Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Palo Alto Networks Launches Idera Identity Platform

Palo Alto Networks
08/04/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


All these agents need to be identified. All these agents need to be understood. All their data needs to be brought together. This is my eighth year in cybersecurity. I'm pretty sure many of you have spent more time in cybersecurity than I have. And eight years ago when I joined Palo Alto Networks, we were a firewall company. We used to sell the best firewalls you could find. But as I spent time trying to understand the industry, I realized we're one of the latest entrants into enterprise technology. Now AI has sort of taken over the charm, but at that point in time, we were the earliest entrants or latest entrants in the world of enterprise technology. And you realize when industries are formed, when they're early, you find a series of smart companies delivering amazing solutions in the market. But the plan doesn't emerge. And you've seen that happen in perhaps CRM, if you remember those things, they're called CRM, Salesforce, et cetera, you've seen that happen in ITSM or IT technology, you've seen that happen in HR technology, in financial technology. As time passes, all these amazing new features become commonplace. Everybody has them. As they become commonplace, the value of them together far supersedes the innovation in each one of them. What I'm trying to tell you is that in the early stages of an industry, the task of stitching and connecting various solutions belongs to the customer. As the industry evolves over 10, 15, 20 years, the task of stitching goes back to the industry partners, suppliers, vendors, whatever your favorite word is. And you've seen that in cybersecurity happen over the last seven years. You no longer buy individual features for small companies because it's very hard at the pace and the speed that cybersecurity is moving for our partners, our customers to actually take the time and stitch the data together, stitch the solutions together, and have possible solutions that actually prevent the act of bad actors. We came to the realization about three or four years ago when at Palo Alto, we had reached approximately 70 products, I realized even we had a hard time keeping it together in terms of how to go deliver, deploy, and make those products successful for our customers. We came upon this idea, which we were vilified originally for, called platformization. The principle of platformization is that let us do the stitching for you. We can take what our hardware firewalls do, we can take what our software firewalls do, we can take what our SASE product does, put them together with single control plane, a single deployment capability, a single set of policies, a common data lake underneath it, so we can actually act at machine learning speed. We did that for network security, we did that for the SOC, and we did that for cloud security. My view in the last seven years has always been every time you hit an inflection point in that particular sector in cybersecurity, things are going to change. All of you remember the inflection point and end points. There were industry leaders in the past called McAfee or Symantec, which did an amazing job, they actually protected many of our customers for many, many years, and suddenly you saw this wave of EDR and XDR arrive. The wave of EDR, XDR built new winners, like the CrowdStrikes of the world, the Sentinels ones, the Palo Altos, the Microsoft Defenders of the world. You saw as the inflection point hits, if the industry doesn't rally, if existing players don't rally, you see a shift because the new players have figured out something. If your customers in the room realize you hit a point, the inflection point is when it's worth ripping out the old technology because the new technology offers so much more features, I will go through the pain of taking out something else. That's kind of a failure on the part of our industry. We should never get it to a point where some other product is so much better than we deliver that you feel the need to take us out. That's the inflection point we at Palo Alto Networks look for because those inflection points allow us the opportunity to go ahead and fundamentally platformize our customers. We've seen that a few times in our life. We've seen that within Palo Alto Networks at, as I said, the hardware firewall. We actually were able to build software firewalls where we enjoy 50% market share thanks to our customers because we saw that trend first. We saw SASE flip during COVID from just being pure internet access to being comprehensive access for every employee, every application, every user where they are. Now we're the second largest player in SASE coming fast to trying to go be the industry leader in that space. We've seen the same happen in the SIM. If you were not a player in the SIM today, one of the top three players in the SIM category because we are able to provide real-time capability and protect our customers in real-time against bad actors with a median time to detect and remediate at Palo Alto, one minute. This is important because I'll come back to it. However, the industry still has a lot of vendors. We still discover when we go to one of our customers that on average their cybersecurity vendors are more than their technology vendors in their infrastructure, which doesn't make