by Gary Zimmerman | Sep 14, 2026 | AI, Governance, Identity
The governance architecture that Black Hat 2026 defined — the five-layer control plane for AI agents built from identity outward — depends on a premise that most enterprise identity programs have not yet confronted: role-based access control does not work for AI...
by Gary Zimmerman | Sep 8, 2026 | AI, Identity
There is a version of the AI governance conversation that has been happening for two years in conference rooms and board briefings and risk committee agendas. It is a conversation about frameworks and policies and responsible AI principles and vendor attestations and...
by Gary Zimmerman | Aug 4, 2026 | AI, Governance, Identity
On July 28, Cyera announced it was acquiring Oasis Security for $1 billion. The same day, Hush Security announced a $30 million Series A. Two days later, Okta announced it was acquiring Permiso Security — financial terms undisclosed, but strategically significant...
by Gary Zimmerman | Jun 22, 2026 | AI, Governance, Identity
The CISO role has always carried accountability that outpaced authority. What changed in 2026 is that the accountability became legally enforceable, personally, and the regulatory mechanisms to enforce it are no longer on the horizon. They are active. Splunk’s...
by Gary Zimmerman | Jun 15, 2026 | AI, Cybersecurity, Identity
Your identity governance program almost certainly has a blind spot. It is not a configuration error or a policy gap. It is architectural. The IGA platforms most enterprises run were designed when “identity” meant a person. Joiner-mover-leaver workflows,...
by Gary Zimmerman | Jun 2, 2026 | AI, Cybersecurity, Identity
The question we keep getting from security architects right now is some version of the same thing: “We have a zero trust program. We have identity governance. We have PAM. Why does none of it cover our AI agents?” The honest answer is that it was never...
by Gary Zimmerman | Apr 10, 2026 | Cybersecurity, Governance, Identity
Most M&A teams move fast on financial, legal, and operational due diligence—but overlook one of the biggest post-close failure points: identity. When you buy a company, you are also acquiring every account, role, entitlement, and backdoor they have in place. Yet...
by Gary Zimmerman | Apr 3, 2026 | Cybersecurity, Identity
Over the last few years, most organizations have made heavy investments in identity: single sign‑on, MFA, privileged access management, and cloud directory modernization. Yet many of the most damaging breaches still begin with something simple: an attacker using valid...
by Doug Simmons | Mar 13, 2026 | Governance, Identity
When boards and CISOs talk about “modernizing identity,” the conversation too often stops at the tooling layer — a refresh of single sign‑on, an IGA upgrade, some PAM rationalization, maybe a Zero Trust pilot. The result? A highly instrumented stack that still behaves...
by Gary Zimmerman | Feb 20, 2026 | AI, Cybersecurity, Governance, Identity
Credential stuffing used to be a volume game. Spray billions of stolen username-password pairs at login pages, get a 0.1% hit rate, move on. In 2026, it’s surgical. And your board is going to ask you about it. Here’s what changed: AI-powered attackers...
Recent Comments