Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

SailPoint: Adaptive Identity as the New Cybersecurity Control Plane

Sailpoint
06/21/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


about SailPoint and SailPoint's products. Joining me today is Matt Mills, president of SailPoint. Matt, super excited to have you on the show. Welcome. Yeah, dude, I'm thrilled to be here. Awesome. I watch your show. Oh, thank you. And I kept wondering, like, I wonder if he's ever going to call. And now here I am. I took too long to call. So obviously, Matt, we're here at Navigate 2025. Very exciting week. Just very exciting. A lot of great announcements. You announced a lot of things on stage. And so I'm going to kind of jump in. I think you've seen the show. We kind of just dive right into the conversation. So given the speed of technology and technology change we've experienced, how are organizations currently struggling to keep their identity security strategies aligned with this evolving threat landscape? Yeah, look, I think it is the most challenging of times. And I don't think it's any single thread, right? I think these companies are, I mean, just start with people, right? Being able to hire, retain, enable top talent. And then you sit here and think about the threat landscape. We're all excited about all the AI and the agents, right? But so are the bad guys, right? And they're using the same tools against us. And so it puts us in what feels to me like perpetual state of chaos, right? And then I think the other thing I would add, James, is that even folks that are on modern platforms, they're not accelerating as much as maybe we had hoped, right? In terms of, you know, I'll just use our Horizon study, right, as a barometer. But still over 60% of these organizations are sitting in Horizon 1 or Horizon 2, right? And so if they're going to sit there, they're going to find themselves in harm's way and not able to use some of these new technologies. And the last piece I would add, you know, is look, today there's certain applications that use agents. Yeah. Tomorrow, I think virtually every application out there is going to have to use some form of agents, right? Yes. Or they're going to be completely disenfranchised. So I think this problem with agents is going to be exacerbated, and I think companies are really going to be pushed to get to that what we call Horizon 3, right? Yeah, at least three. Yeah, at least three. At least three. So you mentioned agents. And so, you know, with that explosion of digital identities that we're talking about, from human users to non-humans, how do you see the attack surface expanding? And what are the most critical blind spots organizations have when it comes to securing this breadth of identities that we have? Yeah. Look, I think the first big challenge is just going to be the idea of I don't know what I don't know, right? Yeah. Absolutely. So it's this discovery process. Yes. And so, and I think, you know, we've got that in place for machines. Yes. And so, you know, with what we announced this week, we have it in place for the base agents. Right. And I think that's going to go a long way in helping companies and CISOs and CIOs alike to understand what am I dealing with here, not only in machines, but also agents. I gave a little bit of an example the other day about a CIO who had, you know, some number of agents running unbeknownst to her or any of their team, right? Right. And that's a pretty common item that these folks are starting to find out about, you know, as they start to poke at it. Absolutely. Yeah. And so, you know, I'm going to pivot. You've seen them. I like to pivot. So why do you believe that identity security, it has emerged as the foundational pillar of a cybersecurity strategy? Yeah. I mean, look, for years, we kind of thought if we have this perimeter set, right? The firewall. And then if we kept all the bad guys on the other side of it, we were good. Yeah. And now what's happened is that the bad guys have found a way that would attack us from the inside out. Exactly. Right? And so I think we say like the bad guys used to come and kick the front door in, right? And now they get your credentials and they might be sitting right next to you. Yeah. Exactly. And so I think that's kind of changed the overall perimeter. And so now it's kind of an inside out defense. Yeah. Right. And to be fair, I don't think you can completely say I don't need the perimeter anymore. I think you got to have it all. Yeah. But man, I think the identity space from everything we see, it is where it's all happening. Absolutely. So one thing we talked about, well, excuse me, you talked about this week in Navigate is around adaptive identity. So can you kind of walk us through what do you mean by adaptive identity? You mentioned three core components of this trifecta. Yeah. Yeah. I mean, look, what it really is about is context. Yes. Right. And I use the example to me. It's a pretty simple one, so everybody can follow along, right? And it's, you know, we know John, John has access, and we give John ability to enter the room. Right. Right. Right. In the new modern world, right, we got to be smarter than that. So we've got to say, yes, I do know John, right, and John does have access, but John's on a new device. Yes. It's three o'clock in the morning. Yes. And he's in another country. Yeah. Right. That's context. Yes. And now with that context, I say, I don't think John's getting access. Right. At least not right now. Right. Right. Right. And so that's kind of the picture. And then you say, well, how do we do that? Well, it's this trifecta. Mm-hmm. The trifecta of identity. Yes. Data. Yep. And then, and security. Right. Right. So you have to have those. And I think the term we use is control plane. Yes. So it's the new control plane for the modern enterprise. Right. Right. And if you have that, then you have context. Yes. And with that context now, I get a lot smarter. And look, here's the other thing I would add. I think in this new world of agentic AI, I don't think it's one of these niceties. I think it is absolutely something these companies have to have if they're going to try to be secure, and they're going to be able to use some of these emerging technologies that we're talking about. Right. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. I agree. So we're on the last one. All right. All right. So only five questions. So looking at the vision for a unified platform, what specific innovations that we've been talking about are you most excited about? Well, look, this isn't necessarily new to us, right? Right. We've been building this literally for the last couple decades, right? Exactly. One of the things that entitles us to say, you know, you should buy from us, right, is the fact that, you know, we've got two decades of experience and breadth of context. And I think the real outcome here is everything kind of becomes real time. I get asked a lot, so is governance going away? Governance is not going away. It's just going to manifest itself very differently. Exactly. And we're going to be in a world where we've got to have real time. Yes. Right? And we've got to have authorization across every identity and system that allows us to really and truly embrace zero trust and zero standing privilege. Yeah. Because I think that's the end of the game. Yeah. Awesome. Matt, thank you so much for joining. All right, man. I'm sad we waited so long to get you on the show. Yeah. Well, look, I'm here. I'm ready to go again. Just call. Don't worry. We will. We will. Thank you for having me, buddy. Absolutely. Appreciate it. Thank you to everyone watching and listening today. If you'd like to learn more about some of the new innovations we've talked about, join us at salepoint.com.

