Hype Cycle for Zero-Trust Technology, 2025

ARCHIVED
1 August 2025 - ID G00830246 - 101 min read
By Tiffany Taylor, Andrew Lerner
Organizations are developing zero-trust strategies with a need to evaluate and deploy zero-trust technologies. Ongoing advancements in technology continue to accelerate zero-trust adoption. This Hype Cycle provides cybersecurity leaders with a framework to prioritize technology innovations that are most effective in advancing an organization’s zero-trust security posture.

Analysis


What You Need to Know

Zero trust is a strategic imperative for organizations seeking to mitigate risk by minimizing attack surfaces, standardizing user access and enabling risk-based access policies. Far from being a singular technology or one-time deployment, zero trust is a strategic framework guiding the implementation of specific architectures and technologies across environments. Successful adoption hinges on the careful selection of technologies across its core pillars. However, navigating the pervasive industry noise surrounding zero trust makes distinguishing genuine best practices from mere marketing hype a significant challenge.
Key zero-trust tenets include:
  • Positive identification and continuous verification
  • Explicit policy enforcement
  • Adaptive access
  • Segmentation
  • Continuous monitoring
  • Automated response
Effective zero-trust implementation necessitates close collaboration between cybersecurity and infrastructure and operations (I&O) leaders, given the substantial investment required across people, processes and technologies. This Hype Cycle identifies key emerging and established technologies that security and risk management (SRM) leaders should prioritize, ensuring alignment with zero-trust principles and the organization’s risk mitigation goals.

The Hype Cycle

Zero trust has rapidly transitioned from a niche security concept to a foundational strategy for organizations navigating complex, distributed environments. While network-centric technologies like zero-trust network access (ZTNA), network microsegmentation, along with network detection and response (NDR) remain crucial, they are reaching maturity and are anticipated to enter the Plateau of Productivity within the next two years.
Advancements in AI, authentication, automation, cyber-physical systems (CPS) security, endpoint security and postquantum threats will propel the next wave of zero-trust technology adoption. To capitalize on these emerging trends, organizations must realign their zero-trust strategies by:
  • Leveraging AI for adaptive security and automation.
  • Implementing automation to accelerate threat detection, facilitate adaptive access and streamline endpoint management.
  • Implementing segmentation as attack surfaces expand.
  • Investing in postquantum security through cryptographic agility and authentication methods to proactively address emerging threats.
  • Expanding zero-trust principles beyond traditional IT — applying them across hybrid environments, CPS, Internet of Things (IoT) and edge computing to safeguard the proliferation of devices and distributed data. This necessitates tailoring zero-trust technologies for industrial and critical infrastructure.
Furthermore, regulatory pressures, including new mandates like executive orders and the EU Network and Information Systems (NIS)2 Directive, coupled with increased government funding, are significantly accelerating zero-trust adoption across industries.
Figure 1: Hype Cycle for Zero-Trust Technology, 2025
Figure 1: Hype Cycle for Zero-Trust Technology 2025, plots 26 innovations from the Innovation Trigger through the Slope of Enlightenment. Innovations range from Agentic AI for Backup to Universal ZTNA to ZTNA.

The Priority Matrix

To help organizations prioritize technology investments by impact, we provide a Priority Matrix. While impact is a key consideration, factors such as applicability, budget, implementation time and risk mitigation are equally important. The Priority Matrix enables leaders to make informed, future-ready decisions by clarifying trade-offs between high-impact, long-term investments and immediate opportunities. It maps the potential benefits of innovations against their position on the Hype Cycle, serving as a strategic guide for technology investment and adoption planning.
Currently, no transformational technologies are expected to reach mainstream adoption within the next two years; instead, organizations will adopt mature, high-impact technologies over this period. Digital transformation requires simplifying the delivery and operation of critical network and security services delivered through secure access service edge (SASE), with mainstream adoption within two to five years. Also within this time frame, escalating privacy concerns and heightened regulatory requirements will compel organizations to transform their identity strategies with decentralized identity solutions.
Over the next two years, organizations are expected to mainstream the adoption of OpenID and network microsegmentation, utilizing these technologies to significantly improve user experience and bolster security measures.

Priority Matrix for Zero-Trust Technology, 2025

BenefitYears to Mainstream Adoption
Less Than 2 Years2 to 5 Years5 to 10 YearsMore Than 10 Years
Transformational
High
Moderate
Low
Source: Gartner (August 2025)

On the Rise

Agentic AI for Backup

Analysis By: Rene Rodriguez
Benefit Rating: High
Market Penetration: 1% to 5% of target audience
Maturity: Embryonic
Definition:
Agentic AI is an approach to building AI solutions based on the use of one or multiple software entities that are classified, completely or at least partially, as AI agents. AI agents are autonomous or semiautonomous software entities that use AI techniques to perceive, make decisions, take actions and achieve goals in their digital or physical environments.
Why This Is Important
Agentic AI for backup and data protection platforms has the potential to provide intelligent support to backup administrators by enhancing cyberthreat detection and response, cost and operational efficiencies, and recovery through AI-driven autonomous operation. This technology aims to help organizations streamline their recovery capabilities and efficiencies, particularly in environments facing a diminishing level of focus regarding backup specialization in data protection and recovery.
Business Impact
Agentic AI for backup:
  • Automates routine admin tasks, freeing engineers for more strategic work.
  • Standardizes recovery operations using AI for autonomous decisions from data points and not human-based intervention.
  • Enables autonomous development and testing of recovery plans for standard/cyber scenarios, ensuring reliable processes.
  • Improves diagnostics and recovery to reduce RTOs and boosts RPOs with dynamic scheduling based on data change rates, importance and application mappings.
Drivers
  • Organizations are searching for opportunities to integrate agentic AI into their operations to enhance workflows and administrative functions, mitigating the need for human touch time by skilled administrative staff.
  • Agentic AI for backup can reduce touch-time and vendor support dependency for troubleshooting issues like failed backups, restores or performance problems by making informed decisions based on numerous data points, providing fault or failure resolution with minimal human interaction. It also offers guided assistance to resolve issues and collect data for support ticket generation, ensuring robust and reliable recovery support.
  • Requirements to identify operational and cost inefficiencies and tailoring responses to meet the organization’s recovery objectives autonomously is gaining interest, offering comprehensive oversight and streamlined operations.
  • Agentic AI for backup can be utilized to create recovery plans and exercise them systematically for both standard and cyber recovery scenarios, ensuring preparedness and resilience.
  • It enhances IT operations by autonomously detecting, diagnosing and resolving infrastructure issues, reducing the burden on IT teams and minimizing downtime.
  • Integrating agentic AI into operations improves predictive capacity planning and resource allocation, providing real-time insights into system health, network performance and usage patterns. This helps organizations optimize their IT resources and reduce operational costs.
  • Increasing sophistication and frequency of cyberthreats necessitate the need for proactive intelligent anomaly detection and faster automated recovery processes without constant human intervention and monitoring.
Obstacles
  • Implementations of agentic AI for backup are embryonic with few production features available in the backup and data protection market today.
  • There are data security and privacy concerns between customers and vendors about how the customer data is shared and used by an organization's agentic AI for backup offerings.
  • Vendor solutions will need to prove their reliability before clients are willing to relinquish some decision-making control of operations to an AI agent. Demonstrating consistent performance and trustworthiness is crucial for adoption.
  • Use of agentic AI for backup creates new potential attack surfaces. The AI platform itself could be targeted, or its decision-making capabilities can be compromised, manipulated or poisoned.
User Recommendations
  • Distinguish market hype from clear examples of autonomous decision-making capabilities as agentic AI for backup emerges from embryonic stages.
  • Continually evaluate your backup vendor’s agentic AI capabilities, noting this technology will evolve rapidly in both maturity and capability over time.
  • Assess how agentic AI for backup can streamline your organization’s administrative and recovery tasks, especially where resources and skills are limited.
  • Consider data security, privacy and legal aspects when using corporate data in a vendor’s agentic AI for backup.
  • Confirm the reliability and ethical operation of the vendor’s agentic AI for backup offering. Ensure that vendors prove their AI’s capabilities through POC and ongoing operation. Verify it operates without bias to prevent unfair resource allocation and false threat assessments.
Gartner Recommended Reading
Top Trends in Enterprise Backup and Recovery for 2024

Postquantum Authentication

Analysis By: Ant Allan, Sarah Almond, James Hoover, Paul Rabinovich
Benefit Rating: High
Market Penetration: Less than 1% of target audience
Maturity: Emerging
Definition:
Postquantum authentication (PQA), also known as quantum-safe authentication (QSA), is a horizontal category that encompasses any authentication method that incorporates postquantum cryptography (PQC) to mitigate attacks using quantum computing. This innovation cuts across different flavors of authentication, especially phishing-resistant MFA based on public-key cryptography (X.509, FIDO2), but also includes mobile push methods.
Why This Is Important
Authentication should provide credence in an identity claim, sufficient to bring account takeover (ATO) risks within an organization’s risk tolerance. By 2029, advances in quantum computing will weaken and break the conventional asymmetric cryptography that underpins many authentication methods. This will significantly reduce the credence that these methods can provide, increasing enterprises’ exposure to ATO risks. Thus, migration to postquantum authentication is a critical task.
Business Impact
PQA is crucially important to identity and access management (IAM) and other cybersecurity leaders:
  • In all industry verticals and geographies
  • Across multiple use cases incorporating authentication methods based on asymmetric cryptography
  • To protect these methods from attacks based on advances in quantum computing
  • To avoid increasing the organizations’ exposure to ATO risks and consequent data breaches, financial loss and so on.
Drivers
  • Public-key cryptography underpins three important flavors of authentication tokens: mobile push, X.509 and FIDO2; the latter two provide phishing-resistant MFA.
  • Mobile push is one of the most popular authentication methods. Mobile push apps typically embed public-key credentials, used to sign the user’s response and provide data integrity and data origin authentication, confirming possession of the token (smartphone).
  • Phishing-resistant MFA is of increasing client interest as a way of avoiding the vulnerabilities of other token-based MFA (including mobile push). Both X.509 and FIDO2 flavors incorporate public-key credentials in the sole possession of the user, activated​ by a local PIN or biometrics​.
  • Key cracking is one of the mathematically approachable problems the new generation of commercial quantum computers are positioned to solve. Gartner predicts that by 2029, quantum computing will make conventional asymmetric cryptographic systems unsafe to use.
  • In many classes of systems, replacing existing algorithms has begun and is expected to accelerate now that NIST has identified new quantum-safe algorithms and drafted deprecation dates for classical asymmetric algorithms.
  • Commercial PQA (i.e., authentication that incorporates quantum-safe algorithms) is currently (July 2025) generally available from only one specialist vendor. Thus, it is still at a far left position on the Hype Cycle.
  • Adoption is likely to be slow for the next 2 years. However, Gartner projects that adoption will increase rapidly as mainstream authentication vendors bring their PQA tools to market, enabling organizations to implement and roll out PQA comfortably ahead of the 2029 deadline. Thus, we project that PQA will reach the Plateau of Productivity quite rapidly.
  • Vendors that lag in making PQA generally available are likely to lose customers, who will seek new partners that can enable a timely implementation and roll out.
Obstacles
  • Organizations may lack a full inventory of where vulnerable authentication methods are used and who the stakeholders are. It may be difficult to orchestrate change across all dependent parties.
  • There is a key dependency on the FIDO Alliance and individual authentication vendors for PQA, but most plans are at early stages.
  • FIDO2 and X.509 methods depend on algorithm standardization and incorporation into various protocols, as well as updates to OSs, browsers, devices (especially Trusted Platform Modules [TPMs]) and other infrastructure. Some proprietary offerings may be free of such prerequisites.
  • Authentication vendors may be late incorporating PQC within their tools. PQA must be generally available sufficiently early, ideally by 2027, to enable organizations’ timely migration to PQA. If vendors are late, customers should seek alternative providers.
  • Implementing and rolling out PQA will mean updating authenticators and reprovisioning these to every user, a significant logistical effort that may present opportunities for ATO attacks.
  • Supply chain constraints may impact sourcing new PQA compliant hardware tokens, impacting timelines and budgets.
User Recommendations
  • Include PQA within a comprehensive postquantum program. While PQA might not be a high priority in terms of data value and “harvest now, decrypt later” exposure, it may still need significant effort and early discovery/inventory is a priority.
  • Work with incumbent vendors to understand their timeline for PQA. Seek support for hybrid methods to enable a robust transition to pure PQA.
  • If selecting new tools, prefer vendors in this order: those that offer PQA. Otherwise, prefer vendors that have a clear timeline for PQA over any that don’t.
  • Establish a clear setback schedule that will give you sufficient time to select, implement and roll out a new PQA tool. Use this to set a watershed. If an incumbent vendor cannot offer PQA at that time, be prepared to switch.
  • In any case, ensure timely PQA rollout. Be wary of attacks against credential management processes. Reprovision authenticators ahead of time so the process can be bootstrapped using existing methods. Later (re)provisioning will require more onerous identity verification steps.
Sample Vendors
Wultra
Gartner Recommended Reading