sense. Cybersecurity is about 8% of your spend and how can the number of vendors in cybersecurity be as many as your technology vendors, which means there's still further room for integration, for stitching, for things to work together better, faster. As we were thinking about this, we were wondering where the next inflection point in cybersecurity is going to arrive. We had avoided the space of identity because we felt identity was full of amazing players in the market and the identity problem was being solved for our customers by people like CyberArk, which is now a Palo Alto company, or people like Okta, perhaps, in the IAM space. As we spend more and more time to understand how identity is going to inflect and when, as we saw the beginnings of AI, we came to the realization that AI was going to create the inflection point for identity. If you think about what's going on, almost 90% of cybersecurity attacks originate from somebody. Credential thefts, credential hijacking, somebody posing as somebody else. What's fascinating is most organizations take anywhere from, if you're lucky, 48 hours to two weeks to actually build the identity graph of the individuals who have been compromised because the data is sitting in many different places. It's sitting in your IAM provider. It's sitting in your privileged access provider. It's sitting in a bunch of SaaS logs which belong to SaaS applications. It's sitting all over your enterprise in different systems. There's no way to actually collate that, collect that, build an identity graph, and understand what actually happened in infrastructure. Under that insight, we spent a lot of time trying to see who had the best position and where could we bring the concept of platformization to the market in partnership with and who could we do that with. I can't tell you how excited we are at Palo Alto Networks that we had the privilege of meeting the CyberArk team. We had the privilege of meeting the leadership of CyberArk, Udi and Matt and others. We reached a common understanding because the vision of both Palo Alto Networks and CyberArk were aligned. Our vision was that we need to bring innovation, we need to bring platformization, and we need to change how identity operates in the market of cybersecurity because that is the next inflection point in cybersecurity. I just want to give a big thank you and a round of applause to the CyberArk team in the room for choosing to be part of Palo Alto Networks. But that's not where it stops. If you think about cybersecurity, since I'm still learning my cybersecurity after seven or eight years, I appreciate P.D. calling me the influential person in cybersecurity and just hiding behind all these great people who work for me. So for me, cybersecurity is somewhat simplistic. If it's a bad guy, there are products that sit at the perimeter, and if you know it's bad, we stop them. If you've ever been stopped by getting into a building, they think you're a bad guy. We stop them at the beginning. That's the easy part of cybersecurity. All the action happens when the bad guy gets in. No breach happened because you stopped somebody at the door, I promise you, even though I understood that in seven years. All the breaches and attacks happen because something got past your perimeter defense. The moment something gets past your perimeter defense, how do you figure out how to solve the problem? All of you have this amazing thing called SOCs and you have all these analytic techniques and you have all these tools that you deploy to make sure that we're going to analyze all the stuff that's going on to figure out how to figure out if this is good or bad. So there's a second order of determination whether what's got in is good or bad, and if it's bad, how bad is it and how sure am I because if it's really bad and you're very sure you can stop it. If you're not quite sure, if it's not really bad, you don't want to bring the boss' laptop down because typically the phone calls from cyber teams and IT teams get is, why is this not working? I'm still waiting for a phone call to say, things are working great, thank you for doing what you do. So if you believe that that's what cybersecurity is, then how do we make sure that things that get through our perimeter can be analyzed, can be understood, and can be stopped with full certainty? That requires a lot more context. It requires a lot more understanding. It requires amazing perimeter defense. So if identity is one of the critical factors of the perimeter, it is very important that we continue to innovate and ensure that the perimeter of identity continues to be safe in the future. You will hear today from Perez and others on the team, how we're going to go take this innovation forward. We have spent a lot of time over the last few months getting to know the team, understanding, and actually aligning on a common vision, and we're going to talk about that in a bit. No discussion in technology is finished today without talking about the two alphabets which have overtaken our lives. How can we have a keynote without talking about AI? We should talk about AI. Sorry? And agents, we'll get to them. Don't speak my keynote, dude, give me a chance. So we have to talk about AI. Well, while we're busy thinking about identity platformization, this amazing thing shows up called AI. Now the only danger is we are all, and I say all because I think all the cool AI people are not in the room. They're