Security management

Insights

Blog

Announcing The Forrester Wave™ For Microsegmentation Solutions, Q3 2026: Not Your Parents’ Access Control Solution

James Plouffe 1 day ago
For as long as I’ve been in cybersecurity, we’ve been trying to “adapt to the shifting threat landscape.” More recently, a number of vendors and security leaders alike have told me some version of a joke about how starting a microsegmentation project is a great way to get fired. But this is a market that […]
Blog

The Capital Connection: Exploring Washington, DC During Security & Risk Forum 2026

Forrester 1 day ago
Security & Risk Forum 2026 brings security, risk, and resilience leaders to Washington, DC, a city where technology, governance, security, and public trust intersect every day. From iconic landmarks and Smithsonian museums to neighborhood cafes and networking-worthy restaurants, explore what to see and do while you’re in the nation’s capital.

Secure AI Agents Before You Scale

Scaling AI agents shouldn’t mean scaling exposure. Download Forrester’s AEGIS playbook to set guardrails on intent, authority, and access so that adoption stays accountable, auditable, and defensible.

Blog

The First Principles Of Cybersecurity Still Apply

Paddy Harrington 3 days ago
As cyberthreats evolve and AI accelerates attacker capabilities, the most effective defenses remain the foundational practices many organizations overlook. Learn why recent attacks on critical infrastructure reinforce the need to focus on basic security principles before investing in new technologies.
Blog

The Customer Identity And Access Management Solutions Landscape, Q3 2026 Is Live

Andras Cser August 13, 2026
The 2026 installment of the customer identity and access management (CIAM) landscape report has just published. The report identifies three primary drivers in the CIAM landscape. AI agents are a new identity type in CIAM. In our research, we found that CIAM solutions are increasingly enabling organizations to: Properly manage inbound access of customers’ AI […]
Blog

Bringing Crypto Agility And PQC Visibility To The Network With NAV

Jitin Shabadu August 12, 2026
The Q4 2025 Forrester Wave™ evaluation for network analysis and visibility (NAV) solutions was the first iteration of the research to evaluate vendors on their post-quantum cryptography (PQC) capabilities, a decision that has become more pronounced in 2026. The rationale was compelling then; it is unavoidable now. Most notably, the US federal government has moved […]
Blog

OpenAI Makes Hardware Passkeys Mandatory For Its Highest-End Cyber Model

Andras Cser July 31, 2026
In April 2025, OpenAI announced that it will require its users to complete formal, government-issued, national ID document-based identity verification (IDV). Now OpenAI has announced that, effective September 1, 2026, Trusted Access for Cyber (TAC) accounts will be required to authenticate using hardware passkeys to access OpenAI’s most advanced cyber AI models. This capability will […]
Blog

An AI Security Facepalm: OpenAI’s Evaluation Became Hugging Face’s Incident

Jeff Pollard July 22, 2026
When an AI evaluation becomes a real-world security incident, leaders can no longer view model testing as a low-risk exercise. The OpenAI and Hugging Face incident reveals how agentic AI can cross trust boundaries, exploit vulnerabilities, and create business risk long before deployment.

Save 10% On Our Technology & Innovation Forums This Summer

Register by September 4 to lock in summer advantage savings — 10% off your ticket to our Technology & Innovation Forums in Austin, New York City, or London. Turn ideas into action with frameworks and strategies you can use immediately.

Blog

Microsoft Makes Passkeys Default: What Identity And Security Leaders Need To Do

Geoff Cairns July 16, 2026
Microsoft’s decision to make passkeys the default authentication method in Entra ID signals a broader industry shift: phishing-resistant authentication is no longer optional. Identity and security leaders should use this moment to accelerate passkey adoption, reduce reliance on vulnerable MFA methods, and align authentication strategies with Zero Trust principles.
Blog

Use 2027 Budget Optimism To Drive An AI Reset

Sharyn Leaver July 14, 2026
Budget optimism is rising as 2027 approaches — but more spend alone won’t improve outcomes. Use this moment to reset your AI investments. Prioritize the readiness, governance, and context required to make it truly work.
Blog

Quantum Negligence On The Clock: The US Just Set The Egg Timer On Quantum Migration As An Enterprise Risk

Alla Valente July 2, 2026
The question is no longer whether organizations should prepare for the quantum era, but how they will prove that they acted in time. New US guidance elevates post-quantum cryptography migration from a technology initiative to a board-level risk management responsibility.
Blog