Endpoint Access Isolation

Analysis By: Chris Silva, Stuart Downes
Benefit Rating: Moderate
Market Penetration: 1% to 5% of target audience
Maturity: Adolescent
Definition:
Endpoint access isolation (EAI) consists of client-side applications facilitating secure access to applications and data while isolating that endpoint from the systems it accesses. The technology can be deployed as a remote access agent, managed application or self-contained virtual endpoint. It extends access where client management or security software can’t be reliably installed.
Why This Is Important
EAI extends remote access to devices the organization can’t directly secure. Windows and macOS platforms lack the same controls that allow secure bring your own (BYO) on mobile. Lacking direct control, isolating the data from local access becomes the means of enforcement. EAI tools rely on a client-side application to provide telemetry attesting to device posture, allowing it to remain continually authenticated and monitored while accessing the resource. EAI tools are a separate class of technology from traditional VDI or DaaS tools and may be used as an access layer for those tools as a comprehensive isolation solution.
Business Impact
Hybrid work across multiple devices by users may require extending access securely where local controls and management are not an option. EAI lets organizations offer secure access to difficult-to-secure devices, combining endpoint security, audit and data isolation capabilities. EAI tools are designed as lightweight, easy-to-install alternatives to traditional but costly and complex VPN or VDI solutions. The technology focuses on locally installed access clients or isolated compute environments that act as a launching point to securely present content and apps.
Drivers
  • Traditional VDI and DaaS solutions are costly and complex for presenting applications that are predominantly accessed via a local app or browser.
  • Organizations are exploring means to offer access to more users and use cases, but require some visibility and the ability to interrogate devices that are not directly under the organization’s control.
  • Traditional VPN remote access, while cost-effective, may have difficulty supporting dynamic, zero-trust access policies and is unable to dynamically adapt access based on user or device context.
  • Organizations can reduce operations overhead by shifting contractors and other outsourced workers from logistically complex company-owned and managed hardware to unmanaged local devices with EAI brokering access to company data.
Obstacles
  • EAI is made up of a broad range of technologies and architectures. Some tools are specifically focused on certain requirements (e.g., enhanced user authentication) and therefore may have narrow appeal.
  • While EAI tools offer a wide variety of access options where data and applications are truly isolated from the local client, performance and user experience trade-offs of these tools may deem a directly managed, traditional device a more tenable option.
  • Secure enterprise browser technology continues to mature and often is deemed adequate for protecting the same use cases EAI often serves. Cost and user experience can drive this decision toward or away from EAI depending on context.
  • Users are resistant to installing company technology on their personal devices, especially agents that monitor usage and performance.
User Recommendations
  • Identify relevance of EAI by surfacing use cases such as consuming sensitive data on unmanaged devices, enhanced user authentication, or a locally executing, segmented and centrally managed OS container.
  • Plan for extended procurement; technologies range from access agents to local hypervisors and may not overlap, and use cases may require multiple pieces to achieve a given goal.
  • Measure the cost and complexity of EAI against existing — if flawed — methods to find out the true, long-term impact of adopting EAI.
  • Expect that EAI technology will be employed in specific, targeted use cases, but it should adhere to the same zero-trust policies and access norms (e.g., enforcement of MFA, conditions for access) as all other methods of access.
Sample Vendors
Amazon Web Services; Citrix; Evren; Hypori; Nubo Software; SentryBay; SessionGuardian; ThinScale Technology; Venn
Gartner Recommended Reading

Extranet as a Service

Analysis By: Andrew Lerner
Benefit Rating: Low
Market Penetration: Less than 1% of target audience
Maturity: Embryonic
Definition:
Extranet as a service (ExtranetaaS) is a network software offering that delivers extranet functionality as a service. An extranet is a logical network zone that connects multiple independent parties together, typically under different administrative domains and often with diverse requirements. These are sometimes also referred to as B2B networks.
Why This Is Important
ExtranetaaS improves how companies enable extranets in their environment. It simplifies the ability to set up and secure an extranet’s operation in the modern era as enterprises increasingly use public cloud and SaaS services.
Business Impact
ExtranetaaS allows companies, partners, customers and other outside parties to access data and systems on a network. It enables these parties to connect and exchange necessary information, such as application components or financial transactions, and is helpful in connecting independent parties with common interests.
Drivers
  • Traditionally, extranets were established in data centers, nearby applications and data, using dedicated circuits or IPsec VPN. Migrating applications to the public cloud and SaaS is causing organizations to rethink their existing extranet approaches.
  • The native public cloud providers don’t offer robust advanced networking configurations to support complex extranet connectivity scenarios, driving enterprises to entertain ExtranetaaS solutions.
  • Organizations want to simplify and replace physical infrastructure, including routers, firewalls and VPN appliances, with solutions that are more API- and software-oriented.
  • Organizations also want to remove expensive dedicated lines such as MPLS or a dedicated broadband.
  • ExtranetaaS increases the speed of connecting to external business entities.
  • Smaller and startup network vendors are aggressively targeting enterprises to help them solve the technical and security challenges as organizations migrate their applications to cloud services.
  • Businesses with overlapping IP addresses, that need to connect, are looking to ExtranetaaS as an option.
Obstacles
  • ExtranetaaS is an unknown technology and terminology for most enterprises.
  • Extranets often support mission-critical environments that lead to a desire for moderate incremental change. This is in contrast to a shift to ExtranetaaS, which entails a software-only as-a-service delivery from lesser-known vendors.
  • The public cloud providers’ native capabilities are good enough for some extranet use cases.
  • Organizations can use colocation in cloud data centers to get the services closer to public cloud, SaaS and partner services without using ExtranetaaS.
  • Most enterprise network teams take a “set it and forget it” perspective toward extranet deployments, preferring not to rearchitect the entire deployment. This drives moderate incremental modernization of existing extranets versus conversion to ExtranetaaS.
  • The supply of vendor solutions is immature, as many of the vendors focused on this technology are smaller, unproven companies.
User Recommendations
  • Investigate ExtranetaaS if native cloud provider constructs don’t support your B2B networking requirements.
  • Opt for ExtranetaaS if you’re migrating an existing on-premises, hardware-based extranet or B2B network to a public cloud environment.
  • Shortlist ExtranetaaS offerings as an option for connecting to a large number of customers’ data in a secure way.
  • Explore ExtranetaaS as an alternative to MPLS replacement for B2B use cases or for standardizing your or your business partner’s connectivity across regions.
Sample Vendors
Alkira; Graphiant; Trustgrid
Gartner Recommended Reading

Automated Moving Target Defense

Analysis By: Franz Hinner
Benefit Rating: Moderate
Market Penetration: 1% to 5% of target audience
Maturity: Emerging
Definition:
Automated moving target defense (AMTD) is a technology that continuously alters digital assets’ system resources and configurations, such as runtime memory, network configuration, available binaries and others, to increase the complexity of exploitation for threat actors by making systems less predictable.
Why This Is Important
AMTD:
  • Gives organizations a dynamic, adaptive defense by constantly shifting the attack surface, making it much harder for threat actors to exploit vulnerabilities.
  • Acts as a proactive layer to strengthen endpoint protection, especially when sophisticated attacks bypass traditional EDR.
  • Disrupts attacker reconnaissance and exploitation by introducing unpredictable system changes, keeping defenders ahead.
Business Impact
ATMD:
  • Lowers operational costs by reducing manual security workloads and minimizing false positives.
  • Improves business continuity by decreasing downtime from ransomware and zero-day attacks.
  • Reduces the risk of data loss and reputational damage across critical sectors like healthcare, finance and infrastructure.
  • Accelerates incident response and recovery, empowering lean security teams to protect more with less.
Drivers
  • Organizations face increasing breaches as traditional detection and response tools are bypassed, driving demand for a second layer of endpoint defense like AMTD.
  • Traditional defenses struggle to keep up as endpoint environments become more complex. Organizations need dynamic solutions that continuously obfuscate the attack surface, making it significantly harder for attackers to move laterally or exploit endpoints.
  • Persistent issues like poor endpoint configurations and widespread credential reuse expose organizations to identity and access risks. AMTD addresses these challenges by disrupting attacker reconnaissance and lateral movement, helping organizations close critical security gaps.
  • AMTD enhances operational efficiency by automating attack surface management, reducing the burden on security teams and enabling faster response to emerging threats.
Obstacles
  • Integration complexity: Deploying AMTD alongside existing security architectures, such as IDS/IPS and zero trust, can significantly impact operations, requiring specialized expertise and phased rollouts to minimize workflow disruptions.
  • Platform limitations: AMTD lacks comprehensive support for Linux, Apple macOS and virtualized environments, forcing organizations to maintain fragmented security strategies.
  • Perceived redundancy: Security teams often undervalue AMTD, mistakenly viewing it as redundant due to feature overlap with modern EDR/EPP tools, despite its distinct prevention capabilities.
  • Skills shortages: IT teams typically lack experience with AMTD-specific tools, necessitating significant investment in training to operationalize dynamic defense strategies.
User Recommendations
  • Prioritize AMTD as part of your defense-in-depth strategy in highly targeted sectors — such as government, financial services, healthcare, and insurance — where advanced threats and regulations demand robust protection.
  • In other sectors, pilot AMTD on select workloads or endpoints — especially where traditional security tools cannot be deployed or to address threats like fileless and in-memory attacks.
  • Invest in training for security teams to ensure effective deployment and management of AMTD, accounting for the expertise required to integrate and operate these solutions.
  • Collaborate with security vendors to evaluate and gradually incorporate AMTD capabilities into your long-term endpoint protection strategy, replacing stand-alone solutions as the technology matures.
Sample Vendors
Arms Cyber; Cloudbrink; Dispel; Morphisec; RunSafe Security
Gartner Recommended Reading

Autonomous Endpoint Management

Analysis By: Tom Cipolla
Benefit Rating: High
Market Penetration: Less than 1% of target audience
Maturity: Emerging
Definition:
Autonomous endpoint management (AEM) is a next-generation approach that is enabled by new functionality within advanced endpoint management tools. AEM leverages configuration, compliance, risk, performance and experience data to intelligently perform common endpoint and digital employee experience (DEX) management tasks. The first foundational use case for AEM is autonomous patching that accelerates patch deployment and compliance and reduces IT overhead and degradation of DEX.
Why This Is Important
End-user services and digital workplace leaders are simultaneously pressured to increase the velocity of patching and maintain DEX. AEM is accelerating endpoint patching and promises to streamline and automate configuration management, while protecting DEX and reducing IT overhead.
Business Impact
End-user services leaders can further automate endpoint and DEX management tasks and reallocate efforts toward business-value-added work. Specific impacts include:
  • Reduced IT overhead through the automatic resolution of issues that impede employee productivity.
  • Enforced endpoint configuration standards based on vendor, industry or self-defined baselines.
  • Reduced cyber risk by automating patch and configuration management.
  • Automated software and configuration deployment based on policy and persona.
Drivers
  • IT staff is overwhelmed with the growing number of endpoint devices, operating systems and applications.
  • Largely driven by increased AI and ML capabilities, technology vendors have accelerated development and release cadence, and IT cannot keep pace.
  • Increased cyberattacks demand faster patch deployment, better device configuration compliance and closer alignment with vendor life cycles to reduce vulnerabilities.
  • Adoption of DEX practices and tools continues to grow rapidly as many accelerate their focus from a technology-centric to an employee-centric experience.
  • Cloud-based endpoint management and DEX tools are demonstrating how AI- or ML-powered intelligence can quickly process a significant amount of data, provide actionable insights and recommendations, and execute automations.
  • Developing and maintaining automation for common administrative tasks and applying standard policies and configurations is time-consuming and requires integration across multiple tools.
  • End-user services leaders struggle with utilizing and consolidating data from other endpoint management tools and agents.
  • AEM directly supports the end-user services leader’s goal of speed and agility.
  • AEM use cases are promising in addressing the management of applications and replacing human execution of routine IT processes.
Obstacles
  • Overly complex environments with too many disparate tools that lack integration.
  • Highly customized environments that require extensive testing of every update prior to deployment.
  • Fragile environments with a significant amount of technical debt — including legacy operating systems or applications that depend on unsupported browsers, runtime environments or plug-ins.
  • Low- to midmaturity organizations lack the competencies, tools and roles to ensure that more basic processes and concepts are already deployed.
  • Device operating system limitations or controls may prohibit experience and automation capabilities.
  • AEM is not possible on-premises, so cloud-averse organizations will not be supported.
  • Organizations that lack experience with agile methodologies and automation skills operate with a legacy mindset prioritizing control and customization.
  • AEM tools are unlikely to address niche use cases due to insufficient data to train ML and AI models to perform the automated activities.
User Recommendations
  • Avoid vendor lock-in by ensuring strategic endpoint and DEX management vendors have a roadmap that directly provides or includes necessary partnerships to enable AEM.
  • Reduce location dependence by migrating experience and endpoint management, security and identity solutions to the cloud.
  • Prepare your organization by assessing current and future skills requirements, updating existing and defining new roles, and implementing strategies for upskilling and professional development.
  • Eliminate inertia by promoting a human-centric and enablement mindset, while adopting modern management principles and agile methods.
Gartner Recommended Reading

