𝐑𝐞𝐬𝐩𝐨𝐧𝐬𝐞 𝐝𝐨𝐞𝐬𝐧’𝐭 𝐬𝐭𝐨𝐩 𝐢𝐧 𝐭𝐡𝐞 𝐰𝐨𝐫𝐬𝐭-𝐜𝐚𝐬𝐞 𝐬𝐜𝐞𝐧𝐚𝐫𝐢𝐨; 𝐢𝐭 𝐬𝐭𝐨𝐩𝐬 𝐰𝐡𝐞𝐧 𝐲𝐨𝐮’𝐫𝐞 𝐮𝐩 𝐚𝐧𝐝 𝐫𝐮𝐧𝐧𝐢𝐧𝐠 𝐚𝐠𝐚𝐢𝐧. I’ve followed Felix Gaehtgens — since his early Gartner days — and always valued his sharp industry insights (even when I didn’t fully agree). So when he sat down with Martin Kuppinger, another respected expert, I knew I had to tune in. A few key #ITDR (Identity Threat Detection and Response) takeaways: • 𝐕𝐢𝐬𝐢𝐛𝐢𝐥𝐢𝐭𝐲 𝐯𝐬. 𝐎𝐛𝐬𝐞𝐫𝐯𝐚𝐛𝐢𝐥𝐢𝐭𝐲: Felix highlights an important gap. Solutions often offer either visibility or observability, but organizations need both. You need to reduce attack surface 𝘣𝘦𝘧𝘰𝘳𝘦 an incident and also detect and contain threats 𝘥𝘶𝘳𝘪𝘯𝘨 an attack. • 𝐈𝐓𝐃𝐑 𝐮𝐧𝐝𝐞𝐫 𝐭𝐡𝐞 𝐂𝐈𝐒𝐎: There’s a positive trend I took away from #Gartner research: about 30% of companies now have IAM reporting to the CISO (up from <10% when Semperis started). I’ve long believed ITDR needs to sit with, or be championed by, security leadership. • 24𝐱7 𝐑𝐞𝐬𝐩𝐨𝐧𝐬𝐞 & 𝐀𝐮𝐭𝐨𝐦𝐚𝐭𝐢𝐨𝐧: While ITDR enables real-time detection, IAM teams can’t always respond instantly, especially when facing a new generation of AI threats. SOC teams might have some identity expertise, but it’s rarely enough. The answer? More automation. The critical decisions during an incident should be handled by the system, not delayed by waiting for an expert. • 𝐓𝐡𝐞 𝐌𝐢𝐬𝐬𝐢𝐧𝐠 ‘𝐑’ 𝐢𝐧 𝐈𝐓𝐃𝐑: Felix rightly notes many solutions lack true response capabilities. At Semperis, we’ve been advocating for ITDR that goes beyond detection, with a customizable response matrix: disabling compromised accounts, alerting SOCs, undoing malicious changes, and fully restoring a trustworthy identity system. Simply put: “Response” isn’t just what you do in the moment, it’s how you get back to business, safely and confidently. More thoughts on #NHI in my next post and link to the podcast in the first comment.
10000%
Good to see more companies having IAM reporting to the CISO, especially as organizations take on non-human identities as well.
CEO at Semperis | Be a Force for Good
1mohttps://www.linkedin.com/posts/kuppingercole_itdr-machine-identities-nhis-rethinking-activity-7368228808765628416-Q-B-?utm_source=share&utm_medium=member_desktop&rcm=ACoAAACax1MBdH8zGZDtOPvdtUAaqP-NHP9NWSc