Search/sailpoint
Vendor

sailpoint

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
desktop password reset
Connections
19 relationships
Security Hub Extended adds Supply Chain Security as its tenth category
Since February, we’ve grown AWS Security Hub Extended from 14 curated partners across 9 categories to 23 partners across 10. At Black Hat this month, 14 of those partners were at the Amazon Web Services (AWS) booth demoing live. Four of those partners delivered theater talks and ten were featured on SecurityLive streaming. We hosted a partner reception that brought our leadership together with partner executives to plan what comes next. These are companies investing real engineering and real go-to-market (GTM) alongside us, and increasingly with each other, because the model resonates with the customers they’re talking to every day. The most common question we heard at the booth was when Supply Chain Security was coming. It’s here. And that’s the thing I want to spend the most time on today, because it’s the category customers keep asking us about. Supply Chain Security: The category customers have been asking for Software supply chain risk has moved from a security-team concern to a board-level conversation. SolarWinds showed what happens when a build system is compromised. Log4j showed what a single transitive dependency vulnerability can do at global scale. The xz utils backdoor showed the patience of a maintainer-compromise attack executed over years. Each demonstrated a different dimension of the same problem, and the pace is accelerating. Attackers know that a fast way into an enterprise is through the open source packages that enterprise unknowingly trust. Every customer I talked to at Black Hat had this on their risk register. Most still hadn’t operationalized a solution, because doing so meant a standalone deployment, a new contract, a new console, and integration work their security team couldn’t prioritize. That’s the friction we aim to remove. Security Hub Extended now offers Supply Chain Security with Chainguard and Socket as the curated partners. Supply Chain Security uses the same model as everything else in Extended. Every offering has pay-as-you-go pricing, one bill, no required long-term commitment. For enterprises that prefer to continue using the procurement process they always have, Security Hub Extended Private Offers are also available. These are committed term agreements with deeper discounts, the ability to aggregate spend across partners on a single AWS bill, and both monthly and annual payment options throughout the term. You pick the path that fits how you buy. What Chainguard does Chainguard gives you open source dependencies rebuilt from source in a hardened, verified build process, so what enters your environment is malware-resistant and provenance-backed. Their research shows that rebuilding from source would have stopped 98% of known malicious packages from ever reaching production. If you can’t verify the source, it never appears in the Chainguard repository. That’s the filter between the public registry and your developers. What Socket does Socket analyzes the actual behavior of open source packages to block malicious dependencies at the time of install. Not after a Common Vulnerability and Exposures (CVE) is published days or weeks later. At the moment the package tries to land in your environment, Socket flags it based on what it does, not what a database says about it. Its reachability analysis then tells you which vulnerabilities are exploitable from your code instead of drowning your team in noise. You pay for the distinct packages you check, not for how often your builds run. Why they work together Together, Chainguard and Socket cover the two questions that matter: Can I trust what I’m pulling in? Can I stop malicious components before they get built into my applications? Chainguard helps secure the foundation your code is built on. Socket secures the packages you pull into it. Both help protect your software supply chain regardless of where you deploy—across clouds or on-premises. Activate both through Security Hub Extended and their findings flow into Security Hub in OCSF (Open Cybersecurity Schema Framework) alongside everything else, so a supply chain risk is correlated and prioritized next to your endpoint, identity, and cloud signals. From there, it routes out to the downstream tools you’ve already integrated, so it fits the pipeline your builders run today. 23 partners, 10 categories. Built on what customers asked for Every partner in Security Hub Extended is here because customers told us they needed that capability and that specific solution was already working for them. We add categories because the threat landscape evolves, and we add partners because customers point us to who’s solving those problems well. The goal is straightforward: Simplify adopting the security solutions your peers are already succeeding with, through the AWS relationship you already have. The full set today spans endpoint, identity, email, network, data, browser, cloud, AI, security operations, and now supply chain. The 23 curated partners are 7AI, Britive, Chainguard, CrowdStrike, Cyera, Island, LayerX, Native Security, Noma, Okta, Oligo, Opti, Palo Alto Networks, Proofpoint, SailPoint, SentinelOne, Socket, Splunk, Sublime, Upwind, Varonis, Zenity, and Zscaler. Our focus now is deepening integrations and reducing activation friction so these solutions work together, not in isolation. That’s where the real value compounds. What we’re building next Everything I’ve described so far is the commercial model working: Customers buying best-of-breed security through one AWS relationship with the flexibility they expect. But the bigger vision is the integration layer that makes these tools genuinely better together, not just easier to buy together. The integration we’re most focused on is cross-partner correlation, turning signals from an endpoint solution, an identity solution, and a cloud solution into one exposure and one attack path instead of three disconnected alerts. Right alongside that, we’re dramatically reducing the activation, deployment, and integration friction so customers go from subscribing to seeing value in hours rather than weeks. Both efforts enable the curated solutions you already trust to deliver stronger outcomes together than they do apart. That’s the build we’re accelerating with our partners now, and you’ll hear more leading into re:Invent. Explore what’s available If you’re running open source in production and don’t yet have supply chain visibility, start there. Activate Chainguard and Socket through the Security Hub console today. If you’re managing multiple security vendor relationships and want to understand what consolidation looks like with Security Hub Extended, talk to your AWS account team. Pricing for every partner is published on our pricing page , no sales call required. And if you’re already using Security Hub for posture management and threat detection, the Extended plan is available in the same console you already use. We’re just getting started. If you have feedback about this post, submit comments in the Comments section below. Michael Fuller Michael has been with AWS for 16 years and led product for AWS Security Services for 11 years. Michael has 29 years in the industry and held several roles in product management, business development, and software development for IBM, Cisco, and Amazon. Michael has a Bachelor’s of Science in Computer Engineering from the University of Arizona and an MBA from the University of Washington.
