Estimated reading time: 5 minutes · Last updated:
A contributed industry report brought together vendor perspectives from Keeper Security, Cribl, Automox, Nisos, Surf AI, Adaptive Security, Red Sift, Asimily, SentinelOne and CrowdStrike to map how core cybersecurity segments are changing in 2026. The piece argues that attackers now move across identities, software and infrastructure, driving a shift from point controls to continuous monitoring, stricter access governance and faster automated response. The vendors highlighted in the report illustrate three practical moves organisations are making: tighten identity and least-privilege controls, route and reshape telemetry before it reaches tools, and apply AI inside security operations to reduce human toil.
Managing multiple disconnected tools is itself a security liability.
Darren Guccione, CEO & Co-Founder, Keeper Security
Key takeaways
- Identity: Keeper Security frames identity as a primary boundary and urges continuous governance for human and non-human identities.
- Telemetry: Cribl recommends routing, shaping and reusing telemetry to improve signal quality across security toolchains.
- Human risk: Nisos positions human risk intelligence as a complement to technical controls for threats involving employees, executives and third parties.
- AI-native ops: SentinelOne describes AI as a way to accelerate investigations while preserving human judgement in the SOC.
Table of contents
- Key takeaways
- Why identity is now a control plane for security
- Telemetry and data: quality over quantity
- Human risk and social engineering are a technical problem too
- AI-native operations, endpoints and cloud converge on speed
- Where this trend could head next
- What to be careful about
- Frequently asked questions
Why identity is now a control plane for security
Identity has moved from being one control among many to a primary surface that attackers exploit as organisations expand cloud services, automation and machine identities. Keeper Security and others in the report argue that teams must shift from periodic access reviews to continuous governance and least-privilege enforcement for both people and services.
That change means treating identity tooling and secrets management as first-order infrastructure: access requests, credential issuance and non-human agent permissions must be observable and revocable in real time. Where organisations still run separate, disconnected identity tools, vendors warn that those gaps create chains of trust that attackers can abuse.
Practically, teams adopt runtime identity controls, step-up authentication for sensitive actions and automated deprovisioning tied to HR and asset systems. Those moves aim to shorten the window between exposure—an issued credential or misconfigured role—and corrective action under operational control.
Telemetry and data: quality over quantity
Security teams are collecting far more telemetry than they can meaningfully use. Cribl’s contribution stresses that ingesting raw volume is not the same as visibility; the emphasis is on routing, reshaping and retaining the right signals so downstream tools can act efficiently.
That approach breaks telemetry work into three tasks: decide which streams to forward, normalize schema and enrich events with context, and apply retention policies that balance investigation needs against cost. Organisations experimenting with AI also require provenance and data-quality controls so models do not learn from noisy or biased telemetry.
Teams that centralise these functions reduce alert noise and speed up investigations because correlation and enrichment happen before analysts or detection engines see the events, not after. Vendors in the report position telemetry management as an enabler of scalable detection rather than a raw-input problem.
Human risk and social engineering are a technical problem too
The report’s vendors treat social engineering, impersonation and insider risk as problems that intersect with technical controls rather than stand-alone HR issues. Nisos and Adaptive Security outline how identity attribution, digital investigations and continuous, personalised simulations strengthen detection of targeted fraud and deepfake-enabled attacks.
Human risk intelligence combines external investigation, attribution work and evidence about candidates, vendors and executives to reveal attack paths that conventional scanners miss. That intelligence is then fed into runtime controls and user-specific interventions—blocking suspicious workflows, enforcing step-up checks or isolating accounts when behaviour diverges from a baseline.
Because attackers increasingly blend voice, video and text impersonation, defenders pair continuous simulation exercises with signal-based controls that operate across email, DNS and web infrastructure so an impersonation attempt can be interrupted before it becomes a compromise.