Automated Security Control Assessment

Analysis By: Evgeny Mirolyubov, Jeremy D'Hoinne
Benefit Rating: Moderate
Market Penetration: 1% to 5% of target audience
Maturity: Emerging
Definition:
Automated security control assessment (ASCA) is a security technology that continuously analyzes, prioritizes and optimizes technical security controls to reduce an organization’s threat exposure. ASCA identifies configuration drift, policy and control deficiencies, detection logic gaps, poor defaults, and other misconfigurations in security controls. It then uses identified weaknesses to recommend and prioritize remediation steps to improve security against organization-specific threats.
Why This Is Important
Without optimal configuration, security tools are likely to fail to log, detect and block security threats, leading to poor return on security investments. The growing size and complexity of security stacks paired with security skills gap compounded the problem of maintaining an optimal configuration of security controls without automation. These issues are intensified by rapidly changing attack techniques, turning the required set of controls and configurations into a moving target, necessitating continuous improvements.
Business Impact
ASCA reduces the organization’s risk of business disruption and financial loss by optimizing technical security controls and reducing exposure to threats. Organizations implementing ASCA technologies enhance staff efficiency, minimize the impact of human errors, realize the potential of their security investments and improve resilience in the face of organizational churn.
Drivers
  • Misconfigurations in technical security controls and overreliance on default settings are among the leading causes why attacks continue to succeed.
  • Organizations lack the resources and expertise needed to fully understand and interpret thousands of configuration settings across security stacks without automation, let alone understand the resulting level of protection.
  • Uncertain threats, such as the use of generative AI by threat actors, may intensify the need for optimizing existing security controls more frequently to keep up with the pace of change in attacks.
  • Continuously assessing and optimizing security controls against specific threats, rather than best practices, is an effective risk mitigation strategy that ultimately reduces the organization’s exposure.
  • Manual configuration reviews against best practice settings and occasional penetration tests are insufficient due to the likely impact on user experience, limited scope and low frequency.
  • Meaningfully improving security posture requires going beyond compliance-driven assessments and evaluations focused on assessing the sole presence of security controls.
Obstacles
  • ASCA technology delivers an automated assessment of technical security controls and their configurations, with no active validation of the hypothesis. Thus, end users must validate findings and recommendations about an effective course of resolution.
  • Fully automating the process of implementing improvements based on ASCA findings is unlikely to become a reality in the near future. The heightened risk of business disruption makes most organizations hesitant about the idea of complete automation.
  • The slow pace of implementing recommendations, paired with continuous assessments performed by ASCA technologies, may cause recommendations to pile up. Security leaders may already be overwhelmed, and adding yet another source of findings may be more of a hindrance than a help.
  • Implementing improvements based on ASCA findings requires additional investment in people, processes and technologies, and a corresponding increase in budget. Yet, ASCA technologies rarely align with a dedicated budget and are usually an additional spend on top of existing security tools.
User Recommendations
  • Do not buy a third-party ASCA tool if your incumbent cybersecurity provider offers similar capabilities included in their offering. Similarly, refrain from buying if your existing managed detection and response or cyber insurance provider offers a similar capability that meets your requirements.
  • Choose a third-party ASCA provider based on its abilities to integrate with existing security controls on a sufficient level, granularity and alignment of optimization guidance with organization-specific threats, and security reporting capabilities.
  • Use ASCA to shift focus beyond evaluating the presence of controls, implementing best practice configurations or adhering to compliance frameworks.
  • Integrate ASCA with adjacent exposure assessment platforms and adversarial exposure validation technologies to better understand relationships between organization-specific assets, vulnerabilities, attack techniques, business context and controls.
  • Align security control optimization efforts with a continuous threat exposure management program to support a repeatable process for prioritizing and implementing improvements.
  • Highlight the potential for improvements in reduced cybersecurity incidents and less manual work for security control assessments to gain buy-in from teams required to respond to ASCA findings. These teams may include infrastructure security, identity, security operations, digital workspace and asset owners.
Sample Vendors
CardinalOps; Nagomi Security; Reach Security; Tidal Cyber; UST (CyberProof); Veriti; Zafran
Gartner Recommended Reading

MASQUE

Analysis By: Andrew Lerner, Aaron McQuaid, Simon Richard
Benefit Rating: Low
Market Penetration: 1% to 5% of target audience
Maturity: Adolescent
Definition:
Multiplexed Application Substrate over QUIC Encryption (MASQUE) is a proposed standard that enables secured transport and proxying of traffic, led by the Internet Engineering Task Force (IETF).
Why This Is Important
MASQUE is an alternative to replace existing encryption protocols such as IPsec, WireGuard and Transport Layer Security (TLS). It improves performance, security and privacy of communications between two endpoints. As a result, MASQUE has the potential to provide a unified foundation for multiple product categories including VPN-based remote access, Secure Sockets Layer (SSL) VPN and zero-trust network access (ZTNA) products.
Business Impact
Zero trust is a priority for most organizations as they seek to reduce the risk of certain cybersecurity threats in their environments. MASQUE can help accelerate or expand organizations’ zero-trust deployments as it provides a unified protocol to underpin networking deployments.
Drivers
  • MASQUE can provide enhanced privacy, improved performance and flexibility, compared to alternative protocols.
  • MASQUE builds on top of existing protocols including HTTP and Quick UDP Internet Connections (QUIC).
  • QUIC is the default transport protocol for Microsoft Office and Google Workspace, but is blocked by many security devices/services including security service edge (SSE) and firewalls. MASQUE helps address this, as it provides a mechanism for enterprises to inspect and regulate QUIC-based traffic, which can’t be done using existing technologies.
  • Vendors such as Cisco, Cloudflare and Ericsson are driving interest in and awareness of MASQUE.
  • Mobile OS vendors such as Samsung, Google and Apple are including MASQUE in their OS.
  • MASQUE can improve security, as it encrypts flow metadata, allows proxying of connections without interception, improves segmentation and provides encryption to protect data in transit.
  • MASQUE enhances the privacy of end-user-initiated encrypted traffic by ensuring that no party has visibility of both source and destination of the traffic flow.
  • MASQUE should improve performance and throughput compared to alternative protocols, as it leverages QUIC, which is notably performant.
  • MASQUE is protocol-agnostic, which means intermediate nodes don’t have to understand the encapsulated protocol. This will help with network address translation (NAT) and firewall compatibility issues.
Obstacles
  • MASQUE is not a fully ratified standard; it is a collection of standards and proposed standards.
  • There are vendor-specific implementations of MASQUE that may not interoperate, given that MASQUE is a framework versus a fully ratified standard.
  • There is limited enterprise awareness and experience with MASQUE.
  • There is limited native support for MASQUE in network hardware including load balancers, network firewalls and network interface cards.
  • To achieve optimal performance, HTTP/3 and QUIC need to be supported, and there is limited HTTP/3 adoption today.
User Recommendations
  • Include MASQUE in RFIs as an optional component for ZTNA, secure access service edge (SASE) and remote access projects. MASQUE will be an underlying technology for these offerings, which could provide a competitive advantage over traditional transport protocols.
  • When investing in products using MASQUE, prefer options that can fall back to existing and well-understood mechanisms (given it is not yet ratified).
Gartner Recommended Reading

AI for Access Administration

Analysis By: Nathan Harris
Benefit Rating: High
Market Penetration: 1% to 5% of target audience
Maturity: Emerging
Definition:
Artificial intelligence (AI) for access administration is the application of all types of AI (machine learning, generative AI [GenAI] and agentic AI) specifically for access governance and administration. Common applications are rapidly and efficiently identifying and resolving instances of excess access (least privilege violations) and not enough access (justified access that isn’t provisioned), including proposing rules to standardize, automate and govern entitlements.
Why This Is Important
Nearly all organizations find it difficult to manage access effectively, even if they have implemented identity governance and administration (IGA) tooling. Ever-changing workforce populations, business applications and IT systems, combined with no standard approach for entitlements/permissions models in apps and systems, make keeping up with effective access policies nearly impossible. AI methods can help improve manageability, sustainability and overall progress of target outcomes for access administration.
Business Impact
Applying AI to access administration (including access governance) processes can reduce manual work, improve delegation to non IAM teams, and speed up value delivery for identity and access management (IAM) teams struggling to keep up with organization changes and transformation. Using AI for access administration enables more rapid improvement in access policy than is possible with human decision making alone. This can improve IAM program results for business enablement, security and compliance simultaneously.
Drivers
  • Even with access administration and governance automation tooling (pre-AI), identifying and configuring rules/policies to address both least-privilege issues and access provisioning automation needs is simply too much work for most IAM programs. Applying access policy may be automated, but analyzing, modeling and configuring policies remain manual in most organizations.
  • Rapid advancement in AI capabilities, including (but not limited to) GenAI and agentic AI, makes AI more capable of processing high data volumes of access in most organizations. This can also deliver recommendations for access policy improvements (access modeling) more quickly and responsively to organization and IT system changes.
  • Most IAM programs have a security mandate to keep assigned access well-maintained and as close to the least-privilege principle as possible. Many successfully address access termination when an individual leaves the organization, but most are unable to successfully maintain good access hygiene overall, especially related to mover/transfer activity, even when using leading IGA tooling. AI for access administration enables faster response to changes and identification of hygiene issues to be addressed.
  • Most IAM programs also have a business enablement mandate to grant access that is justified as quickly as possible (right-time access). This enables their business to operate effectively, yet progress on the automation to accomplish this is slow in most organizations, with little to no “sight line” to fully achieving target outcomes. Applying AI can accelerate access automation efforts.
  • Lack of standards for how entitlements and permissions are managed across different systems prevents the IAM team, which has figured out how to standardize access for one system, from immediately applying to the next system. The sheer amount of access modeling and analysis needed is beyond the delivery capacity of most real-world IAM teams, but not beyond the capacity of AI methods.
Obstacles
  • Machine intelligence is no better than human intelligence at dealing with data that doesn’t exist. As a result, the value of AI to access administration in each organization will be limited to use cases where the organization can provide the necessary identity, entitlement and access event data to drive AI models. Organizations need to make improvements in IAM data management to realize full value from this innovation.
  • All AI is probabilistic rather than deterministic. It will not be able to recommend the right access for 100% of client use cases. Highly risk- and compliance-sensitive organizations may have difficulty getting to an acceptable comfort level with AI recommendations for access policies and decisions.
  • AI implementation is still expensive and complex, including model selection per use case, necessary tuning, and requirements to address trust, risk and security management (TRiSM). While capability is rapidly improving, the cost of entry to this capability for vendors and client companies remains high.
User Recommendations
  • Ask for AI-driven access administration capabilities from your IGA vendors. When this is not available, evaluate supplemental solutions.
  • Improve data management/engineering capability of IAM programs to improve both manual access administration and AI-facilitated access administration.
  • Test and implement AI-driven access administration improvements from IAM vendors. Evaluate the outcome primarily on its impact on the speed of delivering process improvements (do not expect 100% accuracy).
  • Expect technology vendors, including, but not limited to, IGA vendors, to incorporate AI methods and models into their solutions to help customers get more rapid and sustainable value. Use best-available AI models to improve both access provisioning/deprovisioning processes and access review/certification processes.
Sample Vendors
Delinea; Gurucul; IBM; Lumos; Nexis; Ping Identity (ForgeRock); Radiant Logic; SailPoint Technologies; Saviynt; Veza
Gartner Recommended Reading

At the Peak

CPS Secure Remote Access

Analysis By: Katell Thielemann
Benefit Rating: High
Market Penetration: 5% to 20% of target audience
Maturity: Emerging
Definition:
Cyber-physical systems (CPS) secure remote access solutions allow employees, contractors and OEMs to access production or mission-critical assets remotely for the purpose of safely and securely operating, maintaining or updating them. They provide a robust mechanism to verify users’ identity, enforce granular access policies for users and systems, ensure secure communications and track the integrity of the actions being taken.
Why This Is Important
Enterprises increasingly need to provide manufacturers, employees and contractors with secure remote access to production or mission-critical CPS. In the past, this was either done in an ad hoc way using consumer tools such as virtual network computing or TeamViewer without centralized policies, or via VPN and jump-server-based approaches. These approaches have proven to be increasingly unsecured and complex to manage.
Business Impact
CPS secure remote access solutions provide a robust mechanism to ensure only approved users can remotely granularly access CPS in production or mission-critical environments. They support multiple security controls such as sessions management/recording, file transfers with malware scanning, multifactor authentication (MFA), audit trails and least privilege over access, assets and sessions. But, importantly, they also allow production engineers to perform operations, maintenance and upgrades securely.
Drivers
  • Safety considerations: Some CPS are deployed in harsh environments or handle materials that could be hazardous to humans, so remote management can be a preferred option over deploying humans.
  • Contractual obligations: As OEMs sell equipment, they cannot have support teams on standby at each location; they routinely mandate remote access in their sales contracts to support SLAs. These OEMs also need to ensure that their own employees only access what they should.
  • Cost/productivity pressures: The ability to leverage the same labor pool and keep travel costs low to support multiple operational environments is central to cost control and productivity initiatives.
  • Competitive pressures: Competition is driving the race to automate and increase the quantity and quality of outputs. The ability to remotely manage assets has become a differentiator.
  • Production uptime and equipment maintenance/upgrades: The ability to keep production and mission-critical environments up and running without disruption is a key factor in remaining competitive.
  • Skilled labor pressures: Production engineers and industrial maintenance professionals are in short supply globally, so remote operations are often required due to the lack and/or cost of local professionals.
  • Training of new engineers and maintainers: To counter the lack of skilled labor, organizations often have to turn to training new recruits virtually, and CPS secure remote access solutions are increasingly used for that purpose.
  • Geographically dispersed setups: In verticals such as utilities, substations may be located across the country, making hands-on maintenance impossible
Obstacles
  • Security and risk management leaders are often not aware of shadow remote access that likely already exists throughout operational networks, particularly at field sites.
  • Concerns with adding point solutions have slowed adoption.
  • OEM-installed assets may require a 4G or 5G point-to-point solution, which may not be supported by the secure remote access solution.
  • Some vendors have been in the market for less than three years. Merger and acquisition activity is likely to occur, since these capabilities will remain in high demand as digital transformation efforts roll out more automation and enable more remote operations.
  • Lack of vertical-specific specialization can slow acceptance by production engineers.
  • Difficulties exist in defining and implementing strong onboarding, administration and access controls for remote users before deploying CPS secure remote access tools.
  • MFA is an effective protection control against the account takeover threat, but static MFA methods do not consider external context and risk signals in the same way that adaptive MFA approaches do. Most CPS secure remote access tools provide static MFA mechanisms, which is an improvement over not having MFA, but they don’t provide the range of context and risk signals that adaptive MFA would provide.
User Recommendations
  • Use CPS protection platforms to identify data flows to discover undocumented remote access capabilities.
  • Define the organization’s needs and use cases before selecting a solution. In some cases, an IT remote privileged access management (RPAM) tool will work for light-touch CPS access, but a CPS secure remote access solution will be needed if hands-on operations, maintenance or upgrades to equipment are needed.
  • Work closely with CPS asset custodians (such as production engineers or maintainers) to define policies that balance cybersecurity best practices such as MFA with operational and production needs.
  • Deploy a CPS protection platform to perform a full inventory of all remote connections across the entire organization, as shadow remote access likely exists throughout operational networks, particularly at field sites.
  • Remove older remote access solutions when deploying newer CPS secure remote access solutions. Organizations commonly deploy new solutions without focusing on what is left behind, and with the number of exploited VPN vulnerabilities growing, this could be a significant blind spot.
Sample Vendors
Claroty; Cyolo; Dispel; OTORIO; WALLIX; Xage Security
Gartner Recommended Reading

