Identity Security

Identity Security examines how enterprises protect human, machine, service, and AI identities across increasingly complex digital environments. Coverage includes IAM, privileged access, authentication, authorization, credentials, machine identities, AI agents, Zero Trust, identity-based attacks, and delegated authority—with a CISO focus on controlling who and what can access, decide, and act.
19
Aug
MCP Is Becoming Enterprise Infrastructure

MCP Is Becoming Enterprise Infrastructure

MCP is becoming enterprise infrastructure. As AI agents gain access to tools, identities and business systems, CISOs must govern not just integration — but the authority flowing through it.
15 min read
19
Aug
The Agent Is Becoming the New Privileged User

The Agent Is Becoming the New Privileged User

AI agents are becoming a new privileged identity class. The real security question is no longer what AI can know — but what it is authorized to do, through whose identity, and with what consequences.
14 min read
19
Aug
MCP Is Becoming an Attacker’s Routing Layer

MCP Is Becoming an Attacker’s Routing Layer

An AI agent’s real privilege extends far beyond its IAM permissions. MCP, managed identities and connected services create transitive authority paths that attackers can exploit—turning tool connectivity into a new routing layer for enterprise privilege.
17 min read
18
Aug
The Agent Is the New Attack Path

The Agent Is the New Attack Path

A safe model does not imply a safe agent. Agentic AI shifts the security problem from jailbreaks to authority: can an attacker make the system perform an authorized action for an unauthorized reason?
17 min read
18
Aug
When Data Becomes Instruction

When Data Becomes Instruction

AI agents are erasing the boundary between data and instruction. DEF CON 34 shows why untrusted context can become an indirect control plane—and why CISOs must secure the entire path from meaning to authority.
15 min read
28
Jul
AI Attacks in SAP RISE: The Visibility Problem Inside the Managed Cloud

AI Attacks in SAP RISE: The Visibility Problem Inside the Managed Cloud

SAP RISE changes who operates your ERP—but not who is accountable for its security. AI-driven attacks exploit fragmented visibility across cloud providers, identities, APIs, and contracts. The biggest detection gap may not be technical. It may already be written into your RISE agreement.
7 min read
27
Jul
AI-Driven Attacks on SAP: Why Generic Security Tools Will Miss the Business Impact

AI-Driven Attacks on SAP: Why Generic Security Tools Will Miss the Business Impact

6 min read
20
Jul
SAP RISE Is Never “Set and Forget”

SAP RISE Is Never “Set and Forget”

SAP RISE is not a project that ends at go-live. It is a continuously evolving operating model that requires permanent governance. This article explains why operational assurance—not implementation success—has become the defining responsibility of the modern CISO.
14 min read
18
Jul
Vendor Lock-In Is Not the Real Risk in SAP RISE - Loss of Control Is

Vendor Lock-In Is Not the Real Risk in SAP RISE - Loss of Control Is

17 min read
18
Jul
SAP RISE Is a Transfer of Control— Not Just a Cloud Transformation.

SAP RISE Is a Transfer of Control— Not Just a Cloud Transformation.

12 min read