busy writing code for building cloud code or building Anthropic. All of us have become very, very smart about AI very, very quickly, right? Because none of us grew up learning AI or the tools of cloud code, et cetera. We're all learning, we're all adapting to AI. But we're all smart people, we live in technology. If I told you that the largest technology companies in the world are going to spend $1 trillion in the next 12 months on something, whatever it is, we have to pay attention, right? $1 trillion is a lot of money, last I checked. So $1 trillion is going to be spent. If I tell you that there's probably 30 to 40% of the developer population already actively using AI to code, and that number is only going to rise. If I tell you that last night at the dinner in San Francisco, I just came last night, I was sitting across this person who had an undergraduate in economics, and I said, I was just chatting with him, of course, you can't have dinner without talking about AI. And he told me he's got OpenCloud running on his phone, and he's built an agent called Zara, and she's doing all the scheduling and sending all the emails. So the email I got from him about dinner was from Zara, because his Uber was late. So this is interesting. But when we take that and play that movie three to five years out, because remember, in technology, if you want to anticipate where you should be building product, is you have to play the movie three to five years out. You can't build for today. If you build for today, you're already late. But three to five years from now, every one of you is going to be using multiple agents of your own, acting on your behalf, whether it's in your personal device or your professional device. The world is going to be full of these agents. These are the easier agents. These are people who take our credentials and act on our behalf, and you can choose to restrict their ability to whatever you choose to allow them to do. My agent can book airline tickets but cannot book reservations for dinner because I hate what my agent picks. No problem. Right? So we are all going to have multiple agents floating around using our credentials, both in the personal world as well as the enterprise world. Guess what? I haven't met a systems integrator in the world who doesn't believe that they're going to create non-human agents for us. I will take 5,000 customer support people and turn them into 10,000 customer support agents that will solve your problem. You guys have heard this pitch? That company is raising billions of dollars on that pitch out there. So the world is going to be flooded with agents. The only difference is, with humans, you can hope for some human judgment when they see something wrong. Right? If a human sees something and says, eh, it doesn't look right, I can stop it. Agents will not. Maybe they will develop judgment and we won't be needed, but until then, we're going to have millions of agents floating around in the IT infrastructure. All these agents need to be identified. All these agents need to be understood. All their data needs to be brought together. All that data requires us to be able to analyze it and stop them from acting in a way that they shouldn't be acting. So I think the space of identity just became even more exciting after we made the decision to platformize identity from an inflection point perspective. And I don't think I can stand here and say we all know what the right answer is yet. And the reason I'm saying that is not because our teams are not working hard trying to figure out what the right answer is. We're anticipating scenarios to see how the world will operate, right? Six months ago, there was a different scenario. Six months ago, I heard about these browsers which are going to become agentic browsers and do a lot of work for you. Today, I don't hear much about agentic browsers because it's a little scary thought that the browser is going to take all my credentials and act on my behalf and I have no kill switch and no control capability. So the world is going to evolve. But what is clear in this evolution is that identity needs to evolve. The identity we had where we nicely put it in different boxes called, oh, this is called privileged identity, this is for really important people, this is called IAM or identity access management, it's for normal people. And now this is called NHI, non-human identity, it's for agents. So we had little boxes where we put all the different people, say, have a good time, don't get out of your box. Well, unfortunately, some of these people live across all boxes. They say, oh, but if you have a problem with the way you set up the posture, we'll create something called ISPM. And if you're really not managing it right, we'll create something called IGA governance. So we created these many three-letter, four-letter acronyms to bifurcate the identity business. At the end of the day, what do you want? I want to know who did it, how they did it, when they did it, where are they, and how do I kill that identity because it's going to be bad in my infrastructure. Sounds pretty straightforward. Well, that's the problem that the team from CyberArk is going to solve. As you know, that in any such coming together of two businesses, the power of the networks and CyberArk, you take the best of both and you bring it together. As part of the best of both, we took the CyberArk brand and their stock ticker and we listed