Security management
Insights
Blog
Announcing The Forrester Wave™ For Microsegmentation Solutions, Q3 2026: Not Your Parents’ Access Control Solution
For as long as I’ve been in cybersecurity, we’ve been trying to “adapt to the shifting threat landscape.” More recently, a number of vendors and security leaders alike have told me some version of a joke about how starting a microsegmentation project is a great way to get fired. But this is a market that […]
Blog
The Capital Connection: Exploring Washington, DC During Security & Risk Forum 2026
Security & Risk Forum 2026 brings security, risk, and resilience leaders to Washington, DC, a city where technology, governance, security, and public trust intersect every day. From iconic landmarks and Smithsonian museums to neighborhood cafes and networking-worthy restaurants, explore what to see and do while you’re in the nation’s capital.
Secure AI Agents Before You Scale
Scaling AI agents shouldn’t mean scaling exposure. Download Forrester’s AEGIS playbook to set guardrails on intent, authority, and access so that adoption stays accountable, auditable, and defensible.
Blog
The First Principles Of Cybersecurity Still Apply
As cyberthreats evolve and AI accelerates attacker capabilities, the most effective defenses remain the foundational practices many organizations overlook. Learn why recent attacks on critical infrastructure reinforce the need to focus on basic security principles before investing in new technologies.
Blog
The Customer Identity And Access Management Solutions Landscape, Q3 2026 Is Live
The 2026 installment of the customer identity and access management (CIAM) landscape report has just published. The report identifies three primary drivers in the CIAM landscape. AI agents are a new identity type in CIAM. In our research, we found that CIAM solutions are increasingly enabling organizations to: Properly manage inbound access of customers’ AI […]
Blog
Bringing Crypto Agility And PQC Visibility To The Network With NAV
The Q4 2025 Forrester Wave™ evaluation for network analysis and visibility (NAV) solutions was the first iteration of the research to evaluate vendors on their post-quantum cryptography (PQC) capabilities, a decision that has become more pronounced in 2026. The rationale was compelling then; it is unavoidable now. Most notably, the US federal government has moved […]
Blog
OpenAI Makes Hardware Passkeys Mandatory For Its Highest-End Cyber Model
In April 2025, OpenAI announced that it will require its users to complete formal, government-issued, national ID document-based identity verification (IDV). Now OpenAI has announced that, effective September 1, 2026, Trusted Access for Cyber (TAC) accounts will be required to authenticate using hardware passkeys to access OpenAI’s most advanced cyber AI models. This capability will […]
Blog
An AI Security Facepalm: OpenAI’s Evaluation Became Hugging Face’s Incident
When an AI evaluation becomes a real-world security incident, leaders can no longer view model testing as a low-risk exercise. The OpenAI and Hugging Face incident reveals how agentic AI can cross trust boundaries, exploit vulnerabilities, and create business risk long before deployment.
Save 10% On Our Technology & Innovation Forums This Summer
Register by September 4 to lock in summer advantage savings — 10% off your ticket to our Technology & Innovation Forums in Austin, New York City, or London. Turn ideas into action with frameworks and strategies you can use immediately.
Blog
Microsoft Makes Passkeys Default: What Identity And Security Leaders Need To Do
Microsoft’s decision to make passkeys the default authentication method in Entra ID signals a broader industry shift: phishing-resistant authentication is no longer optional. Identity and security leaders should use this moment to accelerate passkey adoption, reduce reliance on vulnerable MFA methods, and align authentication strategies with Zero Trust principles.
Blog
Use 2027 Budget Optimism To Drive An AI Reset
Budget optimism is rising as 2027 approaches — but more spend alone won’t improve outcomes. Use this moment to reset your AI investments. Prioritize the readiness, governance, and context required to make it truly work.
Blog
Quantum Negligence On The Clock: The US Just Set The Egg Timer On Quantum Migration As An Enterprise Risk
The question is no longer whether organizations should prepare for the quantum era, but how they will prove that they acted in time. New US guidance elevates post-quantum cryptography migration from a technology initiative to a board-level risk management responsibility.