aws.amazon.comAug 18, 2026extracted
Cybersecurity M&A Roundup: 37 Deals Announced in June 2026
Thirty-seven cybersecurity-related merger and acquisition (M&A) deals were announced in June 2026. For a detailed view of the more than 420 acquisitions announced in 2025, check out SecurityWeek’s annual M&A report. Here are some of the most important cybersecurity M&A deals announced in June 2026: Password, secret, and access management solutions provider 1Password has acquired Apono, an Israel-based company that specializes in just-in-time access governance for humans, machines, and AI agents. 1Password reportedly paid between $250 million and $300 million for the company that will enable it to enhance and extend its identity security platform. San Jose-based A10 Networks (NYSE: ATEN) has acquired TrojAI, a Canada-based AI security firm, to add AI red-teaming and runtime protection to its security portfolio. Financial terms were not disclosed. Accenture is acquiring a majority stake in Dragos, plus full ownership of runZero and NetRise in transactions valued at a combined $4.175 billion, to build an integrated OT/industrial cybersecurity platform. The combination of the three security firms will deliver a unified solution that provides industrial and critical infrastructure operators with enhanced visibility across their OT environments and improved threat detection and response capabilities. Belgium-based Aikido Security has acquired Root, an agentic vulnerability remediation startup with Israeli roots, in a deal estimated at $70 million – $100 million (not officially disclosed). Root’s automated patching technology will power new Aikido Libraries and Aikido Images products, letting Aikido fix open source vulnerabilities in place without forcing version upgrades. Cisco has announced its intent to acquire WideField Security, a California identity threat detection startup, to strengthen the Agentic SOC capabilities of the Splunk platform by correlating identity, session, and activity data across human, non-human, and AI agent identities. This is Cisco’s third security-related acquisition of 2026, following Astrix Security and Galileo. Data intelligence firm Databricks has agreed to acquire fellow San Francisco company Panther Labs, a cloud-native SIEM and AI SOC platform, in its third cybersecurity acquisition as it builds out a “security lakehouse”. Financial terms were not disclosed, but Panther was last valued at $1.4 billion in 2021. F5 (NASDAQ: FFIV) has acquired Denver-based SurePath AI, a startup specializing in network-based shadow AI detection and discovery, to power its newly launched F5 AI Security Platform. SurePath had previously raised roughly $6 million in venture funding. Francisco Partners has acquired Paris-based EfficientIP, a DNS, DHCP, and IP address management (DDI) and DNS security specialist, from its founders and minority investors TempoCap and Jolt Capital. EfficientIP CEO Norman Girard and the company’s founders are staying on and reinvesting in the business. Rubrik (NYSE: RBRK) has acquired Colorado-based Strata, an identity orchestration company, to power a new Identity Continuity feature that keeps authentication running via automatic failover to a secondary identity provider during cyber incidents. SailPoint (Nasdaq: SAIL) has completed its acquisition of Tel Aviv-based Entro Security, a non-human identity and credentials security specialist, in a deal reportedly worth around $200 million. Entro’s technology will be integrated into SailPoint’s Agentic Fabric platform to expand discovery, governance, and real-time protection of AI agents and machine identities. Other cybersecurity M&A deals announced in June 2026: Related: Cybersecurity M&A Roundup: 26 Deals Announced in May 2026
securityweek.comJul 13, 2026extracted
Cisco to Acquire WideField Security to Boost Splunk’s Agentic SOC
Cisco on Thursday announced an agreement to acquire identity lifecycle security company WideField Security to strengthen the capabilities of Splunk’s Agentic SOC. No financial details have been publicly disclosed. WideField raised more than $11 million in Series A funding last year. WideField has developed technology that enables organizations to discover human and non-human identities, map exposures across accounts and roles, and assess hygiene gaps. The company’s platform also enables users to detect misconfigurations in authentication policies and weak authentication paths, providing live session monitoring for real-time threat detection, and AI-powered behavioral analytics. By integrating this into Splunk’s Agentic SOC and Cisco’s broader data fabric, the acquisition brings deeper identity and session intelligence into threat investigations, adding critical details around credentials, active sessions, and potential impact radius. This helps security teams better understand context for both human and AI-driven activity, and organizations gain the visibility needed to run autonomous AI systems securely at scale. This is Cisco’s third cybersecurity-related M&A deal of 2026, after Galileo and Astrix Security. Cisco’s announcement came on the same day Accenture revealed a major OT cybersecurity push via acquisitions totaling $4.1 billion. The professional services giant is taking a majority stake in Dragos and fully acquiring runZero and NetRise. SecurityWeek’s M&A tracker has cataloged approximately 190 deals to date in 2026. Related: SailPoint to Acquire Entro in Reported $200 Million Deal Related: Cybersecurity M&A Roundup: 26 Deals Announced in May 2026 Related: 1Password Acquires Apono in Reported $250M-$300M Deal
securityweek.comJun 19, 2026extracted
SailPoint to Acquire Entro in Reported $200 Million Deal
Identity governance and security solutions provider SailPoint has announced an agreement to acquire Entro, an Israel-based company specializing in non-human identity (NHI) and credential security solutions. Financial terms of the acquisition have not been officially disclosed, but Calcalist learned that the deal is valued at roughly $200 million. Entro will enable SailPoint to enhance and expand solutions, including its Agentic Fabric product, with capabilities designed for deep secrets discovery, mapping human identities to NHI, and real-time AI agent and machine identity threat detection and protection. Entro raised a total of $24 million in seed and Series A funding. “We are excited to integrate our deep, seamless discovery and lineage mapping engine into SailPoint’s comprehensive identity security framework and Agentic Fabric,” said Itzik Alvas, co-founder and CEO of Entro. “I believe that together, our combined non-human and AI capabilities will supercharge SailPoint’s proven ability to secure every identity, human and non-human, across the global enterprise landscape.” SailPoint returned to public markets via an IPO in early 2025. Its stock experienced positive momentum and gains in May 2026 amid growing investor confidence, but has trended downward in June following its Q1 FY2027 earnings release. The company’s Q1 results exceeded market expectations for revenue and adjusted earnings, but forward guidance was viewed as cautious and came in at the lower end of some estimates. SecurityWeek’s M&A tracker has cataloged roughly 190 deals announced to date in 2026. Related: SailPoint Discloses GitHub Repository Hack Related: 1Password Acquires Apono in Reported $250M-$300M Deal Related: Cybersecurity M&A Roundup: 26 Deals Announced in May 2026
securityweek.comJun 18, 2026extracted
SailPoint Agentic Fabric expands identity governance to autonomous AI agents
SailPoint Agentic Fabric expands identity governance to autonomous AI agents SailPoint has introduced SailPoint Agentic Fabric, a new platform designed to help enterprises secure AI agents and other non-human identities at scale. As organizations deploy autonomous AI agents across cloud environments, applications, and endpoints, they face a growing governance gap. Unlike traditional users, AI agents can act at machine speed, often without clear ownership, oversight, or consistent controls. As these non-human identities multiply, enterprises need a way to extend identity security beyond human users to the agents, machines, and applications now accessing critical systems and data. Identity Security Cloud helps organizations secure human identities, while Agentic Fabric extends that model to agentic governance and protection as part of SailPoint’s adaptive identity approach. Together, they provide a unified approach to managing every identity across the enterprise. By combining discovery, visibility, governance, authorization, and protection in one platform, SailPoint helps organizations accelerate AI adoption without losing control of security, compliance, or accountability. Agentic Fabric connects identities, access, and activity across the enterprise. This identity-centric model gives organizations the context they need to understand what AI agents can access, who is responsible for them, and how to govern them at scale. “AI agents are transforming how work gets done, but they’re also introducing a new class of identity risk that most organizations aren’t prepared for,” said Matt Mills, President at SailPoint. “You cannot secure what you cannot see, or what you cannot tie back to accountability. Agentic Fabric gives organizations the visibility, control, and context to keep autonomous agents secure, accountable, and connected to a human owner.” SailPoint centers security on identity relationships, mapping every AI agent to the human owners, data, and systems it interacts with. Agentic Fabric delivers end-to-end security allowing organizations to: Discover: Create a complete inventory of AI agents, machine identities, and applications across major cloud environments, application agents, and endpoints, and map the complex relationships to critical data using the identity graph. Govern: Map every agent to human ownership and human identity context while managing lifecycle controls and access policies. Protect: Enforce real-time controls for authorization with threat detection and automated response to help maintain least-privilege access as agents act. “With Agentic Fabric, SailPoint is moving aggressively to secure one of the biggest emerging risks in enterprise AI: the rapid growth of AI agents and other non-human identities,” added Chandra Gnanasambandam, EVP of Product and CTO at SailPoint. “As this new identity landscape takes shape, organizations need a way to govern and protect human, machine, and AI identities together. Agentic Fabric is a major step forward in helping customers secure the AI era.” Introducing Agentic packages and discovery free trial To help enterprises match identity security to the pace of AI adoption, SailPoint is introducing two new packages alongside Agentic Fabric: Agentic Business: Establishes foundational governance with least-privilege access across all identities. Agentic Business Plus: Advances to zero-standing privilege with just-in-time access and stronger enforcement controls. SailPoint is also offering a Discovery Tool free trial that provides immediate visibility into shadow AI and applications across existing environments. The tool is available today to net new customers as a standalone offering, as well as existing customers of IdentityIQ and Identity Security Cloud.