CyberArk in Israel as a token of our appreciation, our gratitude for all the amazing work that the CyberArk team had done. However, it's time for us to evolve the product of identity in partnership and under the leadership of the CyberArk team and also welcome the new set of products for identity under a new name. It is my privilege and pleasure to announce the brand identity of the CyberArk product called IDERA. You'll hear a lot more about this from Peretz and the team in a few minutes, but before they come up and talk about what they are working on and how this is going to evolve, I think it's very important. We have to make sure that privilege access management takes the next step. We have to make sure that it is modern, it is in line with the expectations and requirements for our customers as they evolve to new technology platforms of AI and go fully cloud over the future. It is important for us to bring privilege access management and identity and access management together in a much more comprehensive, cohesive way. It is important for us to bring non-human identities into that equation and see the identity as a consistent landscape for our customers over time. What you will hear from the team is the beginnings of us starting on that journey. You'll hear from them our commitment to continue to keep working in that direction to make sure that we build the industry's best identity platform for the future. To help me in the task, to partner with Peretz and Nir and Abhijay and Amy and the team, I'm delighted to announce the new general manager and president of IDERA, Sunny Singh. I've had the privilege of knowing Sunny for a very long time. He's a professional. He's amazing at what he does. He was most recently at Oracle before this. He spent many, many, many years building an amazing set of business for Oracle. We can't be more excited that he's going to be part of the IDERA journey with Palo Alto Networks. Please join me in a big round of applause in welcoming Sunny Singh. Have a great conference, guys. Note to self, never follow Nikesh on stage again. Well, good morning, everyone. First and foremost, to all our customers, partners, and all my colleagues from CyberArk and Palo Alto Networks, I'm absolutely delighted to be here today. It is day zero in the world of cybersecurity for me. But I'm thrilled to be here, and I look forward to working with all of you in the coming future. Thank you very much for that warm welcome. This is an important moment, and I'm excited to be here for that. What we are announcing today is much more than the launch of a brand. The launch of IDERA is very important because, for us, it means a new platform direction. And the reason why this matters is really very simple. Nikesh talked a lot about it. The technology industry overall has been very prolific, very, very innovative. But one thing that you can hold us accountable for is that we've been building new features, building new capabilities. We do what we do best, and then we toss it over the wall to our customers. And we leave the challenge of making all of that work in your environment, in your architecture, to you. This means there's a lot of disparate data sources. There are disconnected workflows. There's a lot of manual integration. And this reduces the opportunity to accelerate time to value. All of this is happening while you're dealing with a threat landscape that keeps on evolving. A phrase you're likely to hear over and over again is that attackers are not breaking in. They're actually logging on. And this is what we are seeing. More and more, attacks start with identity. They start with maybe, you know, unauthorized privilege. They may start with credentials that are outdated. They start with access that looks legitimate until it's abused and it's too late. So this old model where privileged access is treated like a narrow, isolated problem is just not enough anymore. All of you, our customers, need a much more modern approach. And that is what Idera is all about. It's about bringing privileged access and identity security into a broader platform model. It's about reducing the burden of integration for you. It's about delivering that value of integration as a built-in capability, not bolted on after the fact. When we think about platforms, Idera is actually a critical third pillar to the broader Palo Alto Networks portfolio of capabilities. It sits besides network security, which is Strata, cloud security, which is Cortex, and now identity security, all working closely together with AI. This is important because it actually tells you how central identity and privilege have become to the overall security architecture. It's no longer a side category. It's fundamental and it's foundational. And this is where the platform advantage matters so much. It means, for you, less complexity. It means more context. And it means better outcomes and an accelerated time to value. At the end of the day, you as our customers should not have to take on this integration challenge, making all of these piece parts work together so you have a comprehensive capability for managing the threat landscape. It's our job to make that easier for you. It is our job to deliver a platform that works together by design. That is the promise of Idera. A modern platform for privileged access and identity security built for the way attacks happen now and built for the way that customers need to operate going forward.

