Security management

Insights

Blog

The AI Doomsday Circus: Don’t “Step Right Up!”

Sharyn Leaver 15 hours ago
Don’t let AI doomsday headlines dictate your strategy. Stay grounded in what’s real, manage the risks you can control, and focus on the investments most likely to create new value.
Blog

Announcing The Forrester Wave™: Proactive Security Platforms, Q3 2026

Erik Nost 16 hours ago
Last week, we released The Forrester Wave™: Proactive Security Platforms, Q3 2026. This is the first evaluation of this market under this title, which has evolved from attack surface management and unified vulnerability management. Security teams have increasingly turned to vulnerability risk management, attack surface management, and exposure management to decide which weaknesses matter most. […]

Secure AI Agents Before You Scale

Scaling AI agents shouldn’t mean scaling exposure. Download Forrester’s AEGIS playbook to set guardrails on intent, authority, and access so that adoption stays accountable, auditable, and defensible.

Blog

Predictions 2027: It’s Going To Be Another “Hold My Beer” Kind Of Year For Security And Risk

James Plouffe 23 hours ago
AI failures, global outages, and physical disruptions will put security and risk leaders to the test in 2027. Explore three Forrester predictions and the steps organizations can take to strengthen governance, resilience, and readiness.
Blog

Manage Insider Risk To Protect Your Potential

Joseph Blankenship 2 days ago
National Insider Threat Awareness Month is drawing to a close. This year’s theme, “Protect Our Potential,” speaks directly to the impact that insider incidents can have. According to Forrester data, insider incidents account for 25% of data breaches, and a third of those incidents are due to malicious intent. Yet many organizations still don’t have […]
Blog

Context Is King: How Identity Context Will Drive Agentic AI Success

Andras Cser 7 days ago
AI agents are putting traditional identity and access management approaches to the test. Discover why identity context will be essential to securing autonomous agents and scaling agentic AI with confidence.
Blog

Announcing The Forrester Wave™: External Threat Intelligence Service Providers, Q3 2026

Jitin Shabadu September 22, 2026
Last week, Forrester published The Forrester Wave™: External Threat Intelligence Service Providers, Q3 2026. Since our last evaluation in 2023, the market has undergone a significant transformation. This transformation has been driven not only by the growing sophistication and breadth of threat intelligence requirements but also by the rapid adoption of agentic AI as organizations […]
Blog

The Information Security Leader’s Guide To Security & Risk Forum 2026

Forrester September 11, 2026
From securing AI and modernizing identity to strengthening governance and resilience, security leaders face a rapidly expanding mandate. See how Security & Risk Forum 2026 can help you stay ahead of emerging challenges.
Blog

OT Security’s Next Chapter Starts When Asset Discovery Stops Being The Goal

Paddy Harrington September 10, 2026
OT security has moved beyond simply identifying connected devices. Learn why leading organizations are shifting their focus toward reducing operational risk, strengthening resilience, and enabling safer IT and OT security collaboration.
Blog

Intent Is The New Epicenter Of Agentic Security

Jeff Pollard August 31, 2026
Cybersecurity spent decades trying to stop things from happening, identifying them, and then investigating what happened. Agentic AI challenges us with a much more difficult question: What was the system trying to do? Agents don’t just execute instructions. They interpret objectives, select tools, access data, cross systems, and change tactics. In most cases, a user […]
Blog

Announcing The Forrester Wave™ For Microsegmentation Solutions, Q3 2026: Not Your Parents’ Access Control Solution

James Plouffe August 20, 2026
For as long as I’ve been in cybersecurity, we’ve been trying to “adapt to the shifting threat landscape.” More recently, a number of vendors and security leaders alike have told me some version of a joke about how starting a microsegmentation project is a great way to get fired. But this is a market that […]
Blog

The Capital Connection: Exploring Washington, DC During Security & Risk Forum 2026

Forrester August 20, 2026
Security & Risk Forum 2026 brings security, risk, and resilience leaders to Washington, DC, a city where technology, governance, security, and public trust intersect every day. From iconic landmarks and Smithsonian museums to neighborhood cafes and networking-worthy restaurants, explore what to see and do while you’re in the nation’s capital.
Blog

The First Principles Of Cybersecurity Still Apply

Paddy Harrington August 18, 2026
As cyberthreats evolve and AI accelerates attacker capabilities, the most effective defenses remain the foundational practices many organizations overlook. Learn why recent attacks on critical infrastructure reinforce the need to focus on basic security principles before investing in new technologies.
Blog

The Customer Identity And Access Management Solutions Landscape, Q3 2026 Is Live

Andras Cser August 13, 2026
The 2026 installment of the customer identity and access management (CIAM) landscape report has just published. The report identifies three primary drivers in the CIAM landscape. AI agents are a new identity type in CIAM. In our research, we found that CIAM solutions are increasingly enabling organizations to: Properly manage inbound access of customers’ AI […]
Blog

Bringing Crypto Agility And PQC Visibility To The Network With NAV

Jitin Shabadu August 12, 2026
The Q4 2025 Forrester Wave™ evaluation for network analysis and visibility (NAV) solutions was the first iteration of the research to evaluate vendors on their post-quantum cryptography (PQC) capabilities, a decision that has become more pronounced in 2026. The rationale was compelling then; it is unavoidable now. Most notably, the US federal government has moved […]
Blog

OpenAI Makes Hardware Passkeys Mandatory For Its Highest-End Cyber Model

Andras Cser July 31, 2026
In April 2025, OpenAI announced that it will require its users to complete formal, government-issued, national ID document-based identity verification (IDV). Now OpenAI has announced that, effective September 1, 2026, Trusted Access for Cyber (TAC) accounts will be required to authenticate using hardware passkeys to access OpenAI’s most advanced cyber AI models. This capability will […]
Blog

An AI Security Facepalm: OpenAI’s Evaluation Became Hugging Face’s Incident

Jeff Pollard July 22, 2026
When an AI evaluation becomes a real-world security incident, leaders can no longer view model testing as a low-risk exercise. The OpenAI and Hugging Face incident reveals how agentic AI can cross trust boundaries, exploit vulnerabilities, and create business risk long before deployment.
Blog

Microsoft Makes Passkeys Default: What Identity And Security Leaders Need To Do

Geoff Cairns July 16, 2026
Microsoft’s decision to make passkeys the default authentication method in Entra ID signals a broader industry shift: phishing-resistant authentication is no longer optional. Identity and security leaders should use this moment to accelerate passkey adoption, reduce reliance on vulnerable MFA methods, and align authentication strategies with Zero Trust principles.
Blog

Use 2027 Budget Optimism To Drive An AI Reset

Sharyn Leaver July 14, 2026
Budget optimism is rising as 2027 approaches — but more spend alone won’t improve outcomes. Use this moment to reset your AI investments. Prioritize the readiness, governance, and context required to make it truly work.
Blog

Quantum Negligence On The Clock: The US Just Set The Egg Timer On Quantum Migration As An Enterprise Risk

Alla Valente July 2, 2026
The question is no longer whether organizations should prepare for the quantum era, but how they will prove that they acted in time. New US guidance elevates post-quantum cryptography migration from a technology initiative to a board-level risk management responsibility.
Blog

Identiverse 2026 Recap: Identity Security For Agentic AI Dominates

Andras Cser June 25, 2026
Last week’s Identiverse conference in Las Vegas left no doubt that the scope and importance of identity security is now magnified. Identiverse 2026 underscored the current transition in identity security as organizations grapple with an expanding universe of identities beyond humans. As Ping Identity CEO Andre Durand framed it in his opening keynote, the industry […]
More posts