Coffee Shop Networking

Analysis By: Andrew Lerner, Jonathan Forest, Mike Leibovitz
Benefit Rating: Moderate
Market Penetration: 5% to 20% of target audience
Maturity: Adolescent
Definition:
“Coffee shop networking” is a combination of technologies that enables a simplified and consistent employee experience regardless of the employee’s location. The user experience is: grab a seat, connect, work from anywhere. The same experience applies whether the employee is in the office, at a coffee shop or working from home. Enterprises typically refer to coffee shop networking in the context of simplifying their branch office networks.
Why This Is Important
Network teams are interested in mimicking the employee experience of working at a coffee shop (or cafe) and extending that experience to employees within branch offices. Thus, coffee shop networking can improve employees’ experience accessing applications, simplify branch network infrastructure and potentially optimize network investments. It is, in part, a response to hybrid work environments and hoteling arrangements where employees are increasingly working anywhere and accessing applications primarily delivered from the cloud.
Business Impact
Coffee shop networking allows flexibility of work location and can simplify and streamline employee experience when accessing applications. This also allows a single consistent security posture irrespective of where the user chooses to work. This is particularly important as Gartner research indicates about half of employees are hybrid (employees who work remotely less than one day to four days a week in an average week).
Drivers
  • Coffee shop networking appeals to organizations embracing hybrid work styles and for which applications are primarily internet-based SaaS and public cloud, with limited footprint of on-premises apps.
  • Employees prefer a simple and consistent user experience when accessing corporate applications, regardless of where they are located.
  • Network and security teams want to deliver a simple, secure and consistent experience to hybrid working employees.
  • Enterprises often have experience with the underlying technology that enables coffee shop networking, including lightweight software-defined WAN (SD-WAN), zero-trust network access (ZTNA), digital experience monitoring and local Wi-Fi.
  • Some vendors are actively marketing this concept to users as a new and innovative approach.
  • Network teams are looking for ways to reduce or optimize costs for branch and remote workers. Coffee shop networking promises lower costs via reduction of private circuits or network/security equipment. However, whether the promise actually delivers depends on the use case.
  • Companies that rent office space (versus owning) where internet access is provided as a utility look to coffee shop networking. This also applies to hoteling arrangements where employees are assigned a desk but are required to be on-site at least a few days a week, which creates the need to work somewhere else.
  • Enterprises that already invest in ZTNA/security service edge solutions want to leverage that investment in the branch office — not only for remote workers.
Obstacles
  • Return-to-office (RTO) mandates and policies reduce the applicability of coffee shop networking implementations.
  • Coffee shop networking isn’t well-aligned with the requirements of enterprises that haven’t embraced a hybrid working model.
  • Coffee shop networking doesn’t efficiently address requirements for large amounts of nonusers connecting to networks, including Internet of Things and operational technology (OT), such as printers, badge readers and digital signage.
  • Lack of adoption of SaaS or public cloud services reduces the value of coffee shop networking.
  • It is difficult to justify the shift to the coffee shop approach if there are existing investments in next-generation firewall, SD-WAN, and the like that are adequate and aren’t due for refresh.
  • Enterprises that avoid using internet connectivity due to either privacy, security or performance concerns are unlikely to adopt this model.
  • Wireless coverage and/or capacity challenges impede successful deployment of coffee shop networking.
User Recommendations
  • Prefer coffee shop networking for use cases when your organization is cloud-first, internet-first, WLAN-first, focused on hybrid working and has a north-south traffic pattern for users.
  • Include coffee shop networking as an architectural option to business leaders when building, refreshing or modernizing branch or campus infrastructures.
Sample Vendors
Cloudbrink; Fortinet; Hewlett Packard Enterprise; Netskope; Zscaler
Gartner Recommended Reading

CPS Protection Platforms

Analysis By: Katell Thielemann
Benefit Rating: High
Market Penetration: 20% to 50% of target audience
Maturity: Early mainstream
Definition:
Cyber-physical systems (CPS) protection platforms use knowledge of industrial protocols, operational/production network packets or traffic metadata, and physical process asset behavior to discover, categorize, map and protect CPS in production or mission-critical environments outside of enterprise IT environments.
Why This Is Important
CPS protection platforms help secure connected assets in production or mission-critical environments outside enterprise IT. While the traditional approach has been network-centric in nature (anchored by the Purdue Model and network segmentation approaches), CPS protection platforms enable an asset-centric view of security. Leading with asset discovery and network topology mapping allows for the addition of other cybersecurity capabilities, such as threat management, vulnerability management and risk scoring.
Business Impact
Because cyber-physical systems underpin production and mission-critical workloads, cyberattacks on them can lead to loss of visibility or loss of control of physical processes. These outcomes, in turn, can have devastating impacts on revenue, environmental conditions or human safety. To reduce these cyber risks, organizations need to know what CPS assets they have, how they communicate, what exploitable vulnerabilities they have and what steps to take to protect them.
Drivers
CPS protection platforms are becoming core to CPS security because:
  • The attack surface is growing: CPS are usually core value creation assets and, if they go down, they halt production or derail missions. The more connected they become, the more they expand the attack surface. This increasingly makes them attractive targets for ransomware, industrial espionage or geopolitically motivated attacks. From operational disruptions of pipeline operators to halted machinery at shipbuilders, the number of disclosed attacks continue to rise.
  • Threats are on the rise: malware purposely built for industrial environments such as INDUSTROYER.V2 and Pipedream are emerging.
  • More vulnerabilities are surfacing: yet remain difficult to manage as CPS cannot be patched at will.
  • More regulations, directives and frameworks are emerging: due to increased threats to critical infrastructure-related organizations, governments are recognizing that the ubiquitous CPS technology landscape supporting them is key to national security and economic prosperity.
  • Manual asset inventories are inefficient and costly.
  • Cybersecurity tools are inappropriate for many CPS environments.
  • An expanding set of verticals are paying attention to security.
Obstacles
  • Most CPS protection platforms require sensors to passively probe network traffic initially. Deciding where to deploy these sensors is not only necessary to ensure assets can be discovered, but also labor-intensive for the cybersecurity and production engineering teams.
  • Some vertical industries, such as healthcare, defense, rail or maritime transportation, have unique security needs due to their distinctive systems and protocols, sales cycles, or safety and security cultures. Finding vendors with specialized knowledge can be challenging.
  • The variety of pricing options across vendors — and across channel partners for the same product — is confusing to end users, who also increasingly face double-digit price increases at renewal time.
  • Deployment complexity and high product costs.
User Recommendations
  • Evaluate where they are in their journey and, specifically, assess whether they have an inventory of all CPS assets in their organization. They should also determine whether they have solutions for vulnerability management, threat intelligence or specialized protection capabilities that IT-centric tools cannot address.
  • Evaluate vendor capabilities and select a limited number of CPS protection platforms to conduct controlled proofs of value to see which one performs best in their environment.
  • Work closely with business teams to prioritize security mitigation efforts, update governance models based on initial findings and then iterate accordingly.
Sample Vendors
Armis; Claroty; Dragos; Forescout Technologies; Microsoft; Nozomi Networks; Tenable
Gartner Recommended Reading

Crypto-Agility

Analysis By: Mark Horvath
Benefit Rating: High
Market Penetration: 5% to 20% of target audience
Maturity: Adolescent
Definition:
Crypto-agility is the capability to transparently swap out encryption algorithms and related artifacts in an application, replacing them with different and, presumably, safer algorithms.
Why This Is Important
  • Mandates and regulations (such as PCI DSS 4.0.1, DORA Commission Delegated Regulation [EU] 2024/1774 Section 6.4 and the proposals to increase the amount of certificate renewals) often require changes to existing cryptographic systems and policies. This increasing scale and complexity demands more scalable and dynamic cryptographic management.
  • The National Institute of Standards and Technology (NIST) has standardized its first suite of quantum-safe alternatives, CRYSTALS-Kyber, CRYSTALS-Dilithium, SPHINCS+, and FALCON (for ML-KEM, ML-DSA, SLH-DSA, and FN-DSA standards respectively), for widespread use. HQC, an alternative to lattice, is scheduled to be approved in 2027. These algorithms will form the core of crypto-agile alternatives for vendors and developers going forward.
Business Impact
Given the increased demands for classical cryptography to achieve operational efficiencies and cost reductions (e.g., agility through policy and automation), and the coming threat of quantum computing, Gartner expects crypto-agility to be a significant differentiator for technology vendors. Businesses impacted by the changes to cryptography will need to evaluate and execute the following activities:
  • Applications using encryption or public-key infrastructure (PKI) need visibility and the ability to automatically update or change by policy. Data about algorithms, key sizes, expiration dates and uses must be tracked with a metadata database.
  • Suitable replacement implementations must be identified for applications and use cases that match performance and security expectations.
  • New algorithms are not drop-in replacements for existing cryptography, so alternatives must be tested and replacement policies must be generated.
  • Vendor cryptography products must be identified, and vendors will need to provide some level of crypto-agility consistent with the business objectives.
Drivers
  • Cryptography in vendor products will need to be identified as the regulatory and security needs of the business evolve, and vendors will need to provide a schedule for updates and replacement.
  • Most organizations that have inventoried their cryptographic metadata have found they already have considerable PKI technical debt (e.g., expired certificates, deprecated algorithms, short keys). Cleaning that up will substantially lower the organization’s risk profile.
  • The development of quantum computers capable of damaging cryptography through Shor’s or Grover’s algorithms is estimated to be five to seven years away. This is much shorter than the typical life span of sensitive information found in most organizations, leading to data exposure of sensitive data. Keybreaking with Shor’s algorithm goes linearly with key size, but is limited by the number of available qubits; once the algorithm is running, larger key sizes will fall quickly, leading to a short runway to implement changes.
  • Early adopters of new algorithms have found that performance can vary significantly with the implementation. Most have reported race conditions, slower performance and other issues related to timing. Moving applications to a crypto-agile posture is a good way to test implementations to find the right mix of performance and security.
  • Government organizations are beginning to require a quantum-safe encryption strategy for vendors selling to them (e.g., U.S. NSM-10, EO-14028). This includes all products or code in the final product, including open-source software (OSS) and other vendor products. As with a software bill of materials, this significantly expands the scope of these orders to include many vendors not otherwise selling directly to the government.
  • New algorithms have additional uses that can foster novel business cases (e.g., stateful signatures, homomorphic encryption).
Obstacles
  • Cryptographic technical debt (e.g., use of hard coded secrets and algorithms, deprecated algorithms, etc.) often have very low visibility in IT, and thereby liable to be undervalued.
  • Many organizations don’t know how to inventory their cryptographic usage, relying on vendors or struggling themselves.
  • Crypto-agility is fundamentally a developer-driven effort, but developers often lack architectures, patterns, libraries and other artifacts needed to successfully implement crypto-agile applications.
  • Many organizations lack the expertise needed to lead this kind of cryptographic hygiene, delaying action and becoming blind to risks.
  • Most cryptographic systems have source/destination dependencies and stakeholders have difficulty orchestrating change across all dependent parties in a coordinated and mutually beneficial way.
User Recommendations
  • Start building a cryptographic inventory sooner rather than later. This will help identify key systems and data, allowing a controlled rollover to newer encryption and help to prioritize technical debt.
  • Experiment with various libraries and implementations of the NIST algorithms to determine the effects on your infrastructure.
  • Create standard patterns, policies, architectures and other developer artifacts to make it easier to integrate crypto-agility into existing development plans.
  • Ask vendors what their plans are for replacing algorithms, and when quantum-safe versions of their products will be available.
  • Evaluate crypto dependencies in applications and favor crypto-agile implementations in both vendor purchases and in creating custom-based applications.
  • Automate key and certificate management and favor a policy-based approach for key applications so they can be secure even as the market evolves.
Sample Vendors
Crypto4A; Cyberark; DigiCert; Entrust; IBM; InfoSec Global; ISARA; Keyfactor; Sectigo; Thales
Gartner Recommended Reading