Identiverse 2026 Recap: Identity Security For Agentic AI Dominates

Andras Cser June 25, 2026
Last week’s Identiverse conference in Las Vegas left no doubt that the scope and importance of identity security is now magnified. Identiverse 2026 underscored the current transition in identity security as organizations grapple with an expanding universe of identities beyond humans. As Ping Identity CEO Andre Durand framed it in his opening keynote, the industry […]
Blog

Announcing The Forrester Wave™ On Extended Detection And Response Platforms: Platformization, AI, And … AI

Allie Mellen June 25, 2026
Last week, Forrester released The Forrester Wave™: Extended Detection And Response Platforms, Q2 2026. This is the third iteration of the extended detection and response (XDR) Wave, with prior versions published in 2021 and 2024. This Wave differs significantly from the past, especially because of: The number of vendors. This year, only seven vendors were […]

Save 10% On B2B Forum EMEA This Summer

Register by September 4 to lock in summer advantage savings — 10% off your ticket to B2B Forum EMEA (28–29 Sept, London). Leave with a plan to win in the GTM singularity as AI‑driven buyers rewrite the rules.

Blog

Use The New Executive Order As A Canary For Enterprise PQC Migration And Procurement

Heidi Shey June 24, 2026
On June 22, 2026, the White House issued a new executive order (EO), Securing the Nation Against Advanced Cryptographic Attacks. While it has direct implications for federal agencies, there are parts that are worth paying attention to for enterprise security and risk leaders. Here’s what’s worth your attention, whether or not you hold a federal […]
Blog

New Executive Order Makes PQC Migration A Multiyear Operational Program For Federal Security Leaders

Heidi Shey June 24, 2026
For a private-sector CISO, a new US executive order (EO), Securing the Nation Against Advanced Cryptographic Attacks, is an additional signal and call to action. For federal security leaders, it’s an order with your name on it. The recap on what to do is short: Inventory your cryptography, name someone to run the migration, and […]
Blog

AI Is Moving Fast, But Trust Is Struggling To Keep Up: Why Security And Risk Leaders Can’t Miss Forrester’s AI Forum

Jinan Budge June 24, 2026
AI adoption is accelerating, but confidence in its outcomes isn’t. At Forrester’s AI Forum 2026, security and risk leaders will learn how to shift from traditional protection to a trust-and-assurance mandate — with practical frameworks, real-world perspectives, and strategies to secure an increasingly agentic enterprise while enabling innovation.
Blog

The EU’s Digital Markets Act Meets The Mobile OS, Round Two

Paddy Harrington June 24, 2026
Tensions between regulators and mobile platform leaders are raising a critical question: How far should openness go when it could expose users to new risks? This blog explores the trade-offs between device freedom, platform safeguards, and the growing security implications of AI-powered assistants.
Blog

Total Recall: A Cautionary Fable Of Anthropic And The US Government

Jeff Pollard June 15, 2026
On Friday, June 12, the same model class covered by our previous blog post went dark. Anthropic suspended Fable 5 and Mythos 5 worldwide after the US Department of Commerce issued an export control directive, which led to requests from prominent cybersecurity pros to undo the action. The bypass that triggered the export controls, per […]

Save 10% On Security & Risk Forum This Summer

Register by September 4 to lock in summer advantage savings — 10% off your ticket to Security & Risk Forum (Nov 9–10, Washington, DC). Leave ready to act with real‑world security and risk frameworks.

Blog

How Fable 5 And Mythos 5 Change AI Security, Data Retention, And Vendor Risk

Jeff Pollard June 10, 2026
Anthropic’s Fable 5 and Mythos 5 is the most 2026 product launch you’ll read this year. The same model can find nation-state zero days, design novel drug candidates, and play FireRed on a Gameboy Advance with nothing but screenshots. And for the gaming fans out there, yes, we got Fable 5 before Fable 4. These […]
Blog

Announcing The Forrester Wave™: Workforce Identity Security Platforms, Q2 2026

Geoff Cairns May 21, 2026
Our latest evaluation of workforce identity security providers, The Forrester Wave™: Workforce Identity Security Platforms, Q2 2026 is now available! Workforce identity security is now a strategic pillar of modern cybersecurity, driven by the expansion of nonhuman identities, increasingly sophisticated identity‑based attacks, and the operational demands of Zero Trust. Organizations already grappling with identity sprawl across […]
Blog

Announcing Forrester’s 2026 Security & Risk Enterprise Leadership Award

Stephanie Balaouras May 18, 2026
Have a great story about leveraging security, privacy, and risk management to drive trust, resilience, and responsible innovation? We'd love to hear from you.
More posts