it also shows.
So there are a lot of things, but there's also some white space or whatever we, we probably need to get better. So we are, we haven't cared enough about data and security. And so software, also software security. And we have learned a lot that we have a lot to do over the past years. And MDR is then factually delivering the XDR part, this managed service. So when we want to look at it from that terminology, we could also put it into a even a bit broader context here. And that would be then that be a really great greater, broader picture. And that would be about how does this fit into SOCs?
And all of these graphics have a bit of a tendency to simplify things. But I think this is the concept of these graphics. If I don't build a full big picture with every element, then otherwise it would, it would be hard to understand. And then I would start with manage detection response. So manage detection response is really the service that is built around. It helps us.
And if, if you're realistic, very few organizations can handle cybersecurity without managed services, without support. Some need to do, but usually everyone is suffering a bit from a skills gap. So is to anyone in the room who says, Hey, it's for us. It's so easy to find a required resources we trust and, and we have the right people on board, probably not.
So if, if then raise the hand. I would be really curious about how you do that. So we need services to, to close gaps in order to, to have some, some economies of scale here where, where we can use sort of rare capabilities optimally for where they are best. In that case, this so to speak, caring about our security operation center or CDC C and there are sync and, and this is not, not, not a complete list. So we have the, the SOAR space security or, or security orchestration automation response, which is sim on steroids by adding orchestration automation response.
And then we have the XDR part where the different specific DRS go in maybe in the future more than these. And we have the peoples and processes and monitors methods like incident management, et cetera. So how do we deal when with the situation, when something goes wrong, how do we handle all these things? And we have more tools in the, so like attack service management. If you want to know anything about attack service management, ask Osman here. He's working a lot on this subject. So he's a person to talk with.
And so this is another perspective on, on how to look at how do these things fit together and, and where do they find their place. And at the end, we need a variety of tools because as I've shown previously with this sort of zero trust alignment across this flow of what HAP is happening, there's a place for different types of tools. And at the end, for for strong security posture, we need to cover a lot of areas.
And this is also, and one of the key areas is identity then, because if you look at real estate, at cyber threats, and there are different numbers between 50 and 80% of the attacks are related in some way related to identity. So ransomware usually starts with phishing business email compromise is about impersonation. So phishing goes into credentials. This is something which has to do a lot of identities, attacks on critical infrastructure, a mix of methods, malicious insiders, use of privileges, entitlement and exercise and so on.
So identity and access, the related things play a very central role in cyber attacks. And this will, so, so cybersecurity will remain a major drive for, IM investments specifically for emerging areas such as I identity, threat detection response. We need to get better here to understand where are the things happening and okay, you could argue and say, hey, why, why do we need this?
We have a same tool in place and we were smart enough to configure all the rules for the same tools couple of years ago already, which helps us to deal with all the signals and figure out when there are any animals around access, et cetera. Yeah, reality is most likely we are, we are not as good on that. We probably, depending, when you're from Germany and from a larger organization, you, you, you may got stuck with the workers council latest here because they say, oh, this sounds like you're supervising the workers even while it's totally legal.
Workers councils sometimes are, are a bit brown here for things like uba, so user behavior analytics, et cetera. So what we, but we need to do that and we have the technology, we can do it good enough. And maybe I TDR also is a new name, helps us a bit to do it better because I tdr sounds way less problematic than user behavior analytics if you're honest. So user behavior, if I were a work as council member, my alarm bills probably would ring when I hear user behavior, you're lost at that point after behavior.
You, you have lost that game. Yeah, it's, it's, it's, it's just a matter of wording.
I, identity, threat, threat. Oh, that's dangerous. We need to do something. Yeah. Psychologically, very different thing. Sometimes it's also really naming the things the right way. Yeah. And and what is it about, it's about monitoring. So what is happening? Gathering signals. And we see a lot of interesting things happening around shared signals. Finally, I remember at eic number one, I, I gathered a couple of people and said, shouldn't we look to create a standard that helps us sharing signals about who uses what, what does it mean from a audit and threat perspective?
I probably was 15 years to to to early with that. Right Now we see finally standards developing in the space. It's detecting it.
So, so baselining normal activities, bringing in ml, et cetera, and identifying the, the outliers, the anomalies respond on that. So first authentication, lower entitlements, whatever you can do disable accounts depending on what is happening, maybe even do deception.
So, so if there's something obvious is lure them to another system, analyze the risk, enforce appropriate identity assurance levels and, and add all the device stuff around it because this is the, or in the broader sense, all the context stuff. Because context, this is what is really essentially here. So we have these things and we must make use of this.
We see a very rapidly emerging market here with a lot of vendors entering this because at the end of the, that it d r, so we see vendors entering from two, two areas or three, some are new startups, some are sort of UBA with a psychologically more attractive name. And the third ones are vendors that come really more from the threat detection space, which are experienced in, in analyzing a huge number of signals. And if you apply it to the right use case and that get us identities related threats, collect the right signals, you're there.
So this is what is happening and I believe it's a very important area to look at, at the really at the, I would say at the center of identity security, because this is exactly in the middle between these two words. Thank you for listening to me. We can have a question, we could maybe have a question. We still have like a minute or something.
Alright, one second. Usual suspects. Sorry. Oh no Thanks Martin.
Just, just a short one on, on the upcoming and never in quality increasing deep fake things in impersonation. What's, what's your take on that? What in what amount the risk will increase looking at these things? Oh yeah, you know, not, not, not because of the question.
I, I think this is going, it's a bit headless chicken mode currently. So a lot of people are panicking by that. But you know, we had fishing at the beginning, we had no idea what to do, that we had a ton of other types of attacks. They came and yes, there was a peak and then we came up with technology that helped us to reduce this to small amount, which we can handle with a reasonable amount of risk for deep fakes. My perspective is, so the usual saying in cybersecurity is our problem is an attacker needs one working attack vector.
We need to defend against all, which is an uneven play for deep fakes. It's also in some sense an uneven play, but the other way around because creating a deep fake takes a lot of compute power if it's good and you need to be perfect to defend against deep fakes, you just need to spot one mistake in that.
And we, I'm convinced in relatively short time, we will have in all the relevant tools in the video conferencing systems, in the platforms where you see a lot of videos, et cetera, we will have integrated, like we have email security, we will have, so to speak, deep fake security integrated. This is easier to do than creating a good deep fake.
So yes, we will have a peak and we, there will be always a residual part of the problem, but I, I think we, we, we, we, we must not be in total panic mode now regarding this. So I'm a bit more on the positive end here. I'll be right on the, oh, I, yeah, I hope so as well, honestly. Okay. Thank you.
Yeah, thank you Martin. Yeah.