CAEP

Analysis By: Erik Wahlstrom
Benefit Rating: High
Market Penetration: 1% to 5% of target audience
Maturity: Emerging
Definition:
The Continuous Access Evaluation Profile (CAEP) of the Shared Signals and Events (SSE) Framework defines mechanisms to communicate security events between trusted parties to enable continuous runtime access decisions. CAEP is a standard that enables identity and access management (IAM), security tools, and the applications and services they protect to continually share security signals to enable session management, mitigate breaches and reinforce policies in a decentralized environment.
Why This Is Important
  • Single sign-on is well-established in organizations’ hybrid environments, but single logout and continuous session management have been elusive so far.
  • Sharing risk events between tools and applications is essential for an interconnected world built on distributed trust.
  • CAEP helps resolve challenges with long-token lifetimes, step-up authentication, the continuous assessment of assurance levels and device postures. It also provides mechanisms to help address identity life cycle events.
Business Impact
Sharing security signals (CAEP events) increases security in loosely connected services and enables continuous control, higher assurance levels, and a better user experience across a hybrid and decentralized IT environment. Leveraging CAEP events as a response to changes or detected threats enables applications and IAM tools to take actions such as termination of a session, reevaluation of claims, step-up authentication, and management of user and entitlement life cycle.
Drivers
  • Modern IAM requires event-based and runtime communication mechanisms to evaluate and establish trust, and orchestrates the right tools for the use cases. For example, an event that says a user is no longer valid or a device’s out-of-compliance security posture must trigger other IAM tools to respond to that event, manage affected identities and reevaluate access decisions in runtime.
  • The increasing decentralization of applications and services in organizations’ hybrid and multicloud environments makes continuous session management imperative but hard or impossible to achieve. For example, single logout integrations have historically been impossible to deploy at scale.
  • Organizations need continuous adaptive trust (CAT) and an interoperable way to react to risk events that happen during sessions to understand what’s going on in applications after users are authenticated. At scale, this can only be achieved using identity standards like CAEP.
  • Using CAEP to continuously feed signals into an adaptive access engine enables the engine to have more data and thereby make more accurate access decisions.
  • The IAM community is starting to implement CAEP. There are 20+ implementations, where a handful are generally available.
  • Gartner, together with the OpenID Foundation, hosted three successful interoperability sessions with 19 CAEP implementations at the Gartner IAM Summit during 2024 and 2025, showing the protocols’ utility, interoperability and implementability (see Gartner Identity & Access Management Summit). During and after the sessions, Gartner clients emphasized the importance of this unmet market need.
Obstacles
  • CAEP is still not commonly known and understood by IAM professionals, or application and service developers.
  • Although implementation has started, all identity standards take a long time to be commonly implemented. Identity standards have a “chicken and egg” problem before they reach wide deployment. Target applications wait to see if a standard takes off, and IAM vendors wait for wide support in their target applications. This is also true for CAEP. The number of implementers is growing but still from small numbers.
  • Another implication of the slow market saturation of new identity standards is the market need for tooling that can help modernize legacy tools and integrations by brokering and translating CAEP events to nonsupporting environments. Gartner is only aware of two such brokers at the moment: SGLN and IBM.
User Recommendations
  • Define an IAM architecture that supports centralized control in a decentralized environment by embracing open standards. CAEP complements other modern identity protocols such as OpenID Connect, System for Cross-Domain Identity Management (SCIM), JSON Web Tokens (JWTs) that enable it.
  • Require IAM vendors to support CAEP. Gartner expects CAEP and other related standards to share security and risk events across decentralized systems to become increasingly important going forward. For example, the SCIM Events and Risk Incident Sharing and Coordination (RISC) profiles of the OpenID SSE Framework specification.
  • Add CAEP as an optional RFP criterion when procuring new applications, specifically SaaS apps. Support is still emerging, but Gartner expects the adoption of CAEP to grow. Configuring a new application in an IAM tool should, over time, include standardized life cycle management, single sign-on and event sharing.
Sample Vendors
Apple; Cisco; Google; IBM; Jamf; Okta; Omnissa; SailPoint; SGNL; Thales
Gartner Recommended Reading

Universal ZTNA

Analysis By: Andrew Lerner, John Watts
Benefit Rating: High
Market Penetration: Less than 1% of target audience
Maturity: Emerging
Definition:
Universal zero-trust network access (ZTNA) extends ZTNA technologies to use cases beyond remote access to support local enforcement in campus and branch “on-premises” locations. Although “universal ZTNA” describes a broad ZTNA implementation, the original ZTNA definition was not limited to remote access use cases.
Why This Is Important
Universal ZTNA unifies access control. It extends ZTNA products from remote access deployments to campus environments and creates several benefits for enterprises, including security gap elimination, unified policy, enhanced visibility, simplified operations and modernized pricing models.
Business Impact
Hybrid working creates challenges for employees and administrators due to inconsistent network access implementations, which can lead to lost productivity and increase the likelihood of security and networking incidents. Universal ZTNA helps to streamline network and security policies across multiple environments.
Drivers
  • IT teams that aim to deliver a consistent end-user experience for accessing corporate resources, regardless of their physical location.
  • IT teams that desire a unified security policy based on identity that allows access to applications regardless of the user or device’s physical location.
  • Organizations that have deployed ZTNA for remote workers and want to extend consistent security policy for users while on-premises.
  • Organizations that are looking to simplify their campus networks by moving some of the security controls to the ZTNA software stack.
  • Organizations that are looking to replace or refresh their network access control (NAC) implementations with a more software-centric, identity-based and dynamic mechanism.
  • Organizations that are looking to enable near-real-time adaptive access controls based on the risk of the user and device, beyond relying on the physical location or Internet Protocol (IP) address of a user or device.
  • Vendors are aggressively marketing universal ZTNA.
Obstacles
  • Investments in campus networking are usually driven by hardware refresh cycles, which are long, often six years and beyond in the enterprise.
  • Steering traffic to enforcement points may require network redesign and/or create latency or complexity, impacting performance.
  • There are only a few vendors with mature universal ZTNA offerings. Specifically, shortcomings include unmanaged devices and unauthenticated users, including unmanaged operational technologies (OT) and Internet of Things (IoT).
  • Siloed network and security teams result in organizations overlooking the opportunity to unify remote access and campus security.
  • Organizations are not ready to embrace fully adaptive, dynamic access policies everywhere due to budgetary constraints, legacy technology supporting internal or external audit findings.
  • IT management tools for patching and software distribution may need modernization to support reaching isolated endpoints, even in campus locations.
  • There is an increased outage risk that a ZTNA service failure (or security vulnerability) will impact both remote and campus work simultaneously.
  • Establishing a granular user-to-application security policy is difficult for many enterprises to scale to all applications.
User Recommendations
  • Pilot universal ZTNA deployments by extending existing remote access deployments to smaller campus or branch environments (with limited OT), in order to determine feasibility.
  • Phase universal ZTNA deployments by starting with secure remote-user-access use cases before extending to on-premises use cases.
  • Prefer vendors who provide unified policy from a single management plane and offer both on-premises and cloud-hosted enforcement points to help avoid suboptimal traffic routing.
  • Prefer cloud-based management for universal ZTNA deployments to gain faster access to new capabilities from the vendor and avoid having to manage the management system.
  • Align universal ZTNA product selection and deployment with secure access service edge (SASE) and security service edge (SSE) initiatives.
  • Develop and test a resiliency plan to prepare for unavailable enforcement points and resources that are not reachable (for example, local policy caching when cloud resources are not available).
Sample Vendors
Appgate; Cloud Brink; Extreme Networks; Fortinet; Versa Networks; Zscaler
Gartner Recommended Reading

Postquantum Cryptography

Analysis By: Mark Horvath, Matthew Brisse, Sarah Almond
Benefit Rating: High
Market Penetration: 5% to 20% of target audience
Maturity: Adolescent
Definition:
Postquantum cryptography (PQC), also called quantum-safe cryptography, is a set of algorithms designed to secure against both classical and quantum-computing attacks. PQC will replace existing asymmetric encryption, which will be broken over the next decade, deprecating existing classical encryption methodologies and processes.
Why This Is Important
  • Existing asymmetric algorithms like Diffie-Hellman, RSA and ECC are vulnerable to cryptographically relevant quantum computers and will be unsafe to use by the end of the current decade. As a result, common cryptographic functions such as digital signatures, public key encryption, blockchains and key exchanges will require replacement.
  • PQC offers organizations a level of cryptographic protection that will remain strong as quantum computers enter the mainstream.
Business Impact
  • The advent of stronger quantum computers means that existing asymmetric algorithms must be replaced with quantum-safe ones. This includes all network, file and data encryption, identity and access management (IAM) and secure messaging, as well as any other uses of asymmetric cryptography.
  • No drop-in implementations of PQC are available for existing cryptographic algorithms, leading to discovery, categorization and reimplementation efforts.
  • New algorithms have different performance characteristics, so current applications must be retested and, in some cases, rewritten.
  • Secondary uses of new encryption (e.g., homomorphic encryption, stateful signatures) will offer new business opportunities beyond data protection. For example, homomorphic encryption allows third parties to run mathematical functions on data while it’s encrypted, but the decrypted result retains all the work done by the third party.
  • Data should be secure from quantum computer attacks for the foreseeable future once an organization adopts PQC.
Drivers
  • Existing asymmetric encryption algorithms will become vulnerable to quantum-based decryption attacks by the end of the decade, potentially requiring reencryption of all data where the risk of exposure of the symmetric keys or tokens is considered important.
  • Governments around the world are preparing and issuing mandates and legal frameworks requiring government agencies and enterprises to start devising PQC strategies. For example, in the U.S., the National Quantum Initiative Act and the Cyber Security Research and Development Act require owners and operators of national security systems and organizations supplying to the U.S. government to start using postquantum algorithms.
  • “Harvest now and decrypt later” attacks are an ongoing concern, especially within the scope of the advanced persistent threat. This drives the urgency to implement PQC security measures sooner rather than later.
Obstacles
  • Most organizations don’t know how cryptography functions within their operations, where keys and algorithms are used, or how secrets are stored and managed. Swapping them out for new algorithms will be challenging.
  • New algorithms have different characteristics than existing algorithms, including ciphertext sizes and different encryption and decryption times. Far from being drop-in replacements, new cryptography will require some experimentation and testing to maintain the dependent application performance envelope.
  • PQC algorithms will require new standards. Standards like PKCS and TLS handshakes will be modified to accept the longer key lengths and other attributes of PQC.
  • Most vendors are typically unprepared when the time comes to upgrade the cryptography and often require some pushing from their clients to recognize the demand.
  • Some crucial systems (e.g., IAM, data security platforms, network equipment) lack built-in crypto-agility.
  • New cryptography gains strength through public review (it’s the keys that are secret, not the algorithms). This can be a very long, uneven process, with some proposals being dropped unexpectedly or needing additional rework, which can undermine public confidence.
User Recommendations
  • Develop cryptography policies for easing the transition to new algorithms. Adopting a policy-based program for cryptographic replacement will reduce confusion and arbitrary choices and increase manageability.
  • Build a cryptographic metadata database of all in-use cryptographic algorithms. Use it to perform an exercise for data, identifying the expected end-of-life targets in the short-, mid- and long-term time scales, and create a key life cycle policy to reflect risks to asymmetric keys.
  • Implement crypto-agile application development and stage to production after extensive testing. Vet and test new PQC algorithms to understand their characteristics, uses and performance.
  • Implement crypto-agility initiatives with an object-based approach to address future changes in PQC algorithm updates and replacement.
Sample Vendors
Crypto4A; CyberArk; DigiCert; IBM; InfoSec Global; ISARA; Keyfactor; SandboxAQ; Sectigo; Thales
Gartner Recommended Reading

Sliding into the Trough

CPS Zoning and Segmentation

Analysis By: Katell Thielemann, Thomas Lintemuth
Benefit Rating: High
Market Penetration: 20% to 50% of target audience
Maturity: Early mainstream
Definition:
Cyber-physical systems (CPS) zoning and segmentation includes solutions that discover existing network topologies, manage firewalls and create enclaves that cloak networks or optimize zones and conduits to prevent the spread of malware or sensitive-data exfiltration.
Why This Is Important
CPS zoning and segmentation products help map existing network configurations, understand firewall settings, hide CPS networks from discovery on the internet, create zones and manage traffic and rules for traffic between those zones. They also ensure CPS only talk to each other if necessary. This helps reduce the chances of intellectual property exfiltration and loss of visibility or control over physical processes via malware:
  • Traversing from IT systems to production or mission-critical environments (north-south)
  • Moving laterally (east-west)
  • Being deployed by insider threat actors using physical access to CPS (south-north)
Business Impact
  • Improved operational resilience by creating logical boundaries separating sites as well as process control systems from business networks and each other.
  • Improved partitioning of separate production lines to create logical segments.
  • Optimized resource deployment by using risk- and criticality-based assessments to create risk profiles and security zones.
  • Optimized access control within and between zones to ensure only authorized individuals or systems can access assets or perform tasks.
  • Detailed monitoring and logging of activities to support incident detection and response.
Drivers
  • Evolving threat landscape: An increase in attacks, notably ransomware-related, has led companies to proactively shut down operations out of concern for potential malware spread to CPS environments.
  • Containment: Enterprises are more aware that having very large trust zones at a facility increases risks. Dividing a network into smaller segments or zones makes it harder for attackers to move laterally.
  • Best practices and security frameworks recommendations: Zoning and segmentation is a core recommendation in industry-recognized frameworks such as NIST SP 800-82 Rev. 3 and ISA/IEC 62443.
  • Compliance: Several industry regulations and standards, such as NERC-CIP, require organizations to implement network segmentation as part of their security measures. Compliance with these regulations is essential for avoiding penalties, maintaining customer trust and protecting sensitive data.
  • Improved performance: Segmentation can improve network performance by reducing congestion and optimizing traffic flow.
  • Scalability: Zoning and segmentation allow for new devices or systems to be added to specific segments without impacting the entire network.
  • Cloud-based solutions: Business requirements to connect CPS to cloud-based solutions are increasing.
Obstacles
  • No security by design: Many legacy systems are not designed with security in mind and may lack necessary capabilities to support effective zoning and segmentation without disrupting critical operations.
  • Lack of visibility and complexity: Lack of visibility into the network and its components as well as potentially unknown interdependencies, where different components or processes rely on each other to function properly, pose a hurdle.
  • Operational impact: Zoning and segmentation may introduce additional network complexity.
  • Limited resources and expertise: Many organizations full of CPS lack budgets and skilled personnel with the required security and engineering know-how.
  • Operational constraints: In certain critical infrastructure sectors, such as energy or manufacturing, downtime or disruptions can have significant financial and safety implications.
  • Fear of the unknown: Production or plant owners may be wary that cybersecurity efforts will introduce production risks.
User Recommendations
  • Deploy CPS protection platforms to discover all CPS assets in their environments and gain visibility over existing network topologies.
  • Work with engineering teams to architect security zones around physical process loops, criticality, safety, risk profiles and operational constraints. Each zone should have a specific purpose and level of security controls.
  • Use firewalls, routers and switches to enforce strict segmentation between different security zones.
  • Use network segmentation technologies like virtual LAN to create isolated network segments and control traffic flow between zones.
  • Deploy cloaking or obfuscation solutions.
  • Apply the principle of least privilege to limit user access rights and privileges to only what is necessary for specific roles.
  • Monitor and log network traffic within each security zone. This enables the detection of suspicious activities and helps in incident response.
Sample Vendors
Barracuda; Blue Ridge Networks; Dragos (Network Perception); Elisity; SecLab; Zero Networks
Gartner Recommended Reading