TL;DR

  • Cybersecurity has shifted from perimeter defense to inside-out threats, making identity security the foundational pillar as attackers now compromise credentials rather than breaking through firewalls.
  • Adaptive identity provides context-aware access control by evaluating the trifecta of identity, data, and security — assessing not just who requests access but device, location, timing, and other contextual signals.
  • The explosion of AI agents across applications will exacerbate identity challenges, requiring organizations to advance to what SailPoint calls Horizon 3 maturity with real-time governance and zero standing privilege.
  • SailPoint announced new discovery capabilities for both machine identities and AI agents at Navigate 2025, addressing the critical blind spot of unknown identities operating within enterprise environments.

The Shift to Inside-Out Defense

In this Navigate 2025 interview, SailPoint President Matt Mills discusses the fundamental transformation in cybersecurity strategy from perimeter-based defense to identity-centric security. Mills explains that traditional perimeter defenses, while still necessary, are no longer sufficient as threat actors have shifted tactics to attack organizations from the inside out using compromised credentials. This evolution has positioned identity security as the foundational pillar of modern cybersecurity, requiring organizations to adopt what SailPoint calls adaptive identity — a context-aware approach that evaluates not just who is requesting access, but the circumstances surrounding that request including device, location, and timing.

Adaptive Identity and the Agentic AI Challenge

Mills introduces adaptive identity as a trifecta of identity, data, and security that creates a new control plane for the modern enterprise. Using a practical example, he illustrates how adaptive identity goes beyond simple authentication to evaluate contextual signals — if a user attempts access from a new device, at an unusual time, from an unexpected location, the system can intelligently deny or challenge that request. This capability becomes critical as organizations face the explosion of AI agents, which Mills predicts will become ubiquitous across virtually every application. SailPoint's recent announcements at Navigate 2025 include discovery capabilities for both machine identities and AI agents, addressing what Mills identifies as a fundamental challenge: organizations don't know what they don't know about their expanding identity landscape.

Chapters

0:00 - Introduction
0:52 - Current Identity Security Challenges
2:39 - Expanding Attack Surface
4:53 - Identity as Foundational Pillar
4:58 - Adaptive Identity Explained
6:40 - Unified Platform Vision

Key Quotes

1:42 "It puts us in what feels to me like perpetual state of chaos, right? ..."
2:22 "Tomorrow, I think virtually every application out there is going to have to use some form of agents, right? Or they're going to be completely disenfranchised."
4:19 "The bad guys have found a way that would attack us from the inside out."
6:05 "It's the new control plane for the modern enterprise."

FAQ

What is adaptive identity and how does it differ from traditional identity management?

Adaptive identity is a context-aware approach that evaluates access requests based on multiple signals beyond just authentication. Rather than simply verifying that a user has valid credentials, adaptive identity assesses contextual factors like device, location, time of day, and behavioral patterns. For example, if a legitimate user attempts access from a new device at 3 AM from another country, the system can intelligently deny or challenge that request. This represents a shift from static access control to dynamic, risk-based decision-making.