helpnetsecurity.comMay 11, 2026extracted
SailPoint Discloses GitHub Repository Hack
Identity management and governance provider SailPoint has disclosed a cybersecurity incident involving its GitHub repositories. In a filing with the Securities and Exchange Commission (SEC), the company revealed that the incident occurred on April 20 and was immediately contained. “On April 20, 2026, we detected unauthorized access to a subset of our GitHub repositories. Our incident response team quickly terminated the unauthorized activity and resolved the issue,” the SEC filing reads. [ Read: Ransomware Group Takes Credit for Trellix Hack ] According to SailPoint, the repositories were compromised through a vulnerability in a third-party application. The underlying issue has been addressed, it said. SailPoint said its investigation into the incident, conducted in collaboration with a third-party cybersecurity firm, has found no evidence that “customer data in our production or staging environments were accessed or that our services were interrupted.” The company told the SEC that it had directly notified customers if their information was stored in the accessed repositories. “[We] informed our customers generally that no additional actions are required at this time,” SailPoint’s SEC filing reads. SailPoint has not shared additional information on the attack, nor on the type of data that might have been compromised. It did not name the threat actor responsible for the incident, and it’s unclear if the intrusion is related to the recent spree of software supply chain attacks claimed by the TeamPCP hacking group. SecurityWeek has emailed SailPoint for additional information on the cyberattack and will update this article if the company responds. Related: Checkmarx Jenkins AST Plugin Compromised in Supply Chain Attack Related: ‘PCPJack’ Worm Removes TeamPCP Infections, Steals Credentials Related: Over 500 Organizations Hit in Years-Long Phishing Campaign Related: Government, Scientific Entities Hit via Daemon Tools Supply Chain Attack
securityweek.comMay 11, 2026extracted
Stolen Logins Are Fueling Everything From Ransomware to Nation-State Cyberattacks
Like an inverted pyramid, the range of different attack modes are now built on top of the single point of identity abuse. Stolen credentials are a major threat. Legitimate credentials illegitimately acquired provide legitimate access to illegitimate actors. Once inside the network, these bad actors have greater ability to move and act in stealth. The continuing rise in ransomware attacks bears testament. The theft and resale of credentials operates on an industrial scale. Fueled by the rise of increasingly more sophisticated infostealers, stolen credentials are packaged into ‘logs’ and sold to criminals on the black market. Ontinue reports, “Listings tied to LummaC2 alone surged by 72%, with high-privilege cloud console credentials selling for $1,000–$15,000+.” Ransomware has been one of the primary beneficiaries of stolen credentials. More than 7,000 incidents and 129 active groups were tracked through 2025. At the same time, ransom payments decreased slightly from $892M in 2024 to $820M in 2025. This apparent contradiction is actually logical. “Larger targets, with larger payout potential, will have seen the most aggressive corporate investment (process and technology) mitigating exposure to this attack pattern,” explains Trey Ford, chief strategy and trust officer at Bugcrowd. These larger targets are also more susceptible to government pressure to not pay ransoms, and ransomware income has consequently declined. The ransomware groups have responded with more attacks demanding smaller payments from more but smaller companies. These bad actors have simultaneously increased the pain threshold. Theft of data for blackmail has been growing for several years but is now often supplemented with operational disruption. “Beyond encrypting endpoints, attackers disrupt the ability to operate by wiping systems, deleting backups, sabotaging virtualization, attacking OT/ICS-adjacent services, or breaking identity/administration planes.” Think of modern ransomware as a multi-layer extortion machine, it continues. “Even when victims avoid paying, they are still dealing with downtime, regulatory exposure, third-party disruption, and long recovery cycles.” Nathaniel Jones, VP of security & AI strategy, and field CISO at Darktrace, adds, “Rather than relying solely on encrypting a target’s data for ransom, threat actors will increasingly employ double or even triple extortion strategies, encrypting sensitive data but also threatening to leak or sell stolen data.” At the same time, adversarial use of AI to assist in attacks is growing. Sophisticated and compelling phishing attacks are already evident, but Ontinue has also seen “the first meaningful signs of LLM-assisted malware development in 2H 2025.” This isn’t yet autonomous malware, but are signs that attackers are using AI to assist malware development for speed and features. “LLMs didn’t write the malware, but they wrote large pieces of it,” says Ontinue. “This lowers the bar dramatically. Adversaries with minimal engineering ability now ship tools that look more professional but still contain fundamental security flaws.” Stolen credentials are also fueling supply chain and SaaS attacks. The two big examples from 2025 are the Salesloft Drift OAuth campaign (with more than700 victim organizations) and the Shai-Hulud npm worm. Both campaigns abused the trust necessary in modern business infrastructure, with that trust breached by legitimate but stolen credentials. The increase in global geopolitical tension has further increased and complicated the cybersecurity battlefield – and has probably decreased any remaining ‘honor among thieves’. The Shai-Hulud actor (financially motivated rather than nation state motivated), for example, may attempt to delete the target’s home directory if it finds little to harvest. “This nihilistic ‘scorched earth’ fallback is new and signals the author’s willingness to cause irreversible damage,” notes Ontinue. Such behavior has traditionally been associated with nation state political motivations. This is widening. It is no longer government against government: targets now include civilian entities while attackers include politically motivated citizens as well as elite nation state actors. Ontinue quotes three examples: North Korea’s Lazarus Group $1.5B cryptocurrency theft; wiper attacks targeting Polish civilian infrastructure by Ghost Blizzard; and record-setting DDoS activity peaking at 31.4 Tbps via botnets with more than 500,000 IPs. There is little sign that geopolitically motivated attacks are likely to decrease in the immediate future – they are more likely to increase. Prompted by the US/Israel war against Iran, Iranian actors used wipers in the attack against Stryker earlier this year. The base of this inverted pyramid of malicious activity is occupied by infostealers fueling the activity. Infostealers are a successful tool for malicious actors. They use social engineering to get installed. Industry is yet to find a successful method to prevent social engineering, so it is unlikely that we will be able to stop infostealers. The implication is organizations should assume that attackers have or will obtain legitimate identities to use in their attacks. This means that more energy must be applied to recognizing and blocking the misuse of credentials while in use rather than simply trying to prevent their theft. “To combat today’s new era of threats, driven by the force multiplier of AI, we need to embrace a new approach of adaptive identity,” says Mark McClain, CEO at SailPoint. “Modern identity tools need to be able to discern between regular user activity and abnormal activity, and grant – or deny – access accordingly. Every access decision is driven by who or what the identity is, the context of the data they touch, and the security signals surrounding them. By unifying identity, security, and data contexts, businesses can make real-time decisions to mitigate risk without disrupting operations.” Ontinue summarizes this. “The organizations that will succeed in this new landscape will not necessarily be those with the strongest perimeters, but those that rethink how security is applied across identity. This means treating identity as the core control plane, monitoring authentication activity as closely as endpoint behavior, and securing both human and non-human identities with equal rigor.” Related: AI Speeds Attacks, But Identity Remains Cybersecurity’s Weakest Link Related: Iran Readied Cyberattack Capabilities for Response Prior to Epic Fury Related: Shadow AI Risk: How SaaS Apps Are Quietly Enabling Massive Breaches Related: 136 NPM Packages Delivering Infostealers Downloaded 100,000 Times
securityweek.comMar 31, 2026extracted
Cybersecurity jobs available right now: March 24, 2026
Cybersecurity jobs available right now: March 24, 2026 Application Security Analyst Alignerr | USA | Remote – No longer accepting applications As an Application Security Analyst, you will review and analyze application security scenarios across code, APIs, and system behavior. You will classify vulnerabilities such as authentication flaws, injection risks, and business logic issues, and evaluate secure coding practices and remediation strategies. You will also help create and validate security-focused reasoning datasets that train AI to accurately assess application risks. Application Security Engineer E.ON Digital Technology | Germany | Hybrid – No longer accepting applications As an Application Security Engineer, you will support the development and rollout of the application security roadmap. You will work closely with development and operations teams to enforce security practices and provide guidance early in the software development lifecycle to identify and mitigate risks. You will collaborate with Technology Platform teams to integrate security tools and processes into CI/CD pipelines, and guide developers on secure coding practices while helping remediate vulnerabilities. Cloud Security Lead Tata Consultancy Services | Ireland | Hybrid – No longer accepting applications As a Cloud Security Lead, you will own and govern cloud security controls across public and hybrid environments, including identity and access management, network security, workload and data protection, configuration baselines, and logging. You will provide cloud security architecture assurance for new and evolving solutions, ensuring alignment with security standards, risk appetite, shared responsibility models, and regulatory requirements. Get weekly updates on new cybersecurity job openings. Subscribe here! Corporate Cyber Security Specialist Paysafe | Ireland | Hybrid – No longer accepting applications As a Corporate Cyber Security Specialist, you will As a Corporate Cyber Security Specialist, you will lead small to medium security