AI-native operations, endpoints and cloud converge on speed
Across endpoints, cloud and the SOC, vendors emphasise speed: reduce time to detect, investigate and remediate. SentinelOne frames AI as a force multiplier for investigations, while Automox focuses on continuous patching and automated remediation to shrink exposure windows on endpoints.
CrowdStrike and others highlight identity-driven lateral movement in cloud environments, urging unified controls that link identity, endpoint telemetry and cloud posture so defenders see attack chains rather than isolated alerts. For connected devices, Asimily warns that visibility must lead to enforced controls as fleets grow.
Together these changes aim to close the operational loop: discovery, prioritisation, automated mitigation and verification. The common theme is removing manual handoffs and letting fast, verified controls interrupt attacker progress at scale.
| Segment | Vendor | Core focus |
|---|---|---|
| Identity | Keeper Security | Continuous governance and least-privilege for human and non-human identities |
| Telemetry | Cribl | Routing, shaping and reuse of telemetry for downstream tools |
| Endpoint | Automox | Continuous patching, configuration and automated remediation |
| Human risk | Nisos | Investigative human risk intelligence and attribution |
| Exposure management | Surf AI | Prioritising exposures and linking weaknesses to owners and actions |
| Human security | Adaptive Security | Continuous, personalised simulations across email, voice and video |
| Email & domain | Red Sift | Visibility across email, DNS, certificates and domains |
| Connected devices | Asimily | Fleet visibility and enforced controls for medical and IoT devices |
| AI-native ops | SentinelOne | AI-assisted investigation and evidence connection in the SOC |
| Cloud | CrowdStrike | Unified protection tying identity, endpoint and cloud telemetry |
Where this trend could head next
The case for
- Faster containment as telemetry shaping and AI-assisted investigations reduce mean time to remediate.
- Reduced impersonation success through combined domain, DNS and certificate monitoring that ties internet-facing trust signals together.
- Operational control for machine identities and AI agents, cutting days or weeks from deprovisioning and credential rotation workflows.
The case against
- If telemetry pipelines are misconfigured, AI models and detection rules may learn from noisy data and produce misleading priorities.
- Widespread reliance on automation could create systemic failure modes if remediation playbooks are incomplete or improperly scoped.
- Privacy and governance friction may slow identity telemetry sharing between teams, leaving gaps defenders cannot see in real time.
What to be careful about
- Overreliance on vendor AI without data-quality controls that ensure models are trained on representative telemetry.
- Fragmented ownership where identity, cloud and endpoint teams do not share the same incident response runbooks.
- Automated remediation that lacks safe rollback or verification, risking operational disruption when controls misfire.
The bottom line
The vendor perspectives assembled in the contributed report point to a consistent operational shift in 2026: security teams tie identity, telemetry and automated controls together to interrupt attacker progress faster. That shift favours organisations that treat data quality and ownership as infrastructure, who pair identity governance with runtime enforcement and who adopt AI with clear provenance and rollback paths. The near-term challenge is practical: stitch teams and pipelines so automated mitigations are safe, observable and reversible, or risk automation creating new systemic outages rather than preventing breaches.
What to watch
- Watch for publication details and any technical appendices for the full vendor report; no date has been set.
- Watch for the Validation Summit ’26 listings referenced in site resources; no date was provided in the piece.
- Watch for webinars on AI agent governance and runtime identity controls promoted on the same site; no date has been set.
Frequently asked questions
How are vendors defining identity changes in 2026?
Vendors such as Keeper Security urge continuous governance and least-privilege for both human and non-human identities, moving away from periodic reviews to runtime controls and automated deprovisioning.
What does 'telemetry shaping' mean for security operations?
Cribl describes telemetry shaping as routing, normalising and enriching event streams so downstream detection and AI models see higher-quality signals rather than raw volume.
Will AI replace SOC analysts according to the vendors?
No; SentinelOne and other contributors present AI as a tool to accelerate investigations and reduce manual work while keeping final judgement and complex decisions with human analysts.
Related reading