Why is identity security now considered the foundational pillar of cybersecurity?

Identity has become foundational because the attack vector has fundamentally changed. Traditional perimeter defenses assumed threats came from outside the network, but modern attackers compromise credentials and operate from inside the organization. This inside-out attack pattern means that identity becomes the new perimeter — the critical control point for determining who and what can access resources. While perimeter defenses remain important, identity security is now the primary battleground where breaches are prevented or enabled.


Categories:
  • » Cybersecurity » Identity & Access Management (IAM)
  • » Cybersecurity » Zero Trust
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Identity & Access
  • Zero Trust
  • AI & Machine Learning
  • Security Operations
  • Executive Briefing
  • Adaptive Identity
  • Identity Security
  • AI Agents
  • Machine Identities
  • Context-Aware Access Control
  • Inside-Out Defense
  • Identity Governance
  • Zero Standing Privilege
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: SailPoint: Adaptive Identity as the New Cybersecurity Control Plane

              XStreaminars (watch here)

              • Jul
                28

                Illumio + Netskope: Zero Trust in the Age of AI Autonomy

                07/28/202601:00 PM ET
                • Jul
                  29

                  Ask Your Cloud Anything: Unlocking Governance Silos in your Environments

                  07/29/202601:00 PM ET
                  More events

                  Industry Events (watch there)

                  • Jul
                    14

                    Crafting a Championship-Caliber Security Team for Lasting Defense

                    07/14/202601:00 PM ET
                    • Jul
                      14

                      Understanding the Crucial Role of Context in Safeguarding AI-Accessible Data

                      07/14/202602:00 PM ET
                      • Jul
                        22

                        Insights from Attackers During the FIFA World Cup: A HUMAN Dialogue

                        07/22/202601:00 PM ET
                        More events

                        Upcoming Webinar Calendar

                        • 07/14/2026
                          01:00 PM
                          07/14/2026
                          Crafting a Championship-Caliber Security Team for Lasting Defense
                          https://www.truthinit.com/index.php/channel/2025/crafting-a-championship-caliber-security-team-for-lasting-defense/
                        • 07/14/2026
                          02:00 PM
                          07/14/2026
                          Understanding the Crucial Role of Context in Safeguarding AI-Accessible Data
                          https://www.truthinit.com/index.php/channel/2037/understanding-the-crucial-role-of-context-in-safeguarding-ai-accessible-data/
                        • 07/21/2026
                          04:00 AM
                          07/21/2026
                          Strategies for Managing AI Governance and Securing App-to-LLM API Traffic
                          https://www.truthinit.com/index.php/channel/1967/strategies-for-managing-ai-governance-and-securing-app-to-llm-api-traffic/
                        • 07/22/2026
                          06:30 AM
                          07/22/2026
                          Insights and Strategies in Data Protection and Privacy Management
                          https://www.truthinit.com/index.php/channel/2000/insights-and-strategies-in-data-protection-and-privacy-management/
                        • 07/22/2026
                          01:00 PM
                          07/22/2026
                          Insights from Attackers During the FIFA World Cup: A HUMAN Dialogue
                          https://www.truthinit.com/index.php/channel/2029/insights-from-attackers-during-the-fifa-world-cup-a-human-dialogue/
                        • 07/28/2026
                          01:00 PM
                          07/28/2026
                          Illumio + Netskope: Zero Trust in the Age of AI Autonomy
                          https://www.truthinit.com/index.php/channel/2031/illumio-netskope-zero-trust-in-the-age-of-ai-autonomy/
                        • 07/29/2026
                          04:00 AM
                          07/29/2026
                          Real-Time Strategies for Safeguarding Against Prompt Injections
                          https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
                        • 07/29/2026
                          01:00 PM
                          07/29/2026
                          Ask Your Cloud Anything: Unlocking Governance Silos in your Environments
                          https://www.truthinit.com/index.php/channel/2048/ask-your-cloud-anything-unlocking-governance-silos-in-your-environments/
                        • 08/19/2026
                          12:00 PM
                          08/19/2026
                          Becoming Agent Ready: Insights from Cyera's Expertise
                          https://www.truthinit.com/index.php/channel/2036/becoming-agent-ready-insights-from-cyeras-expertise/
                        • 09/02/2026
                          12:00 PM
                          09/02/2026
                          Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                          https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                        • 09/30/2026
                          04:00 AM
                          09/30/2026
                          AI Command Center: Optimizing Visibility and Control in Your Operations
                          https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version