IoT Authentication

Analysis By: Michael Kelley
Benefit Rating: High
Market Penetration: 5% to 20% of target audience
Maturity: Adolescent
Definition:
Internet of Things (IoT) authentication is the mechanism of establishing trust in the identity of an entity (typically a device) interacting with other entities, such as devices, applications, cloud services or gateways operating in an IoT environment. Authentication in IoT takes into account potential resource constraints of IoT devices, the bandwidth limitations of networks they operate within and the automated nature of interaction among various IoT entities.
Why This Is Important
From automotive to smart homes and smart buildings to the smart consumer devices market to industrial IoT (IIoT) and cyber-physical systems (CPS), IoT is expanding as a market. These connected devices can bridge cyber and physical worlds and open up entirely new threat vectors. Among other requirements like encryption and culture, sound IoT security requires a strong identity for IoT devices coupled with strong IoT authentication, with the goal of mitigating and minimizing cyberattacks and vulnerabilities.
Business Impact
IoT authentication can mitigate:
  • Privacy issues that directly impact liability and brand reputation for consumer devices.
  • Attacks against connected devices that could lead to disruption in product or service offerings.
  • Attacks against industrial devices that lead to operational impacts and, potentially, catastrophic events in safety-critical production areas.
IoT authentication is foundational for protection for newer mechanisms in the market, including IoT applications and agentic AI components.
Drivers
  • The explosive growth of IoT and IIoT is creating connectivity between humans and machines and machines to machines in an unprecedented way.
  • Long-term spending growth will be led by automotive (8% compound annual growth rate [CAGR]), manufacturing and natural resources (10% CAGR), and transportation (11% CAGR). Organizations are investing in IoT technologies to drive cost optimization and operational efficiency (see Forecast: Internet of Things, Endpoints and Communications, Worldwide, 2022-2032, 1Q25 Update).
  • Ongoing work for defining secure credential storage and rotation approaches for IoT authentication is helping to drive the market.
  • Many use cases stemming from IoT are changing traditional business models, such as continued developments in telehealth.
  • The popularity of public-key infrastructure (PKI) as an identification approach is helping enable adoption. Certificates continue to be the primary way devices are identified and authenticated. PKI vendor investments and focus in this space include CyberArk (Venafi), DigiCert, Entrust, Keyfactor and Sectigo, leveraging their PKI capabilities to solve IoT authentication use cases.
  • Standards helping to provide consistent approaches and solidifying investments, viability and utility include the Connectivity Standards Alliance’s Matter; RFC 8628, the OAuth 2.0 Device Authorization Grant extension; and the ACE working group within the Internet Engineering Task Force.
Obstacles
  • The IoT landscape is complex, including determining the right people, process and technology to employ due to a fragmented market, with highly industry-specific requirements, and difficulties productizing due to inconsistent device types and operating environments.
  • The fragility of many IIoT environments, including the potential for abuse and catastrophic impact, will drive the continuation of proprietary and isolated approaches for authentication in cyber-physical environments.
  • Some authentication methods are not good candidates due to certain IoT devices that are resource- or feature-constrained with low computing power and limited secure storage capacity.
  • Many organizations have challenges based on the variety of different types of IoT devices in their environment.
  • Support of authentication methods via IoT platforms is immature or incomplete. Use-case areas, such as IIoT, have protocols that are not interoperable with each other and often not operable with standards like TCP/IP, creating ongoing challenges for authentication approaches.
User Recommendations
  • Catalog and establish capabilities for each category of device in its IoT network.
  • Evaluate and adopt authentication frameworks that support the range of device types across the IoT realms in operation.
  • Ensure that policy and process for authentication in IIoT environments continue to prioritize safety over interoperability, including traffic isolation.
  • Use trusted computing techniques, such as hardware root of trust, that help to protect against physical attacks on devices and sensors, as well as against the external software attacks that could enable unauthorized reading, analyzing and manipulating of software code.
  • Educate leadership on the regulatory and privacy risks associated with IoT. Identify use cases where the high cost of people or processes in existing approaches would justify investment in IoT solutions in order to secure funding for tools.
  • Use fusion teams to manage the disparate technical and regulatory requirements of IoT projects and implementations (see Fusion Teams: A Proven Model for Digital Delivery).
Sample Vendors
Akeyless; CyberArk (Venafi); DigiCert; Entrust; IN Groupe (Nexus); Keyfactor; Microsoft; Phosphorus; Sectigo; Xage Security
Gartner Recommended Reading

Decentralized Identity

Analysis By: Michael Kelley, Akif Khan, Arthur Mickoleit
Benefit Rating: Transformational
Market Penetration: 5% to 20% of target audience
Maturity: Emerging
Definition:
Decentralized identity (DCI) democratizes digital identity by decentralizing both the storage and the use of identity data. The primary benefits of DCI are privacy, anonymity and user autonomy. DCI tools include an identity trust fabric, a digital wallet, which is tied to an entity (user), and verifiable credentials (VCs), which represent identity attributes used to prove identity claims.
Why This Is Important
DCI can help to solve problems related to identity verification, account takeovers, fraud, privacy and security. It is driven by VCs, which represent proofs for claims about identity attributes, like employment status, citizenship or authorizations to access applications and data. But the process of doing this with DCI, compared with the real world, represents magnitudes of improvement in terms of efficiency, cost and assurance.
Business Impact
Users gain greater control of their identities and data, and service providers (SPs) gain higher trust, speed to value and confidence, as well as lower exposure to risk from identity data leaks. Currently, SPs collect huge amounts of identity information about users for every interaction to increase assurance to an acceptable level. DCI can provide trust, security, privacy, convenience and portability of identity data for end users without needing centralized data, thereby reducing risks of data breaches, account takeovers and privacy compliance violations.
Drivers
  • Vendor investments in DCI: In addition to influential vendors (such as IBM, Microsoft and Ping Identity) making significant investments in DCI, Gartner has been tracking more than 80 startups or established vendors of DCI technologies and DCI components.
  • Government activity: Public sectors are increasingly shaping DCI trends. The EU has ratified eIDAS 2.0, which mandates the provisioning of identity wallets (used in DCI) to citizens by 2026. Other national, regional and local authorities are exploring and investing in DCI use cases across public and private sectors. Examples include Finland, the U.K.’s National Health Service, Buenos Aires in Argentina and the Basque Country region in Spain.
  • Regulations: Countries continue to formalize requirements for user privacy, establishing regulations for collecting and securing large amounts of user data. DCI complies with privacy regulations through decentralizing user data. In addition, basic use cases for know your customer (KYC) and anti-money laundering are being developed for DCI use cases.
  • Client and overall market interest in DCI: Interest is increasing due to the momentum of companies beginning to use DCI approaches to enable new digital business opportunities while maintaining client privacy.
  • Standards: Standards are maturing, led by entities such as the World Wide Web Consortium (W3C), Trust Over IP, the OpenWallet Foundation and OpenID for Verifiable Credentials (OID4VC) to create a consistent approach to DCI.
  • User experience (UX): Asking users to repeatedly go through identity verification (IDV) and affirmation processes for every new online interaction with an SP is a broken model. Significant friction can be removed from UX if users could verify once and then assert their identity to each new SP, as needed, using an identity wallet with full control over their identity data. DCI can make high-trust IDV available to a larger number of SPs without having to invest in discrete IDV tools.
Obstacles
  • Authority of issuers: Ensuring that an organization has the authority to issue a VC (such as only an accredited facility issuing educational credentials) is a challenge.
  • Infrastructure standardization: Part of the process of building out DCI is having standard and straightforward processes for adding issuers of VCs as well as validators for any DCI network; uniformity will be required to drive adoption.
  • Interoperability: Most development is taking place in pockets, and standards are maturing slowly.
  • Technical challenge: Concerns exist about performance, cryptographic key management, scalability, maturity and wallet standards.
  • Regulations: More work is required for how verifiable claims can be used in regulated use cases, such as driver’s license and other government records or KYC and AML, as required in financial services.
  • Security: Identity wallets must enforce strong authentication controls to ensure that only the person whose identity attributes are held within the wallet can make identity assertions. Wallet recovery processes must also be secure.
User Recommendations
  • Explore use cases by identifying tasks and processes that are expensive, complex and time-consuming in the real world, which will benefit from a VC approach.
  • Follow government progress around use cases for citizen IDs for bootstrap opportunities, as well as the various open-source initiatives like those from Walt.ID, SpruceID, etc.
  • Track new developments in emerging standards like Trust DID Web (did:tdw) and Key Event Receipt Infrastructure (KERI), which may help to address some of the technical challenges associated with decentralized trust infrastructure and registries.
  • Observe the development of organization credentials taking place with verifiable legal entity identifiers from the Global Legal Entity Identifier Foundation for the potential of establishing authoritative VC issuers.
  • Be prepared for early disruption in the DCI market. Gartner expects some chaos with mergers and acquisitions, and vendors exiting the business.
Sample Vendors
1Kosmos; Avast; IBM; IdRamp; Interac; Lissi; Microsoft; Ping Identity; Scytáles
Gartner Recommended Reading

Security Service Edge

Analysis By: Dale Koeppen, John Watts
Benefit Rating: High
Market Penetration: 5% to 20% of target audience
Maturity: Early mainstream
Definition:
Security service edge (SSE) secures access to the web, SaaS applications and private applications. Capabilities include adaptive access control, data security, visibility and compliance. Further capabilities include an advanced threat defense and acceptable use control enforced by network-based and API-based integrations. SSE is primarily delivered as a cloud-based service and may include on-premises or endpoint agent-based components.
Why This Is Important
  • SSE offerings unify access-related security functions to improve flexibility in securing usage of web and cloud services and remote work.
  • SSE offerings, primarily delivered from the cloud, combine a core of secure web gateway (SWG), cloud access security broker (CASB) and zero-trust network access (ZTNA).
  • SSE pairs with software-defined WAN (SD-WAN) to simplify networking and security operations when organizations pursue a secure access service edge (SASE) architecture.
Business Impact
Organizations use a strategic hybrid adoption model for key business applications, embracing public cloud for critical services while maintaining private applications in hosted environments and private tenancies within public cloud. SSE supports all users, enforcing consistent access security policies for web, cloud and private app access. SSE simplifies administration by unifying multiple access products and provides improved visibility into user actions on one platform.
Drivers
  • Organizations adoption of public cloud services continues to augment or replace on-premises applications, driving the need to secure user, application and enterprise data that is distributed and requires secure access. SSE enables flexible, primarily cloud-based security for hybrid workers and devices without being tied to on-premises network infrastructure and connectivity.
  • Traditional SWG and VPN offerings, whether hardware or virtual, restrict the ability to support a vast, dispersed workforce. To run resource-intensive security processes and to scale concurrently require a cloud-based approach to enhance performance and reduce traffic bottlenecks at the network edge.
  • A significant amount of critical business processes and data are now delivered as SaaS for many enterprises, which creates a need to perform data loss prevention (DLP) on data located in, going to and leaving these SaaS platforms.
  • Administrators lose visibility of user traffic when users are not connected to enterprise-owned networks, but need to retain configuration and monitoring for this traffic, irrespective of the users location.
  • Organizations want to reduce complexity and the number of point vendors enforcing secure access policies, including fewer endpoint agents. This also means applying controls such as DLP, advanced threat defense and remote browser isolation to secure more use cases from a single provider.
  • Organizations that cannot dictate the choice of their network edge provider (e.g., SD-WAN), or do not want to migrate from existing providers, need flexibility to choose to integrate security services independent of SD-WAN for their SASE requirements.
  • Organizations aim to lessen their reliance on hardware-centric security solutions, typically associated with capital expenditures. By adopting SSE, they can minimize hardware needs and shift to an operational expenditure model, offering a more predictable and consistent budget forecast.
Obstacles
  • Vendors may excel in some areas and lag in others as the market grows by merging capabilities. They are quickly moving to SASE platform solutions but may lack strong integration with their own SSE or SD-WAN capabilities.
  • Some vendors lack adequate DLP features to manage business risks.
  • Cloud-centric SSE typically doesn’t cover all requirements that on-premises controls, like segmentation and inspection of lateral traffic on-site, can meet.
  • Organizations worry about the effect of service uptime, availability and responsiveness that are exacerbated by weak SLAs and limited local features on performance and availability. Some vendors restrict client points of presence (POPs).
  • Migrating to ZTNA capabilities in SSE from a VPN increases costs and may not be compatible with all applications.
  • End-of-term price hikes for SSE-as-a-service offerings drive organizations to assess cost versus value, leading them to spend time and money to replace incumbent vendors.
User Recommendations
  • Exploit this converged market, consolidate vendors and cut complexity as contracts renew for SWGs and CASBs while replacing VPNs with a ZTNA approach.
  • Approach SSE consolidation by identifying which elements you may already have in place, for example, existing cloud-based CASB or SWG. Develop a shortlist of vendors based on your use cases regarding secure end-user requirements, the cloud services you use and the data you need to protect.
  • Inventory your existing equipment and contracts in preparation to implement a multiyear phaseout of on-premises perimeter and branch security hardware in favor of the cloud-based SSE.
  • Validate that remote offices have acceptable performance and features with selected vendors if you are a global enterprise. Vendor POP locations and service support are key.
  • Engage actively with initiatives for branch office transformation, SD-WAN and Multiprotocol Label Switching (MPLS) offload to integrate cloud-based SSE into the scope of project planning.
Sample Vendors
Broadcom; Cisco; Cloudflare; Fortinet; iboss; Netskope; Palo Alto Networks; Skyhigh Security; Versa; Zscaler
Gartner Recommended Reading