projects and support major initiatives, including the expansion of Microsoft 365 security services. You will design, implement, and optimize security automation, including ASR rules and other M365 controls. You will manage and enhance core security tools such as CASB solutions and CyberArk PAM, and build and strengthen IAM/IGA capabilities (Entra ID, SailPoint, Saviynt, Pathlock), including JML automation and access governance. Cyber Security Analyst The Cambridge Building Society | United Kingdom | Hybrid – No longer accepting applications As a Cyber Security Analyst, you will monitor and analyze outputs from security tools to identify early indicators of compromise. You will respond to cyber events and incidents, recommending and taking action to protect systems and data. You will fine-tune and enhance existing security controls to maximize their effectiveness, and coordinate regular testing, audits, and external security assessments, ensuring findings are risk-assessed and remediated within agreed timescales. Cybersecurity Automation Engineer Assurant | India | On-site – No longer accepting applications As a Cybersecurity Automation Engineer, you will design, implement, and maintain security solutions aligned with Assurant’s Information Security Policies and Standards. You will support technologies across applications, infrastructure, and endpoint security, and identify, assess, and remediate hardware and software vulnerabilities. You will ensure the confidentiality, integrity, and availability of enterprise systems, develop and recommend practices to prevent unauthorized access or data loss, and measure, analyze, and report compliance with security policies to leadership. Cybersecurity SOC L3 ZENDATA Cybersecurity | UAE | On-site – No longer accepting applications As a Cybersecurity SOC L3, you will lead SOC operations with a focus on operational excellence, visibility, and responsiveness. You will manage and mentor SOC analysts, fostering skill development and collaboration. You will drive SOC optimization through process improvements, automation, and technology adoption, and build and execute a strategic roadmap aligned with evolving threats and business goals. Head of Cyber Security Aneurin Bevan University Health Board | United Kingdom | On-site – No longer accepting applications As a Head of Cyber Security, you will provide strategic leadership and operational oversight for the organization’s cyber security posture, ensuring the protection of digital assets, clinical systems, and sensitive information. You will be responsible for developing and implementing cyber security strategy, managing risk, leading incident response, and ensuring compliance with national standards, regulatory requirements, and NHS Wales policies. Engineering Manager, Software Supply Chain Security: Pipeline Security GitLab | Canada | Remote – No longer accepting applications As an Engineering Manager, Software Supply Chain Security: Pipeline Security, you will guide the design and delivery of software supply chain security features, with a focus on CI job artifact security. You will lead the implementation of the SLSA framework in GitLab CI/CD and integrate capabilities such as SBOM, software composition analysis, and vulnerability management. Engineer – Network and Security KATIM | UAE | On-site – No longer accepting applications As an Engineer – Network and Security, you will architect, design, and implement scalable, resilient network solutions. You will deploy and manage network devices, including routers, switches, firewalls, and load balancers, ensuring availability, reliability, and performance meet business requirements. You will develop and enforce security policies, protocols, and procedures to protect the organization’s network and data, and conduct regular security assessments and audits to address vulnerabilities and ensure compliance with industry standards. Global Head IT Security & Compliance Lonza | France | Hybrid – No longer accepting applications As a Global Head IT Security & Compliance, you will develop, implement, and oversee a strategic enterprise information security and IT risk management program, including establishing and enforcing security policies and standards across the organization. You will create and manage security and risk awareness training for employees and system users, facilitate IT risk assessments in collaboration with stakeholders, and ensure compliance with relevant laws, regulations, and policies to minimize risk and audit findings. IT Security SecOps LSEG | France | Hybrid – No longer accepting applications As an IT Security SecOps, you will monitor cybersecurity events from internal tools and outsourced detection services. You will coordinate response and recovery efforts with IT teams, deliver cybersecurity service activities including SLA and KPI monitoring for insourced operations, and oversee outsourced security services to ensure effective performance and alignment. Penetration Tester Hacktive Security | Italy | Remote – No longer accepting applications As a Penetration Tester, you will lead and conduct comprehensive tests across systems, networks, web and mobile applications, and other digital assets. You will identify, assess, and ethically exploit vulnerabilities within client environments, and provide expert guidance on security best practices and risk mitigation to both technical and non-technical stakeholders. Safeguards Analyst, Account Abuse Anthropic | USA | Hybrid – No longer accepting applications As a Safeguards Analyst, Account Abuse, you will As a Safeguards Analyst, Account Abuse, you will develop and refine account signals and prevention frameworks that turn internal and external data into actionable abuse indicators. You will build and optimize identity and account-linking signals using graph-based infrastructure to detect coordinated, large-scale abuse. Security Engineer Paragon | Israel | On-site – No longer accepting applications As a Security Engineer, you will implement, configure, and maintain information security systems. You will continuously review and improve the organization’s infrastructure security architecture, ensuring that all requirements defined by the CISO and security team are properly implemented and aligned with the overall design. You will also actively monitor and analyze systems, firewalls, and logs to detect and respond to potential threats. Security Engineer Air Apps | USA | On-site – No longer accepting applications As a Security Engineer, you will develop and implement threat modeling to identify risks across applications and infrastructure. You will conduct vulnerability scanning, penetration testing, and security assessments to uncover weaknesses. You will define and enforce secure coding practices in collaboration with development teams and work with DevOps to integrate security into CI/CD pipelines and automate testing. Senior Cloud Security Consultant CyberCX | Australia | Hybrid – No longer accepting applications As a Senior Cloud Security Consultant, you will work with customers to design and deliver cloud security solutions, including native controls and third-party CSPM, CNAPP, or CIEM tools. You will assess the risk of existing cloud environments, workloads, and services against industry standards and frameworks, and provide recommendations to improve security posture. You will also prepare and present high-quality deliverables such as presentations, pre-sales proposals, assessment findings, and strategic recommendations. Senior Cloud Security Engineer Haventree Bank | Canada | Hybrid – No longer accepting applications As a Senior Cloud Security Engineer, you will act as the technical owner for key cloud security platforms, influencing configuration, detection logic, and roadmap in partnership with operations teams. You will define and maintain cloud security reference architectures across a multi-cloud environment, covering identity, network segmentation, encryption, workload protection, logging and monitoring, and secure service integration. You will also establish secure patterns for Infrastructure as Code, including secure-by-default templates, scanning expectations, and drift management. Senior Cyber Incident Responder Labcorp | USA | Hybrid – No longer accepting applications As a Senior Cyber Incident Responder, you will you will serve as the lead responder for validated cyber incidents, prioritizing threats that could impact clinical operations, EHR systems, connected medical devices, or PHI. You will coordinate with technical and clinical stakeholders to contain and remediate threats across hospitals, clinics, and remote care environments. You will drive improvements to the Incident Response Plan, ensuring readiness for ransomware, business email compromise, and other threats. Senior SAP ERP Security Specialist Merck Group | Germany | On-site – No longer accepting applications As a Senior SAP ERP Security Specialist, you will lead the security architecture across SAP S/4HANA and SAP ECC environments, ensuring alignment with enterprise security frameworks. You will manage user access governance and compliance, and integrate robust security controls into critical business processes. You will also monitor SAP systems for vulnerabilities, conduct risk assessments, and drive continuous improvement in security practices. SOC Analyst Tier 2 Elad Software Systems | Israel | Hybrid – No longer accepting applications As a SOC Analyst Tier 2, you will investigate and respond to escalations from Tier 1 analysts. You will conduct in-depth analysis of complex security alerts, including incidents, breaches, malware, phishing, and unauthorized access attempts. You will perform proactive threat hunting using advanced analytics, event correlation, and MITRE ATT&CK methodologies, and carry out endpoint forensics and network traffic analysis to identify attack vectors and scope. Vulnerability Analyst NTT DATA | Italy | On-site – No longer accepting applications As a Vulnerability Analyst, you will conduct vulnerability assessments using tools such as Nessus, Qualys, Rapid7, and OpenVAS. You will validate automated scan results to eliminate false positives, analyze vulnerabilities to assess exploitability and business impact, and create detailed reports with actionable remediation guidance. You will evaluate vulnerabilities using CVSS scoring and business context, prioritize remediation based on risk and asset criticality, and collaborate with threat intelligence teams to incorporate emerging threat data. Vulnerability Researcher Delta Dental Ins. | USA | Remote – No longer accepting applications As a Vulnerability Researcher, you will conduct research to identify high-impact, previously unknown vulnerabilities across a wide range of applications and technologies, including AI-enabled systems. You will perform vulnerability assessments using industry best practices across web applications, APIs, and cloud environments.