Blog
Identiverse 2026 Recap: Identity Security For Agentic AI Dominates
Last week’s Identiverse conference in Las Vegas left no doubt that the scope and importance of identity security is now magnified. Identiverse 2026 underscored the current transition in identity security as organizations grapple with an expanding universe of identities beyond humans. As Ping Identity CEO Andre Durand framed it in his opening keynote, the industry […]
Blog
Announcing The Forrester Wave™ On Extended Detection And Response Platforms: Platformization, AI, And … AI
Last week, Forrester released The Forrester Wave™: Extended Detection And Response Platforms, Q2 2026. This is the third iteration of the extended detection and response (XDR) Wave, with prior versions published in 2021 and 2024. This Wave differs significantly from the past, especially because of: The number of vendors. This year, only seven vendors were […]
Save 10% On B2B Forum EMEA This Summer
Register by September 4 to lock in summer advantage savings — 10% off your ticket to B2B Forum EMEA (28–29 Sept, London). Leave with a plan to win in the GTM singularity as AI‑driven buyers rewrite the rules.
Blog
Use The New Executive Order As A Canary For Enterprise PQC Migration And Procurement
On June 22, 2026, the White House issued a new executive order (EO), Securing the Nation Against Advanced Cryptographic Attacks. While it has direct implications for federal agencies, there are parts that are worth paying attention to for enterprise security and risk leaders. Here’s what’s worth your attention, whether or not you hold a federal […]
Blog
New Executive Order Makes PQC Migration A Multiyear Operational Program For Federal Security Leaders
For a private-sector CISO, a new US executive order (EO), Securing the Nation Against Advanced Cryptographic Attacks, is an additional signal and call to action. For federal security leaders, it’s an order with your name on it. The recap on what to do is short: Inventory your cryptography, name someone to run the migration, and […]
Blog
AI Is Moving Fast, But Trust Is Struggling To Keep Up: Why Security And Risk Leaders Can’t Miss Forrester’s AI Forum
AI adoption is accelerating, but confidence in its outcomes isn’t. At Forrester’s AI Forum 2026, security and risk leaders will learn how to shift from traditional protection to a trust-and-assurance mandate — with practical frameworks, real-world perspectives, and strategies to secure an increasingly agentic enterprise while enabling innovation.
Blog
The EU’s Digital Markets Act Meets The Mobile OS, Round Two
Tensions between regulators and mobile platform leaders are raising a critical question: How far should openness go when it could expose users to new risks? This blog explores the trade-offs between device freedom, platform safeguards, and the growing security implications of AI-powered assistants.
Blog
Total Recall: A Cautionary Fable Of Anthropic And The US Government
On Friday, June 12, the same model class covered by our previous blog post went dark. Anthropic suspended Fable 5 and Mythos 5 worldwide after the US Department of Commerce issued an export control directive, which led to requests from prominent cybersecurity pros to undo the action. The bypass that triggered the export controls, per […]
Save 10% On Security & Risk Forum This Summer
Register by September 4 to lock in summer advantage savings — 10% off your ticket to Security & Risk Forum (Nov 9–10, Washington, DC). Leave ready to act with real‑world security and risk frameworks.
Blog
How Fable 5 And Mythos 5 Change AI Security, Data Retention, And Vendor Risk
Anthropic’s Fable 5 and Mythos 5 is the most 2026 product launch you’ll read this year. The same model can find nation-state zero days, design novel drug candidates, and play FireRed on a Gameboy Advance with nothing but screenshots. And for the gaming fans out there, yes, we got Fable 5 before Fable 4. These […]
Blog
Announcing The Forrester Wave™: Workforce Identity Security Platforms, Q2 2026
Our latest evaluation of workforce identity security providers, The Forrester Wave™: Workforce Identity Security Platforms, Q2 2026 is now available! Workforce identity security is now a strategic pillar of modern cybersecurity, driven by the expansion of nonhuman identities, increasingly sophisticated identity‑based attacks, and the operational demands of Zero Trust. Organizations already grappling with identity sprawl across […]
Blog
Announcing Forrester’s 2026 Security & Risk Enterprise Leadership Award
Have a great story about leveraging security, privacy, and risk management to drive trust, resilience, and responsible innovation? We'd love to hear from you.
More posts