TL;DR

  • Palo Alto Networks announces Idera, a new identity security platform combining privileged access management and identity security, following the company's acquisition of CyberArk.
  • The platform addresses the next inflection point in cybersecurity: the proliferation of AI agents and non-human identities that will flood enterprise infrastructure within 3-5 years, all requiring unified identity governance.
  • Idera becomes Palo Alto's third major platform alongside Strata (network security) and Cortex (cloud security), reflecting identity's elevation to a foundational security pillar rather than a side category.
  • The platform aims to solve the fragmentation problem where organizations currently take 48 hours to two weeks to build identity graphs during incidents due to data scattered across IAM, PAM, and SaaS systems.
  • Sunny Singh joins as General Manager and President of Idera from Oracle, emphasizing the platform's promise to deliver integration as a built-in capability rather than leaving customers to stitch together disparate solutions.

The Evolution of Cybersecurity Platformization

Palo Alto Networks CEO Nikesh Arora traces the company's eight-year transformation from a firewall vendor to a comprehensive security platform provider. He explains how the cybersecurity industry has matured from customers stitching together point solutions to vendors delivering integrated platforms. The company identified identity as the next major inflection point in cybersecurity, particularly as AI agents proliferate across enterprise environments. This realization led to the strategic acquisition of CyberArk and the development of a unified identity security platform. Arora emphasizes that 90% of cybersecurity attacks originate from credential theft or hijacking, yet most organizations take 48 hours to two weeks to build an identity graph during incident response due to fragmented data across IAM providers, privileged access systems, and SaaS applications.

AI Agents and the Identity Challenge

The presentation addresses the imminent explosion of AI agents in enterprise infrastructure, with predictions that every employee will use multiple agents acting on their behalf within three to five years. These agents will operate using human credentials but lack human judgment to recognize suspicious activity. The challenge extends beyond personal agents to non-human identities created by systems integrators and automation platforms. Arora notes that the traditional segmentation of identity into privileged access management (PAM), identity and access management (IAM), and non-human identity (NHI) categories is insufficient for this new reality. Organizations need unified visibility to answer fundamental questions: who did it, how they did it, when they did it, where they are, and how to terminate malicious identities immediately.

Introducing Idera: A New Platform Direction

Sunny Singh, newly appointed General Manager and President of Idera, announces the brand as Palo Alto Networks' third major security platform alongside Strata (network security) and Cortex (cloud security). Idera represents a fundamental shift from treating privileged access as an isolated problem to integrating it with broader identity security in a platform model. The announcement emphasizes that attackers are no longer breaking in but logging on with legitimate-looking credentials that are abused before detection. Singh criticizes the industry pattern of building innovative features and leaving integration challenges to customers, resulting in disparate data sources, disconnected workflows, and manual integration overhead. Idera promises to deliver integration value as a built-in capability rather than a bolt-on afterthought, reducing complexity and accelerating time to value for customers facing an evolving threat landscape.

Chapters

0:00 - Opening: The Agent Future
0:16 - Industry Evolution and Platformization
4:00 - Inflection Points in Cybersecurity
6:01 - Identity as the Next Inflection
8:12 - Cybersecurity Fundamentals
10:33 - AI and the Agent Explosion
14:45 - Identity Evolution Requirements
17:01 - Introducing Idera
18:55 - Sunny Singh Introduction
19:32 - Platform Direction and Promise

Key Quotes

0:00 "We're going to have millions of agents floating around in the IT infrastructure. All these agents need to be identified. All these agents need to be understood. All their data needs to be brought together."
2:40 "We came to the realization about three or four years ago when at Palo Alto, we had reached approximately 70 products, I realized even we had a hard time keeping it together in terms of how to go deliver, deploy, and make those products successful for our customers."
5:15 "We are able to provide real-time capability and protect our customers in real-time against bad actors with a median time to detect and remediate at Palo Alto, one minute."
6:35 "Almost 90% of cybersecurity attacks originate from somebody. Credential thefts, credential hijacking, somebody posing as somebody else."
11:37 "If I told you that the largest technology companies in the world are going to spend $1 trillion in the next 12 months on something, whatever it is, we have to pay attention."
21:06 "Attackers are not breaking in. They're actually logging on."

