The Business of Cyber Security

Identity Security

What identity security is

Identity security is the discipline of governing who (and increasingly what) can access which resources, under what conditions, and for how long. It is not one product but a stack of adjacent control points that grew up separately and are now colliding:

These were five separate buying centers a decade ago and are converging into a single identity fabric; whoever assembles the most complete fabric, with distribution, captures the pool.

Economics and differentiation across layers

Layer Leaders Challengers Economics & moat M&A posture
Access (IAM/SSO/MFA) Microsoft Entra, Okta Ping (Thoma Bravo), Cloudflare, Beyond Identity Per-MAU SaaS; moat = directory lock-in + app integrations (Okta's ~7,000+ pre-built connectors) Okta independent buyer; Ping a TB roll-up
PAM CyberArk (now Palo Alto), Delinea (TPG), BeyondTrust Teleport, StrongDM, HashiCorp Vault (IBM) Highest ACV in identity; vaulting is compliance-mandated and highly retentive CyberArk absorbed; Delinea/BeyondTrust are sponsor-owned consolidators
IGA SailPoint (re-IPO'd 2025), Saviynt Omada, Zilla (CyberArk), Lumos Deep ERP/HR integration; switching cost is enormous; slow sales cycles SailPoint public again; Saviynt a likely strategic target
Machine / NHI Astrix, Aembit, Token Security, Oasis, Silverfort, Clutch Entro, Britive, Corsha Land-grab pricing; moat still forming; secrets sprawl is the wedge VC-backed, strategic-scarce; primarily sell-side candidates
ITDR / CIEM Silverfort, Microsoft, CrowdStrike Permiso (Okta, agreed Jul 30 2026), Sonrai, Ermetic (Tenable) Detection layer; rides the platform's data Tuck-in fuel for platforms (Tenable–Ermetic, Microsoft, Okta–Permiso)

The key differentiation: PAM and IGA are "system-of-record" businesses (high switching cost, durable, compliance-anchored — which is why TB and PANW pay up for them), whereas access management is a distribution business (whoever owns the directory — Microsoft — has structural advantage), and NHI is a greenfield land-grab (no incumbent has won yet, which is why it draws the most sell-side interest).

Consolidation map

Identity sub-segments by consolidation stage many few independent vendors Fragmented Consolidating Oligopoly Absorbed NHI /machine ITDR /CIEM IGA PAM Access(MSFT)
Identity is consolidating right-to-left: access management is effectively an oligopoly tipping toward Microsoft's directory; PAM just lost its leader to Palo Alto; NHI remains a fragmented land-grab. Bubble position = consolidation stage; the least consolidated sub-segments sit on the left.

Signature deals

AI-agent access governance

The fastest-moving thread inside NHI is no longer just secrets sprawl but governing what an autonomous AI agent is allowed to do — provisioning an agent identity, scoping its access to a task, and revoking it when the work is done. Agentic workflows broke the old assumption that identity = a human with a standing account: agents are non-deterministic, numerous, and short-lived, so the control model shifts from vaulting a credential to brokering just-in-time, policy-bound access in real time. This is the wedge under the 2026 identity buying wave — CrowdStrike–SGNL (real-time grant/revoke), Cisco–Astrix and Cisco–WideField (agent/NHI discovery + telemetry into Splunk's Agentic SOC), SailPoint–Entro (secrets + machine-identity into its Agentic Fabric), 1Password–Apono (JIT access governance), and Keyfactor–Cofide (SPIFFE-based workload/agent identity issuance). Finro's Q2 2026 dataset confirms the pull at the deal level: IAM led every cyber niche with 15 M&A transactions at a ~20x average EV/Revenue, explicitly attributing the demand to "AI-agent proliferation making identity infrastructure non-negotiable for platform buyers" (see 12). The independents still in play — Aembit, Token Security, Oasis, Britive, Corsha, plus newly-funded NewCore — sit directly in the path of that demand.

The bear case

If Microsoft's directory advantage compounds — Entra bundled into E5, free Security Copilot capacity, ITDR built in — then standalone access vendors (even Okta) face structural multiple compression, and the independent identity premium narrows to PAM, IGA, and NHI only. The falsifiable test is Okta's net revenue retention and whether NHI startups can reach durable seven-figure ACVs before the platforms ship "good-enough" native NHI. If NHI economics stay thin and platforms ship native, the land-grab collapses into tuck-ins rather than standalone exits.

Cross-references: Vendors, Thoma Bravo, Deals & Comps, AI Security, Buy-Side Prospect Framework.

Adjacent market: the fraud-prevention and identity-verification industry converging with cyber identity is mapped on Fraud & Identity Verification.


Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.