helpnetsecurity.comMar 24, 2026extracted
SailPoint improves visibility and control over unauthorized AI use
SailPoint improves visibility and control over unauthorized AI use SailPoint has announced the launch of SailPoint Shadow AI Remediation, the latest component of its real-time AI governance and security framework. This solution enables organizations to discover, monitor, and secure the use of unauthorized AI tools, known as “shadow AI,” helping to mitigate the security and compliance risks associated with the rapid growth of artificial intelligence. As employees turn to AI platforms like ChatGPT, Claude, Gemini, and others to enhance productivity, they often do so outside of approved IT channels. This “shadow AI” introduces a critical challenge for enterprises: creating a significant blind spot and loss of control for security leaders over how employees interact with these platforms. SailPoint Shadow AI Remediation addresses this by providing real-time visibility into how employees use these tools, including monitoring document uploads and interaction frequency. This capability is crucial in an environment where, according to a report that was recently published, 80% of organizations report their AI agents have performed unintended actions, such as accessing or sharing inappropriate data. SailPoint Shadow AI Remediation helps organizations: Gain real-time visibility into shadow AI usage: Organizations gain immediate visibility into how employees are utilizing unmonitored AI tools. This visibility tackles the critical risk of sensitive data exposure from employees unknowingly uploading confidential files into unapproved AI models. Enable proactive remediation and centralized oversight: Security teams are empowered to actively prevent misuse by blocking unauthorized uploads, redirecting users to sanctioned AI tools, or prompting them for business justification. This centralized oversight helps reduce security gaps and promotes compliance in an increasingly AI-driven world. Facilitate easy deployment with minimal user impact: Designed for an effortless rollout, the solution can be deployed via a simple browser extension using standard device management tools like Intune or JAMF, requiring no networking or infrastructure updates. This allows for implementation of applicable security measures without disrupting the end-user experience. “Many vendors are trying to solve the shadow AI problem with isolated browser or endpoint tools, but that misses the bigger picture. This is fundamentally an identity challenge,” said Chandra Gnanasambadam, EVP of Product and Chief Technology Officer at SailPoint. “We believe controlling AI usage is best achieved through a platform-centric approach that unifies identity, data, and security intelligence in real-time. Our real-time AI governance and security framework is built on this principle. By linking human and non-human identities, we provide the context needed to not just see shadow AI, but to govern it effectively. Shadow AI delivers robust real-time visibility, proactive remediation, and seamless deployment, all deeply integrated with the SailPoint Platform,” Gnanasambadam added. The release of Shadow AI Remediation is an important milestone for SailPoint’s real-time AI governance and security framework. This framework unifies Agent Identity Security, Machine Identity Security, Data Access Security, and now Shadow AI Remediation to provide a holistic approach to securing AI. By integrating AI tool usage activity into SailPoint’s Identity Security Cloud, organizations can enrich their identity graph, adding important context that enables more intelligent decisions about access and risk. We believe SailPoint’s platform-centric approach, which links human and non-human identities with data and security intelligence, uniquely positions the company to help businesses navigate the complexities of AI security.
helpnetsecurity.comMar 17, 2026extracted
AWS Security Hub is expanding to unify security operations across multicloud environments
AWS Security Hub is expanding to unify security operations across multicloud environments After talking with many customers, one thing is clear: the security challenge has not gotten easier. Enterprises today operate across a complex mix of environments, including on-premises infrastructure, private data centers, and multiple clouds, often with tools that were never designed to work together. The result is enterprise security teams spend more time managing tools than managing risk, making it harder to stay ahead of threats across an increasingly complex environment. At Amazon Web Service (AWS), we believe security should be simple, integrated, and built for the way enterprises actually operate. This belief is what drove us to reimagine AWS Security Hub, delivering full-stack security through a single experience, and this vision is driving our next chapter. Building on a foundation of unified security We transformed Security Hub into a unified security operations solution by bringing together AWS security services, including Amazon GuardDuty, Amazon Inspector, AWS Security Hub Cloud Security Posture Management (Security Hub CSPM), and Amazon Macie, into a single experience that automatically and continuously analyzes security signals across threats, vulnerabilities, misconfigurations, and sensitive data. Security Hub delivers a common foundation, bringing together findings from across your AWS environment so your security team spends less time translating signals and more time acting on them. Built on top of that foundation, a unified operations layer gives security teams near real-time risk analytics, automated analysis, and prioritized insights, helping them focus on what matters most, at scale. We also introduced new capabilities (the Extended plan) that simplify how enterprises procure, deploy, and integrate a full-stack security solution across endpoint, identity, email, network, data, browser, cloud, AI, and security operations. Now, customers can use Security Hub to expand their security portfolio through a curated selection of AWS Partner solutions (at launch: 7AI, Britive, CrowdStrike, Cyera, Island, Noma, Okta, Oligo, Opti, Proofpoint, SailPoint, Splunk (a Cisco company), Upwind, and Zscaler), all through one unified experience. With AWS as the seller of record, you benefit from pay-as-you-go pricing, a single bill, and no long-term commitments. Our goal is simple: unified security, everywhere your enterprise operates. Freedom to innovate, wherever your workloads are At AWS, interoperability means giving customers the freedom to choose solutions that best suit their needs, and the ability to use them wherever their workloads run. But freedom to innovate across multicloud environments also means that it is critical to secure them consistently, and without adding operational complexity. What’s coming for Security Hub In the coming months, we are expanding Security Hub with new multicloud capabilities that extend unified security operations beyond AWS. The foundation of this expansion is a common data layer that unifies security signals from wherever your workloads run. On top of that, a unified policy and operations layer delivers consistent posture management, exposure analysis, and risk prioritization, so your security team operates from a single view of risk rather than a fragmented collection of consoles. Security Hub will deliver unified risk analytics that surface critical risks across your multicloud estate. You’ll be able to manage cloud security posture with Security Hub CSPM checks that give you consistent posture visibility, and extend vulnerability management with expanded Amazon Inspector capabilities, including virtual machine scanning, container image scanning, and serverless scanning. Security Hub will also deliver external network scanning that enriches security findings with context about internet-facing exposure across your multicloud environment, including for resources not running in AWS. The result is more comprehensive risk coverage across your enterprise. It’s about giving your security team a single, unified experience to detect and respond to risks, wherever you operate. Security as a business enabler The security leaders I speak with aren’t just asking for better tools. They’re asking for a way to get ahead of risk, not just manage it. They want security that keeps pace with the business, not security that slows it down. That’s the vision behind AWS Security Hub: unified security through a single, integrated security operations experience, built on a common data foundation, powered by intelligent analytics, and delivered through a consistent operations layer, to help reduce security risk, improve team productivity, and strengthen security operations across AWS and beyond. Our multicloud expansion is underway, and we are just getting started. You can learn more at aws.amazon.com/security-hub, or visit us at the AWS booth (S-0466) at RSA Conference, March 23–26 in San Francisco.