XDR

Analysis By: Eric Ahlm, Franz Hinner, Thomas Lintemuth
Benefit Rating: Moderate
Market Penetration: 20% to 50% of target audience
Maturity: Early mainstream
Definition:
Extended detection and response (XDR) delivers unified security incident detection and response capabilities. XDRs integrate threat intelligence, security events and telemetry data from multiple sources, with security analytics to provide contextualization and correlation of security alerts. XDR must include native sensors. XDR can be delivered on-premises or as a SaaS offering, and is typically deployed by organizations with smaller security teams.
Why This Is Important
XDR offers a platform approach for threat detection, investigation and response (TDIR) by using an ecosystem, rather than a best-of-breed approach. XDR vendors, for the most part, manage the complex dependencies normally associated with building a detection stack through their use of native APIs, automation and detection content. Several XDR vendors now offer basic SIEM-like functionality as part of their ecosystem solutions.
Business Impact
The relative ease of use of XDR to discover and triage common threats reduces the need for internal skill sets and could reduce staffing levels needed to operate a more complex solution, such as SIEM. XDR can also help reduce the time and complexity associated with security operations tasks through a single centralized investigation and response system.
Drivers
  • XDRs appeal to organizations with modest maturity needs, due to the detection logic, mostly vendor-provided, that generally requires less customization and maintenance.
  • XDRs appeal to organizations looking for improved collaboration across the security stack components, as well as those looking to lower the administration requirements of more complex TDIR solutions.
  • Overall operations reduction drives buyers to XDR solutions, since the vendor takes on many responsibilities involving managing stack dependencies, scaling workflows and providing detection content.
  • Purchasing a platform product like XDR simplifies the vendor acquisition and integration challenges associated with a best-of-breed strategies.
Obstacles
  • XDR’s limited extensibility creates obstacles for clients who wish to build highly customized detection and monitoring use cases using solutions outside of the XDR vendor’s preferred open ecosystem.
  • Expanding an XDR detection stack’s capabilities through the addition or replacement of security controls will be limited by the vendor.
  • An XDR’s SIEM component may lack functionality found in best-of-breed solutions, such as long-term storage, system of record, reporting and audit or log connector support.
  • XDR may be a poor choice for high maturity security operations centers (SOCs) that require role-based dashboards, advanced workflows and large-scale enterprise architectural capabilities.
User Recommendations
  • Evaluate the actual operational complexity reduction in an XDR solution by comparing how current workloads are reduced by the vendorsuse of automation, AI, alert enrichment or other time-saving capabilities.
  • Evaluate using scaling functions included in the XDR product, such as automation and knowledge augmentation, to drive efficiencies in common operation functions associated with threat detection and response.
  • Evaluate XDR with SIEM capabilities as a possible migration candidate for organizations with limited SIEM use cases, considering it as a replacement for their existing primary SIEM.
  • Include the knowledge services provided by the vendor for common detection upkeep as part of the solution cost justification.
  • Favor security products that provide APIs for information sharing and that allow automated actions to be sent from an XDR solution.
  • Buy a managed detection and response solution on top of an XDR product when your organization needs more than vendor provided integrations and playbooks including daily operational support for threat detection and response.
Sample Vendors
Cisco; CrowdStrike; Fortinet; Microsoft; Palo Alto Networks; SentinelOne; Sophos; Stellar Cyber; Trellix; Trend Micro
Gartner Recommended Reading

Climbing the Slope

SASE

Analysis By: Neil MacDonald, Andrew Lerner
Benefit Rating: Transformational
Market Penetration: 5% to 20% of target audience
Maturity: Early mainstream
Definition:
Secure access service edge (SASE) delivers converged network and security capabilities, including software-defined WAN, secure internet access, secure SaaS access, firewall and zero-trust network access capabilities. SASE supports branch office, remote worker and on-premises secure access use cases. Primarily delivered as a service, SASE enables zero-trust access based on the identity of the device or entity, combined with real-time context, and security and compliance policies.
Why This Is Important
SASE enables modern digital business transformation, including work from anywhere, branch office transformation and the adoption of edge computing and cloud-delivered applications. It also dramatically simplifies the delivery and operation of critical network and security services via a cloud-centric management and delivery model. SASE reduces the number of vendors for secure access to one or two explicitly partnered vendors.
Business Impact
SASE enables:
  • Digital business use cases (such as branch office transformation and hybrid workforce enablement) with increased ease of use while reducing costs and complexity via vendor consolidation and dedicated circuit offload.
  • Infrastructure and operations, and security teams to deliver consistent and integrated networking and network security services, supporting the needs of digital business transformation, edge computing and work from anywhere.
Drivers
  • Digital workforce and branch transformation projects driven by the adoption of cloud-based services and an increasingly mobile workforce require secure access anywhere, anytime.
  • Organizations desire to move toward a zero-trust security architecture while managing complexity.
  • More than a dozen communications service providers offer competitive single-vendor SASE platform solutions in the form of managed SASE offerings.
  • SASE can reduce the deployment time for new users, locations, applications and devices.
  • For information security, SASE enables a single way to set consistent policy enforcement across internet, web application and private application access, which reduces the attack surface and shortens remediation times.
  • Enterprises want to simplify network and network security deployments via the reduction of policy engines and management consoles.
Obstacles
  • Organizational silos, existing investments: SASE requires a coordinated approach across security, networking and digital workplace teams, which is challenging given refresh and renewal cycles, silos and staff expertise.
  • SASE coverage requirements: A vendor’s cloud footprint may prevent SASE deployments in certain geographies such as China, Africa, South America and the Middle East. In contrast, some buyers have only a regional requirement and don’t need broad coverage.
  • Concentration risk: Organizations cite both commercial and technological concerns consolidating multiple technologies from a single vendor.
  • Higher costs: Depending on the location of an enterprise’s workforce and applications, a cloud-based approach can cost more than on-premises.
  • On-premises requirements: Many vendors don’t have the on-premises deployment options required for customers who are averse to cloud-based inspection or with a static, in-office workforce.
User Recommendations
  • Involve the security and network teams when evaluating offerings and roadmaps from incumbent and emerging vendors to ensure an integrated approach.
  • Leverage software-defined WAN (SD-WAN), router, firewall, VPN hardware refresh cycles or SD-WAN deployments to update network and network security architectures.
  • Explore single-vendor SASE platforms, dual-vendor SASE and managed SASE options when investing. To avoid complexity and improve performance, avoid enabling SASElike outcomes with more than two vendors.
  • Use vendor combinations — when selecting a dual-vendor solution — with explicit integration including turnkey automation, visibility and, ideally, management and data plane integration.
  • Combine branch office and remote access in a single implementation to ensure consistent policies and minimize the number of vendors required.
  • Utilize branch office transformation and dedicated circuit offload projects to adopt SASE.
Sample Vendors
Broadcom; Cato Networks; Cisco; Cloudflare; Fortinet; Hewlett Packard Enterprise; Netskope; Palo Alto Networks; Versa Networks; Zscaler
Gartner Recommended Reading

NDR

Analysis By: Thomas Lintemuth, Charanpal Bhogal, Jeremy D'Hoinne
Benefit Rating: Moderate
Market Penetration: 20% to 50% of target audience
Maturity: Early mainstream
Definition:
Network detection and response (NDR) products continuously monitor network traffic to detect anomalies and threats using behavioral analytics. NDR products include automated responses via integration with third-party cybersecurity products and less commonly directly. NDR is offered with hardware and software sensors. Management and orchestration consoles can be software or SaaS.
Why This Is Important
NDR identifies all devices communicating on the network, network activity to/from these devices, baselines of typical activity, and abnormal activity, all without the need for signature-based controls. NDR detects lateral movement of attackers, command and control activity, and data exfiltration. The placement on the network means NDR catches what other controls miss, and it will not cause downtime and can be tuned to prevent false positives impacting operations.
Business Impact
NDR assists with risk mitigation by exposing the network attack surface. Machine learning (ML) algorithms detect incidents that are missed by signature-based detection techniques. Automated response capabilities enhance the effectiveness of incident responders. NDR facilitates faster and more thorough incident investigations, combining threat hunting and contextualization of alerts with drill-down capabilities.
Drivers
  • Detect breach activity: NDR complements traditional preventative controls by detecting incidents based on deviations from baseline. This enables security teams to investigate breaches without relying on manual controls.
  • Contextualize alerts: SOC analysts are inundated with high volumes of events to the security information and event management (SIEM). NDR is great at providing contextual detail for devices that are involved once an event is considered an incident.
  • Low risk, high reward: Deploying NDR products is a low-risk project, because the sensors are deployed out of band. They don’t inject a point of failure or a “speed bump” for network traffic. Enterprises that implement NDR products as a proof of concept (POC) often report high degrees of satisfaction, because the tools provide much-needed visibility into network traffic and enable even small teams to spot anomalies.
  • Monitor hybrid and cloud traffic: A key functionality for NDR is the ability to monitor IaaS traffic and some site-specific events in SaaS traffic (Microsoft 365). Organizations expanding their cloud presence use NDR to avoid creating gaps in their ability to monitor interactions among all their systems, whether hybrid or singularly IaaS.
  • Eliminate visibility gaps: NDR records every network packet that crosses its sensors. Properly deployed and scoped NDR generates a list of all assets that are communicating on the network.
  • Passive detection: NDR is deployed out of band so attackers have little ability to know they are being observed. This also makes it nearly impossible, unlike endpoint detection and response (EDR), to disable their monitoring.
Obstacles
  • As most attacks happen at the endpoint, NDR identifies fewer incidents than EDR. Enterprises with a lower-maturity security operation program might struggle to justify the expense, compared with more-prolific detection products.
  • NDR has not developed a solid reputation for automated response. Response capabilities are usually actioned manually, if at all, after review from the security team as opposed to an automated response from the NDR system.
  • NDR products require tuning to the environment in which they are deployed. This necessitates ongoing human resources to achieve maximum benefit.
  • NDR is expanding beyond just network analysis, developing competition for budget with consolidated platforms such as SIEM and extended detection and response (XDR).
User Recommendations
  • Develop a strong understanding of the overall traffic patterns to support proper implementation and gain maximum value from NDR.
  • Plan sensor types and deployment locations so that the most relevant network traffic can be analyzed. Proper positioning of the NDR sensors is critically important to achieve complete visibility and control the cost of the deployment.
  • Tune out false positives in the implementation phase — false positives may be triggered by vulnerability scanners, shadow IT applications and other factors that may be specific to your environment.
  • Plan for ongoing tuning, as new detection models are deployed from the vendor.
  • Select network sensors with the appropriate throughput capacity to negate overloaded ports or dropped packets.
Sample Vendors
Corelight; Darktrace; ExtraHop; Gatewatcher; NetWitness; Stamus Networks; Trellix; Trend Micro; Vectra AI
Gartner Recommended Reading