FAQ

Why did Palo Alto Networks acquire CyberArk and create the Idera platform?

Palo Alto identified identity as the next major inflection point in cybersecurity, particularly with the coming proliferation of AI agents. The company needed to platformize identity security the same way it had done with network security (Strata) and cloud security (Cortex). CyberArk's privileged access management capabilities combined with Palo Alto's platform approach enables unified identity governance across human and non-human identities.

How will Idera address the challenge of AI agents in enterprise environments?

Idera is being built to handle the anticipated explosion of AI agents that will act on behalf of employees using their credentials. The platform aims to provide unified visibility and control across all identities—human, privileged, and non-human—with the ability to analyze behavior, detect anomalies, and terminate malicious identities in real-time. This addresses the fundamental problem that agents lack human judgment to recognize suspicious activity.

What makes Idera different from traditional identity and privileged access solutions?

Idera breaks down the traditional segmentation of identity into separate categories (PAM, IAM, NHI, ISPM, IGA) and delivers integration as a built-in platform capability rather than leaving customers to manually stitch together disparate solutions. It consolidates identity data that currently sits fragmented across IAM providers, privileged access systems, and SaaS applications, reducing the time to build identity graphs from 48 hours-2 weeks to real-time analysis.


Categories:
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Identity & Access
  • AI & Machine Learning
  • Security Operations
  • Executive Briefing
  • Announcement
  • Identity Security Platformization
  • AI Agent Governance
  • Privileged Access Management
  • Non-Human Identity Management
  • Cybersecurity Platform Consolidation
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Palo Alto Networks Launches Idera Identity Platform

              Industry Events (Sponsor Hosted)

              • Aug
                06

                Safeguarding Sensitive Data in the Age of AI Platforms

                08/06/202604:00 AM ET
                • Aug
                  06

                  AI Agents Transforming Identity Attack Tactics and Speed

                  08/06/202602:00 PM ET
                  • Aug
                    13

                    Harnessing AI for Secure Innovation in the Enterprise with Netskope & Omada

                    08/13/202612:00 PM ET
                    More events

                    Upcoming Webinar Calendar

                    • 08/06/2026
                      04:00 AM
                      08/06/2026
                      Safeguarding Sensitive Data in the Age of AI Platforms
                      https://www.truthinit.com/index.php/channel/2058/safeguarding-sensitive-data-in-the-age-of-ai-platforms/
                    • 08/06/2026
                      02:00 PM
                      08/06/2026
                      AI Agents Transforming Identity Attack Tactics and Speed
                      https://www.truthinit.com/index.php/channel/2064/ai-agents-transforming-identity-attack-tactics-and-speed/
                    • 08/13/2026
                      12:00 PM
                      08/13/2026
                      Harnessing AI for Secure Innovation in the Enterprise with Netskope & Omada
                      https://www.truthinit.com/index.php/channel/2065/harnessing-ai-for-secure-innovation-in-the-enterprise-with-netskope-omada/
                    • 08/19/2026
                      12:00 PM
                      08/19/2026
                      Becoming Agent Ready with Cyera: Essential Strategies and Insights
                      https://www.truthinit.com/index.php/channel/2036/becoming-agent-ready-with-cyera-essential-strategies-and-insights/
                    • 09/02/2026
                      12:00 PM
                      09/02/2026
                      Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                      https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                    • 09/30/2026
                      04:00 AM
                      09/30/2026
                      AI Command Center: Optimizing Visibility and Control in Your Operations
                      https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version