aws.amazon.comMar 10, 2026extracted
SailPoint expands AI-powered identity security with adaptive identity framework
SailPoint expands AI-powered identity security with adaptive identity framework SailPoint announced significant advancements to its AI-powered SailPoint Platform, introducing the first in a series of capabilities that advance its adaptive identity vision, an approach designed to address the critical security challenges of IT environments. New features include: Privilege: SailPoint is delivering total visibility into privilege risk with the launch of privilege discovery and classification and privilege insights, new foundational capabilities that automatically discover, classify, and provide the intelligence to secure privileged access across the enterprise. Non-human identities: New connectors for SailPoint Agent Identity Security can discover and govern AI agents from platforms like Microsoft 365 Co-Pilot and Databricks, in addition to Amazon Bedrock, Google Vertex AI, Microsoft Foundry, Salesforce Agentforce, ServiceNow AI Platform, and Snowflake Cortex AI. Additionally, SailPoint Machine Identity Security is enhanced with full lifecycle management for traditional machine accounts. Agents: The new agent for SailPoint Harbor Pilot, SailPoint’s suite of AI-powered agents designed to revolutionize how SailPoint Identity Security Cloud customers manage their programs, transforms a historically complex process into a simple, guided conversation. It enables users to request access in a simple, guided conversation. Advancements to SailPoint Observability & Insights and SailPoint Data Access Security: New advanced Observability & Insights features deliver direct privilege visibility and risk detection within the SailPoint Identity Graph, identity comparisons, and advanced operational intelligence across all identities. SailPoint is also integrating Data Access Security with the Identity Graph to visualize data access pathways, expand context for identity and data access, and add new capabilities to map and manage sensitive data exposure. Modernization: A next-generation Access Certification engine and a comprehensive Separation of Duties (SoD) revamp, demonstrating a commitment to rebuilding foundational governance capabilities for performance, scale, and modern user experiences. These will be available in the second half of 2026. Identity governance, which relies on slow, manual reviews, can no longer keep pace with the speed of cloud adoption, the explosion of AI and machine identities, and the sophistication of modern threats. “The old way of identity governance is simply no longer effective. It’s not enough to rely on static, after-the-fact reviews in today’s dynamic threat landscape,” said Chandra Gnanasambandam, SailPoint EVP of Product and Chief Technology Officer. “As a market leader, we are moving toward a new, AI-powered adaptive approach to provide continuous visibility and real-time governance for all identity types, including AI identities, machines, agents, and credentials. This year, we aim to help our customers move to least privilege or zero standing privilege. It’s about truly securing the business, not just checking a box, at the speed that AI-driven enterprises demand,” Gnanasambandam continued. SailPoint’s adaptive identity framework is built on four key pillars: Real-time governance: Shifting from periodic reviews to continuous, automated governance that can detect, prevent, and remediate risk the moment it appears. Protecting AI and machines: Extending identity security beyond human users to the rapidly growing population of non-human identities, including AI agents, service accounts, and machine workloads. Universal and dynamic privilege: Reducing the risk of standing privilege by providing Just-in-Time (JIT) access across all enterprise environments, ensuring identities only have the specific access they need, for the minimum time required. Integrated threat management: Bridging the critical gap between identity management and the Security Operations Center (SOC) by correlating identity context with threat signals to detect and respond to threats faster. “Leveraging SailPoint’s AI capabilities, TMF Group has elevated identity governance into a fully automated, intelligence‑driven capability ensuring consistent compliance across 87 jurisdictions while supporting secure global growth,” said Saurabh Gugnani, Senior Director, Global Head, Cybersecurity Engineering, Architecture & Projects at TMF Group.
helpnetsecurity.comMar 10, 2026extracted
AWS Expands Security Hub Into a Cross-Domain Security Platform
AWS has launched a new version of its Security Hub that solves the massive workload involved in cross domain security solution correlation and management. The original AWS Security Hub was announced in 2018, designed to aggregate and prioritize alerts from AWS and third-party security tools. In late 2025, AWS announced a ‘re-imagined’ Security Hub. It unified several of its own security tools, including Inspector and GuardDuty, effectively into a mini-SOC. Inspector is vulnerability scanning; GuardDuty is threat detection. In the re-imagined Security Hub, they can now integrate under a single pane of glass to map activity against vulnerabilities to highlight the most urgent threats and help customers prioritize and respond to their most critical security risks. Now, in early 2026, AWS announced Security Hub Extended. This allows customers to bring third party solutions into the same mini-SOC. It is, writes AWS, “A plan of Security Hub that simplifies how you procure, deploy, and integrate a full-stack enterprise security solution across endpoint, identity, email, network, data, browser, cloud, AI, and security operations.” For now, this full integration is limited to a range of curated vendors, selected from AWS customers’ own preferences. The current vendors include 7AI, Britive, CrowdStrike, Cyera, Island, Noma, Okta, Oligo, Opti, Proofpoint, SailPoint, Splunk, Upwind, and Zscaler. The intent is to offer integrated full stack security within AWS. “The selection was customer-driven,” explains Michael Fuller, director of security services at AWS. “Over the last four months, we went directly to our largest and fastest-growing enterprise customers and asked them which specific solutions they wanted us to prioritize in each category for the initial launch. We are committed to listening to customers and expanding the partner set over time.” The integration is made possible by the partner vendors all providing their findings in the open cybersecurity schema framework (OCSF). The data brought into the Security Hub Extended framework is consequently pre-normalized, and Security Hub Extended can perform instant and automatic cross-domain correlation to detect and highlight more granular threats. The new Hub goes beyond simplifying output correlation – it also simplifies product management whenever one of the partner vendors is used. AWS becomes the seller of record, and no matter how many of the partner vendors are used, there is only one invoice combined within the single AWS monthly bill. “AWS is the seller of record, with pre-negotiated pricing and a single bill covering all selected curated partner solutions,” explains Fuller. “Customers select only the solutions they need. A customer using multiple curated partner solutions would pay for each solution selected.” But always within the single invoice. He continues, “Security Hub Extended plan offers flexible pay-as-you-go pricing with no upfront investments and no long-term commitments. Flat-rate pricing is also available.” Customers are not required to use third-party vendors from the curated partners list. “Security Hub already supports multiple third-party partner integrations through its standard program,” adds Fuller, “so a customer’s existing vendor can already send findings into Security Hub today.” But this would require additional work from the customer and would not qualify for the single invoice structure. The triple benefit of Security Hub Extended is intended to be an easier correlation of security findings within the Hub’s mini SOC offering automated and improved full stack security; no additional coding required from the customer; and drastically reduced administrative overhead in finding, negotiating and on-going payment for multiple separate third party solutions. Related: Hundreds of FortiGate Firewalls Hacked in AI-Powered Attacks: AWS Related: AWS Trusted Advisor Tricked Into Showing Unprotected S3 Buckets as Secure Related: AWS Launches Incident Response Service Related: AWS Using MadPot Decoy System to Disrupt APTs, Botnets
securityweek.comMar 2, 2026extracted
Identity Security: Your First and Last Line of Defense