Network Microsegmentation

Analysis By: Adam Hils, Rajpreet Kaur
Benefit Rating: High
Market Penetration: 5% to 20% of target audience
Maturity: Early mainstream
Definition:
Network microsegmentation is the ability to insert a security policy into the access layer between any two workloads in the same extended data center. It divides a network into smaller, isolated zones or segments at a granular level, such as individual workloads or applications or down to specific processes.
Why This Is Important
Once a system is breached, attackers move laterally (including in ransomware attacks), which can cause serious damage. Microsegmentation seeks to limit the propagation and spread of such attacks. It can greatly reduce the initial attack surface as well.
Business Impact
Microsegmentation reduces the attack surface, enabling breach containment of cyberattacks. It is a core component of zero-trust architecture that controls the access between workloads and is used to limit lateral movement, if and when an attacker breaches the enterprise network. Microsegmentation also enables enterprises to enforce consistent segmentation policies across on-premises and cloud-based workloads, including those that host containers.
Drivers
  • As servers are being virtualized, containerized or moved to infrastructure as a service (IaaS), existing safeguards such as traditional firewalls, intrusion prevention solutions and antivirus software struggle to follow the fast pace of deployment for new assets. This leaves the enterprise vulnerable to attackers gaining a foothold and then moving laterally within enterprise networks. This has created increased interest in visibility and granular segmentation for east-west traffic between applications, servers and services in modern data centers.
  • Zero-trust approaches are expanding and now a requirement in modern data center design. Microsegmentation is cited by zero-trust frameworks as a practical way to build a secure policy-driven infrastructure.
  • The increasingly dynamic nature of data center workloads makes traditional network-centric segmentation strategies difficult to manage at scale, if not impossible to apply.
  • Microsegmentation products provide rich application communication mapping and visualization, allowing data center teams to identify which communication paths are valid and secure.
  • The shift to application microservices has increased the amount of east-west traffic and further restricted the ability of network-centric firewalls to provide segmentation.
  • The extension of data centers into IaaS has placed a focus on software-based approaches for segmentation — in many cases, using the built-in segmentation capabilities from cloud-based vendors.
  • Growing interest in zero-trust networking approaches has also increased interest in using application and service identities as the foundation for adaptive application segmentation policies. This is critical to enforcing segmentation policies in the dynamic networking environments used within container-based environments.
Obstacles
  • Complexity If not planned and scoped correctly, microsegmentation projects can lose organizational support before completion.
  • Lack of application dependency knowledge — Cybersecurity leaders don’t know which applications should be communicating with others, sowing doubt in automatically generated protection rules.
  • Legacy network firewalls — Traditional firewalls can present operational challenges to some identity-based segmentation solutions when policies overlap or conflict.
  • Organizational dynamics Cloud-centric organizations employing DevOps may value agility more than security, believing that any additional security controls will introduce operational friction.
  • Expense — Full microsegmentation can come at a high price. Many organizations consider microsegmentation to be a net new budget item.
User Recommendations
  • Select zones to microsegment based on the highest risk. Oversegmentation is the leading cause of failure and excessive costs.
  • Seek a solution that maps application communication paths and makes policy recommendations, using AI-based policy recommendations.
  • Do not use IP addresses or network location as the foundation for east-west segmentation policies. Use logical tags, labels, fingerprints or stronger identity mechanisms to identify workloads.
  • Use the microsegmentation style (such as network overlay, host-based, cloud-native and API-based) that best works with your environment, factoring in location (such as on-premises, hybrid and IaaS) and environment (such as containers and virtual machines).
  • Focus on automating microsegmentation deployment and changes integrated with the DevOps continuous integration/continuous delivery pipeline to maintain agility.
  • Plan for coexistence of traditional firewalls and microsegmentation approaches and seek microsegmentation products that support integrations with firewalls.
Sample Vendors
Akamai; Aqua Security; Broadcom; Cisco; ColorTokens; Elisity; Illumio; Palo Alto Networks; Zero Networks; Zscaler
Gartner Recommended Reading

OpenID Connect

Analysis By: Erik Wahlstrom, Abhyuday Data, Yemi Davies
Benefit Rating: High
Market Penetration: 20% to 50% of target audience
Maturity: Early mainstream
Definition:
OpenID Connect (OIDC) is an identity federation protocol built on the OAuth 2.0 framework that enables web services to externalize authentication functions. It enables applications (e.g., web-based, mobile and JavaScript) to authenticate human end users, as well as obtain basic profile information over an API.
Why This Is Important
  • OIDC lets application owners and developers authenticate humans across websites and applications without having to create, manage and maintain accounts in each application/service.
  • With OIDC, you can provide single sign-on (SSO) and reuse enterprise or social accounts to access applications and APIs, improving usability, security and privacy.
  • OIDC provides crypto-agility, consent management, support for hybrid and multicloud environments and support for more client types than previously developed federation protocols.
Business Impact
Built on top of the OAuth 2.0 protocol, OIDC offers a flexible, secure, efficient alternative to SAML. Its main benefits are:
  • Improving user experience by providing authentication, authorization and consent management
  • Reducing the data entry burden during user registration with SSO and federation support
  • Providing better support for key discovery and rotation than SAML
  • Supporting token and API-centric architectures with mobile and single-page applications efficiently.
Drivers
  • Interest in adopting OIDC continues to grow to replace SAML for new client-facing and enterprise applications. The benefits that OIDC brings to API access controls, privacy regulation, consent management, step-up authentication, compliance and implementation of adaptive access will accelerate its time to plateau.
  • OIDC is a way to use a single set of user credentials to access multiple sites and APIs, improving usability.
  • OIDC has been proven to allow identity interactions to be conducted more seamlessly and with less friction for developers than XML-based standards, such as SAML, or purely proprietary implementations, and with greater security than preceding protocols.
  • OIDC is mature and well-supported. Organizations can find certified solutions through the OpenID Connect Foundation that certifies solutions against server conformance profiles of OIDC.
  • Finance, government and healthcare institutions can benefit from the increasing work to profile OIDC specifications to support, and be fine-tuned for use by, industry verticals.
  • Work is ongoing to extend OIDC to support more use cases. This includes fast trust establishment between OpenID providers and relying parties. It also means establishing standards to share risk signals using adjacent technologies such as the shared signals framework and Continuous Access Evaluation Profile [CAEP] and Risk Incident Sharing and Coordination (RISC).
  • Growing adoption of sign-in with decentralized identity (DCI) approaches using OIDC4VC, an extension of OIDC.
  • Extensions built for OIDC establish a federation of federation services (multilateral federation), which is commonly used in higher education and with select industries such as healthcare, in which a common set of policies is followed.
Obstacles
  • The list of SaaS applications supporting OIDC continues to grow; however, it still has smaller market penetration than SAML.
  • Developers often underestimate the intricacies of the protocol and build homegrown libraries with “cherry-pick” features from the specification, making implementations insecure.
User Recommendations
  • Give preference to OIDC over SAML. Use OIDC for modern application “greenfield” developments.
  • Leverage an access management tool that centralizes adaptive access, supports multiple protocols and can translate among protocols, especially between SAML and OIDC, and other proprietary security token formats.
  • Use OIDC for human user authentication, not for machines (workloads and devices). Instead, rely on machine-specific OAuth 2.0 framework flows to get tokens.
  • Use OIDC instead of proprietary API keys or authentication methods to avoid vendor lock-in and balance security, privacy, usability and scale when building and deploying applications and services.
  • Use proven and well-tested, open-source and/or vendor-provided libraries that are up to date and meet the latest security recommendations.
  • Don’t misuse the ID token to call APIs. Instead, use the access token and modern authorization frameworks to validate the access token in and behind enterprise API gateways.
Sample Vendors
Authlete; Curity; IBM; Microsoft; Okta; OpenText; Ping Identity; Red Hat; SecureAuth; Thales
Gartner Recommended Reading

ZTNA

Analysis By: John Watts, Thomas Lintemuth
Benefit Rating: Moderate
Market Penetration: 20% to 50% of target audience
Maturity: Early mainstream
Definition:
Zero-trust network access (ZTNA) is software that provides secure network access. ZTNA creates an access boundary based on identity and device context that encompasses an enterprise user and an internally hosted application or set of applications. The applications are hidden from discovery, and access is restricted via a trust broker to a collection of named entities, which limits lateral movement within a network.
Why This Is Important
ZTNA enables adaptive user-to-resource segmentation based on least logical privileged access through a trust broker. It allows organizations to hide private resources from discovery and attack. It reduces the surface area for attack by obfuscating an organization’s infrastructure and creating individualized “virtual perimeters” that encompass only the user, the device and the resource.
Business Impact
ZTNA logically separates the source user and device from the destination resources to mitigate full network access and reduces the attack surface for the organization. This improves some user experience (UX) issues with static, network-based VPN routing and enables remote access flexibility with dynamic, granular user-to-resource segmentation through adaptive access controls defined as zero-trust policies. Cloud-based ZTNA offerings improve scalability and ease of adoption for secure remote access.
Drivers
  • The adoption of zero-trust strategy within organizations has led to a requirement to replace legacy network-based VPNs with secure remote access. This allows for more precise and adaptive access and session control to on-premises and private resources hosted in infrastructure as a service (IaaS).
  • Increased attacks in the past few years against vulnerable, exposed legacy VPN infrastructure has led organizations to seek alternative secure remote access methods.
  • The rise of IaaS adoption and hybrid infrastructure requires more flexible secure remote connectivity to enable access directly to resources as opposed to static connections that are then routed to multiple destinations.
  • Organizations have a need to connect third parties such as suppliers, vendors and contractors to resources directly without using a full-tunnel VPN to their networks or exposing resources directly to the internet in a DMZ.
  • Organizations that undergo mergers and acquisitions need to be able to extend access to resources to acquired companies without deploying endpoints or interconnecting their corporate networks.
Obstacles
  • ZTNA is typically licensed per named user on a per-user/per-year basis at a price roughly twice or three times that of traditional VPNs.
  • Cloud-based trust brokers may not extend policy enforcement points on-premises, limiting use cases compared to universal ZTNA offerings that offer distributed enforcement points.
  • Organizations must map resource access for users and balance risk mitigation with complexity. Organizations will end up either with access rules no better than the VPN being replaced or with access too granular, which adds significant overhead to managing the product over the long term.
  • Mature zero-trust implementations must continuously assess access based on context of user accounts and devices. Many organizations find this difficult to adopt at scale due to complicated troubleshooting and inconsistency of access controls based on fluctuating risk scores.
  • ZTNA is only one technology that enables a zero-trust posture. To be effective, it must be integrated and deployed with other technologies, such as identity and access management products.
User Recommendations
  • Enable resource-specific access with clientless ZTNA rather than full-tunnel network access for nonmanaged devices.
  • Based on the risk posture of the organization, start small with narrow, risk-based and dynamic access controls or wider access to fewer end users and refine over time.
  • Align agent-based ZTNA vendor choice with security service edge vendor choice to support the organization’s zero-trust strategy.
  • Unify access control policies when providers offer both on- and off-premises enforcement points with added IoT support to replace legacy technologies such as Network Access Control.
  • Mitigate the risk of operational downtime with hot or cold standby options when the vendor has a single point of failure for connecting end-user devices to applications.
  • Assess the need for separate products to address adjacent functionality such as remote privileged access management, and to support nonuser devices such as IoT and desktop-as-a-service alternatives. ZTNA does not solve all use cases.
Sample Vendors
Absolute Security; Appgate; Cisco; Microsoft; Netskope; Palo Alto Networks; Zero Networks; Zscaler
Gartner Recommended Reading

Appendixes


Hype Cycle Phases, Benefit Ratings and Maturity Levels

Hype Cycle Phases

Phase
Definition
Innovation Trigger
A breakthrough, public demonstration, product launch or other event generates significant media and industry interest.
Peak of Inflated Expectations
During this phase of overenthusiasm and unrealistic projections, a flurry of well-publicized activity by technology leaders results in some successes, but more failures, as the innovation is pushed to its limits. The only enterprises making money are conference organizers and content publishers.
Trough of Disillusionment
Because the innovation does not live up to its overinflated expectations, it rapidly becomes unfashionable. Media interest wanes, except for a few cautionary tales.
Slope of Enlightenment
Focused experimentation and solid hard work by an increasingly diverse range of organizations lead to a true understanding of the innovation’s applicability, risks and benefits. Commercial off-the-shelf methodologies and tools ease the development process.
Plateau of Productivity
The real-world benefits of the innovation are demonstrated and accepted. Tools and methodologies are increasingly stable as they enter their second and third generations. Growing numbers of organizations feel comfortable with the reduced level of risk; the rapid growth phase of adoption begins. Approximately 20% of the technology’s target audience has adopted or is adopting the technology as it enters this phase.
Years to Mainstream Adoption
The time required for the innovation to reach the Plateau of Productivity.
Source: Gartner (August 2025)

Benefit Ratings

Benefit Rating
Definition
Transformational
Enables new ways of doing business across industries that will result in major shifts in industry dynamics
High
Enables new ways of performing horizontal or vertical processes that will result in significantly increased revenue or cost savings for an enterprise
Moderate
Provides incremental improvements to established processes that will result in increased revenue or cost savings for an enterprise
Low
Slightly improves processes (for example, improved user experience) that will be difficult to translate into increased revenue or cost savings
Source: Gartner (August 2025)

Maturity Levels

Maturity Levels
Status
Products/Vendors
Embryonic
In labs
None
Emerging
Commercialization by vendors
Pilots and deployments by industry leaders
First generation
High price
Much customization
Adolescent
Maturing technology capabilities and process understanding
Uptake beyond early adopters
Second generation
Less customization
Early mainstream
Proven technology
Vendors, technology and adoption rapidly evolving
Third generation
More out-of-box methodologies
Mature mainstream
Robust technology
Not much evolution in vendors or technology
Several dominant vendors
Legacy
Not appropriate for new developments
Cost of migration constrains replacement
Maintenance revenue focus
Obsolete
Rarely used
Used/resale market only
Source: Gartner (August 2025)

Acronym Key and Glossary Terms


AI
artificial intelligence
CAEP
Continuous Access Evaluation Profile
CPS
cyber-physical systems
EU
European Union
I&O
infrastructure and operations
IoT
Internet of Things
MASQUE
Multiplexed Application Substrate over QUIC Encryption
NDR
network detection and response
NIS
network and information systems
QUIC
Quick UDP Internet Connections
SASE
secure access service edge
SRM
security and risk management
UDP
User Datagram Protocol
XDR
extended detection and response
ZTNA
zero-trust network access