In 2026, Cisco bought Astrix, SailPoint bought Entro, Okta bought Permiso and Cyera bought Oasis. The Agent Security Map deals ledger tracks all 30 deals with SEC-filed prices and sources, and shows a security buyer how to check a vendor's ownership before the next call.
Model providers solved the machine half of agent authentication in 2026. The half nobody solved is attribution: no provider can tell you which human authorized what your agent did.
An AI model manufactured fake identities to socially engineer a real maintainer, then edited its tracks when challenged. The request failed. The threat model should not.
Meta's settlement with 51 attorneys general commits at least $12.1 billion, but the money is the survivable part. Every teen safety term in the deal depends on knowing who is under 18, and nobody has solved that yet.
Mandiant ranked voice phishing the second most common initial infection vector of 2025. In the same window, thousands of businesses handed their phone lines to AI agents. Those two facts are related, and the security implications run in both directions.
Your identity stack was architected for humans with browsers and thumbs. Agent traffic breaks consent, delegation, sessions, bot defence and audit at once.
On System Administrator Appreciation Day, appreciation for the people who hold the literal keys to the organization, and why identity work matters more, not less, in the AI era.
Identity vendors rarely die of bankruptcy. They die of acquisition, then neglect, then a shutdown email. A complete history of every dead CIAM vendor, the pattern behind the deaths, and the questions that protect you from the next one.
A founder's guide to the difference between authentication and authorization in 2026, with passkeys, agent auth, JWT pitfalls, and the mistakes I see at scale.
AT&T's $177M settlement covers 73M customers, but the real story is how breach data from 2019 just resurfaced in 2026 with fully decrypted SSNs. Here's why.
Production authentication patterns for OAuth 2.0, OIDC, JWT, SAML, and WebAuthn, including the build-versus-buy maths and the storage and session decisions that are expensive to reverse later.
Master workplace identity security with our comprehensive 2025 IAM buyers' guide. Explore 25 essential strategies from SSO to Zero Trust, with practical
Ten identity verification platforms compared on liveness, deepfake and injection defense, coverage and published pricing, plus specialist tools and use cases.
Azure AD is now Microsoft Entra ID. Compare Okta, JumpCloud, Ping Identity, Google Cloud Identity, Keycloak and more, with Entra ID P1/P2 pricing verified.
Ten identity lifecycle platforms compared on HR-driven joiner mover leaver automation, SCIM, non-human identities and pricing. Verified September 2026.
IGA platforms compared on access certifications, separation of duties, role management and AI agent governance, with verified pricing and 2026 market changes.
Which cloud directory should you pick? JumpCloud, Entra ID (formerly Azure AD), Okta, Google Cloud Identity and four more, compared on protocols, devices, and price.
Protect against identity-based attacks with the top 5 ITDR solutions. From Microsoft Defender to Semperis DSP, discover platforms that detect compromised
Which IAM platform fits your organization? 21 workforce platforms compared with verified 2026 pricing, the year's acquisitions, and newer entrants to watch.
IASM discovers every identity in your estate, maps what each can reach, and closes the paths attackers use. How it relates to ITDR, ISPM, CIEM and NHI security.
In the battle of the old vs. the new, it is evident that traditional identity and access management (IAM) solutions are gradually getting phased out by
Identity Governance and Administration is the policy and audit layer on top of IAM. Why every mid-sized organization now needs it and what to evaluate.
An identity provider centralises authentication for every app you run. Here is what it does and why it is one of the highest-ROI infrastructure investments.
IAM is the discipline of giving the right people the right access and proving it after the fact. Concepts, controls, and how to design a modern program.
In the previous article (Guide to Digital Identity-Part 1 [https://medium.com/@dip_ak/guide-to-digital-identity-part-1-4b7c8fe45ee1]), we talked about the
Social login still has a place, but it is no longer the front door. A practitioner's view on when to use it, how to harden it, and what is replacing it.