The danger isn’t that AI agents have bad days — it’s that they never do. They execute faithfully, even when what they’re executing is a mistake. A single misstep in logic or access can turn flawless automation into a flawless catastrophe. This isn't some dystopian fantasy—it's Tuesday at the office now. We've entered a new phase where autonomous AI agents act with serious system privileges. They execute code, handle complex tasks, and access sensitive data with unprecedented autonomy. They don't sleep, don't ask questions, and don't always wait for permission. That's powerful. That's also risky. Because today's enterprise threats go way beyond your garden-variety phishing scams and malware. The modern security perimeter? It's all about identity management. Here's the million-dollar question every CISO should be asking: Who or what has access to your critical systems, can you secure and govern that access, and can you actually prove it? How identity became the new security perimeter Remember those old-school security models built around firewalls and endpoint protection? They served their purpose once — but they weren’t designed for the distributed, identity-driven threats we face today. Identity has become the central control point, weaving complex connections between users, systems, and data repositories. The 2025-2026 SailPoint Horizons of Identity Security report shows that identity management has evolved from a back-office control to mission-critical for the modern enterprise. The explosion of AI agents, automated systems, and non-human identities has dramatically expanded our attack surfaces. These entities are now prime attack vectors. Here's a sobering reality check: Fewer than 4 in 10 AI agents are governed by identity security policies, leaving a significant gap in enterprise security frameworks. Organizations without comprehensive identity visibility? They're not just vulnerable—they're sitting ducks. The strategic goldmine of mature identity security But here's where it gets interesting. Despite these mounting challenges, there's a massive opportunity for organizations that get identity security right. The Horizons of Identity Security report reveals something fascinating: Organizations consistently achieve their highest ROI from identity security programs compared to every other security domain. They rank Identity and Access Management as their top-ROI security investment at twice the rate of other security categories. Why? Because mature identity security pulls double duty—it prevents breaches while driving operational efficiency and enabling new business capabilities. Organizations with mature identity programs, especially those using AI-driven capabilities and real-time identity data sync, show dramatically better cost savings and risk reduction. Mature organizations are four times more likely to have AI-enabled capabilities like Identity Threat Detection and Response. The great identity divide Here's where things get concerning: There's a growing chasm between organizations with mature identity programs and those still playing catch-up. The Horizons of Identity Security report shows that 63% of organizations are stuck in early-stage identity security maturity (Horizons 1 or 2). These organizations aren't just missing out—they are facing more risk against modern threats. This gap keeps widening because the bar keeps rising. The 2025 framework added seven new capability requirements to address emerging threat vectors. Organizations that aren't advancing their identity capabilities aren't just standing still—they're effectively moving backward. Organizations experiencing capability regression show significantly lower adoption rates for AI agent identity management. This challenge goes beyond just technology. Only 25% of organizations position IAM as a strategic business enabler—the rest see it as just another security checkbox or compliance requirement. This narrow view severely limits transformative potential and keeps organizations vulnerable to sophisticated attacks. Time for a reality check The threat landscape is evolving at breakneck speed, with unprecedented risk levels across all sectors. Identity security has evolved from just another security component into the core of enterprise security. Organizations need to honestly assess their readiness for managing extensive AI agent deployments and automated system access. A proactive assessment of your current identity security posture provides critical insight into organizational readiness and competitive positioning. Ready to dive deeper? Get the full analysis and strategic recommendations in the 2025-2026 SailPoint Horizons of Identity Security report.
thehackernews.comOct 17, 2025extracted
Identity management was hard, AI made it harder
Identity management was hard, AI made it harder Identity security is becoming a core part of cybersecurity operations, but many organizations are falling behind. A new report from SailPoint shows that as AI-driven identities and machine accounts grow, most security teams are not prepared to manage them at scale. This gap creates new risks and makes identity security harder to deploy across global enterprises. Investments in IAM provide the highest perceived ROI when compared to all other security domains (Source: SailPoint) Most organizations are still at early maturity levels The study, based on a global survey of 375 identity and access management (IAM) leaders, found that the majority of organizations are still in the early stages of building mature identity programs. Sixty-three percent remain in the two lowest maturity categories, relying on manual processes and basic tools to manage user access. Only a small percentage have reached higher maturity levels where identity controls are automated and adaptive. These advanced organizations use real-time risk data and AI to manage access dynamically, but they are the minority. Technology and financial services companies are more likely to have reached these levels, while healthcare, manufacturing, and many organizations in Europe and Latin America continue to lag. Progress is uneven. For every three organizations that advanced their identity capabilities in the past year, two regressed. This backward movement does not always reflect reduced effort. Instead, the bar for higher maturity has risen as new requirements, such as AI agent lifecycle management, have been added. AI-driven identity management and the rise of machine identities The report highlights a shift in identity management priorities. In the past, identity security mainly focused on human users such as employees and contractors. Now, machine identities and AI agents are growing faster than any other type of identity. These non-human identities often operate without consistent governance, creating blind spots for security teams. Less than four in ten organizations currently govern AI agents, even though they are expected to expand over the next three to five years. Managing these identities requires different approaches. Just-in-time access, dynamic privilege adjustments, and continuous monitoring are becoming essential. Without these controls, machine identities can accumulate excessive permissions or remain active after they are no longer needed, creating opportunities for attackers. Why deployments fall short Even when organizations invest heavily in identity security, many struggle to see results. Deployment problems are a common barrier. Only 14 percent of respondents said their most recent IAM deployment was completely successful. Almost half reported projects that ran over budget, and 60 percent said deployments missed timelines by at least a month. One of the biggest challenges is application onboarding. At lower maturity levels, teams often lack visibility into all their applications and attempt to onboard too many at once, leading to gaps and errors. As organizations mature, the complexity increases. Advanced organizations have 3.6 times more applications to manage than those at lower maturity levels, with each requiring tailored integrations and governance policies. Data quality is another issue. Identity data is often fragmented across HR systems, cloud services, and directories. Poor data hygiene undermines access controls and slows automation efforts. Organizations that clean and standardize identity data before deploying new tools are far more likely to succeed. Building for the future The report shows that advanced organizations are moving toward identity systems that are both adaptive and automated. AI plays a growing role in these systems, handling tasks such as real-time privilege adjustments, anomaly detection, and automated remediation. To move in this direction, organizations need to strengthen the basics first. Unified identity data is essential. So are structured deployment processes that prioritize critical applications first and establish governance for both human and non-human identities. “Identity is the central control point where policies are enforced, critical decisions are made, and security operations converge. Its future is tightly connected to security and AI-driven data governance, enabling enterprises to manage every identity—human, machine or AI agent—across the enterprise. With advances in AI, data management, and threat detection, modern identity security now delivers the unified visibility, expanded governance, and automated resilience organizations need,” said Matt Mills, President, SailPoint.
helpnetsecurity.comSep 8, 2025extracted
SailPoint Accelerated Application Management simplifies app governance
SailPoint Accelerated Application Management simplifies app governance SailPoint unveiled SailPoint Accelerated Application Management, a solution that redefines how enterprises discover, govern, and secure applications at scale. While most organizations govern fewer than 50 applications, thousands more remain outside governance, creating serious risk. SailPoint’s new approach represents a strategic shift: combining intelligence with expert-led deployment to deliver coverage and compliance at a fraction of the cost and complexity of competing solutions, delivering value while setting a new market standard. Today, many organizations connect only a subset of their applications to identity security tools. Traditional connectors, while comprehensive, are complex – often requiring deep application knowledge, lengthy manual processes and outside consultants. This leaves critical applications unmanaged, risks unidentified, and threats unaddressed. Visibility alone is not enough; without the intelligence to pinpoint the highest-risk applications and the governance automation to remediate them, organizations remain exposed. SailPoint Accelerated Application Management delivers a solution that combines application intelligence with systematic governance. Built on top of SailPoint’s Atlas platform, it unites continuous application discovery, zero-touch onboarding, risk-based prioritization, and automated governance workflows to reduce risk and scale coverage. With AI-driven insights and automation, organizations can go further—enforcing policies, streamlining remediation, automating privileged tasks, and even leveraging intelligent recommendations for faster decision-making. The result: immediate compliance wins for high-impact applications and the ability to bring hundreds of apps under governance in days, not months—dramatically reducing cost, time, and effort. In connection with announcing this new offering, SailPoint has entered into an agreement to acquire key assets from Savvy. Savvy provides best-in-class SaaS application visibility and monitoring, while guiding users in real-time with a focus on identity risks and insider threats. Following a successful completion of the contemplated acquisition, which remains subject to customary closing conditions, SailPoint intends to integrate the acquired Savvy technology with SailPoint’s offerings to deliver unparalleled application visibility and intelligence to customers. “If you can’t see every application, you can’t protect it—but visibility alone is not enough,” said Chandra Gnanasambandam, CTO and EVP of Product, SailPoint. “Our customers need the intelligence to understand where their greatest risks lie, paired with automation that systematically closes those gaps. With SailPoint Accelerated Application Management, they get both—accelerating time-to-value while strengthening their security posture.” Introducing SailPoint Accelerated Application Management SailPoint Accelerated Application Management delivers three progressive capabilities designed to scale with organizational maturity to: Enable application visibility and intelligence: provides continuous application discovery, revealing inventory, ownership, user activities, and risky access patterns across the enterprise. The platform automatically identifies compromised passwords and delivers risk-based prioritization to focus governance efforts on highest-impact applications. Facilitate quicker compliance: enables zero-touch application onboarding via Express Setup, rapidly deploying access reviews, least privilege enforcement, automated leaver workflows, and audit-ready reporting without traditional implementation delays. Deepen governance: supports advanced automation including automated provisioning and deprovisioning, full identity lifecycle management, self-service capabilities, and AI-driven policy enforcement with Separation of Duties controls. Expert-led service offerings that eliminate implementation barriers SailPoint’s robust service offerings include expert-led deployment with dedicated service delivery teams, reducing the need for specialized internal resources or data engineering expertise. To meet organizations where they are, the service is offered in two packages—providing fast visibility for immediate needs, with a path to deeper governance as programs mature. Ongoing expert support facilitates successful implementation and long-term optimization. “Enterprises don’t just need faster onboarding—they need a smarter foundation for long-term resilience and growth,” continued Gnanasambandam. “By embedding intelligence into application management, we’re enabling organizations to secure more, scale faster, and turn identity into a true driver of business agility.” Availability SailPoint Accelerated Application Management is available immediately.
helpnetsecurity.comAug 21, 2025extracted
As AI grows smarter, your identity security must too
As AI grows smarter, your identity security must too AI is no longer on the horizon, it’s already transforming how organizations operate. In just a few years, we’ve gone from isolated pilots to enterprise-wide adoption. According to a recent SailPoint survey, 82% of companies are running AI agents today, often across multiple business functions. These agents aren’t just passive tools; they’re autonomous systems that act, decide, and adapt at remarkable speed and scale. These systems now handle responsibilities once reserved for skilled human oversight, delivering efficiency and innovation at a pace we’ve never seen before. But with that power comes new complexity. Nearly 9 out of 10 companies say their AI agents have already taken unintended actions—from accessing sensitive systems to sharing data without authorization. These AI agents can operate independently and learn, adapt, and interact in ways that are hard to predict. Without strong governance, they can introduce serious vulnerabilities into even the most secure environments. At SailPoint, we believe securing AI agents starts with securing identity. It’s no longer just about “who” can access what. It’s about “what” is acting inside your environment, “how” it’s doing so, and “why.” Proper governance means tracking every AI agent’s access to sensitive data, assigning clear ownership, and enforcing approval workflows before granting or expanding access. Yet only 44% of organizations have formal governance policies for AI agents, and just 52% can track the data these agents touch or share. That’s a governance gap where significant risk can slip through. That’s the type of challenge SailPoint was built to address. Our Identity Security Cloud governs every identity—human or non-human—at enterprise scale. Harbor Pilot, our embedded AI-powered identity security agent, extends that governance with intelligence: recommending access decisions, flagging anomalies, automating repetitive tasks, and learning from context to improve over time. Unlike broad-purpose AI agents, Harbor Pilot is purpose-built to strengthen identity security from within. Delivering this level of security globally takes reach and reliability, and that’s where our alliance with AWS becomes so important, underpinned by our long-standing strategic collaboration agreement (SCA) that has resulted in many co-built solutions. Our partnership and roadmap are rooted in a shared vision: enable enterprises to innovate faster while maintaining security and compliance at scale. Together, we’ve expanded our cloud footprint to serve customers wherever they operate, including new AWS-based SailPoint SaaS instances in Dubai, across APAC, and most recently in Brazil to meet regional data residency requirements. In the U.S. public sector, our FedRAMP-authorized solutions run on AWS to provide secure, compliant identity governance for government agencies. In the AI space, our collaboration extends even deeper. We leverage AWS services like Amazon Bedrock—using Anthropic’s Claude to automatically generate SaaS connector code—to speed integrations while maintaining governance at the core. And with SailPoint Identity Security Cloud and Harbor Pilot now available in the AWS AI Marketplace, enterprises can embed intelligent identity governance directly into the same environment where much of their AI innovation already lives. This integration means customers can move faster without sacrificing control, tapping into the scale, resilience, and security of AWS while deploying SailPoint’s identity-first approach. The stakes are high. Twenty-three percent of organizations have experienced exposed credentials from AI agents, and 60% have had agents access privileged data—often without oversight. Yet, 98% plan to expand AI agent deployments in the next year. Without the right identity security in place, they’ll be scaling not just innovation, but also risk. The smarter AI gets, the more human its risks become. At SailPoint, we’re helping organizations govern these new identities from the ground up—with the precision, speed, and trust they need to move forward with confidence. If your organization is embracing AI, now is the time to make identity security part of that journey. You can explore SailPoint Identity Security Cloud and Harbor Pilot in the AWS AI Marketplace to see firsthand how intelligent identity governance can integrate seamlessly into your existing AWS environment. The future of AI is already here. The question is whether your identity security is ready to keep up.
helpnetsecurity.comAug 19, 2025extracted