Entrust Inc. - Experts & Thought Leaders
Latest Entrust Inc. news & announcements
Entrust announces new capabilities for its Cryptographic Security Platform (CSP) that help organisations turn Cryptographic Bill of Materials (CBOMs) data into action. Government agencies, financial institutions, healthcare organisations, and other critical infrastructure operators are navigating increased cyber threats, shorter certificate lifecycles, the rapid growth of machine and AI identities, evolving compliance requirements, and the transition to post-quantum cryptography. Evolving compliance requirements Managing these changes depends on a comprehensive view of where cryptography resides and how assets and systems depend on it. Growing focus on cryptographic inventory and post-quantum readiness from industry groups, standards bodies, and regulators around the world, including the recent U.S. Executive Order and the EU’s DORA and NIS2 regulations requiring CBOMs-based inventories, reinforces the need for organisations to understand their cryptographic assets, dependencies and risk exposure. Organisations can now connect cryptographic discovery and inventory with governance, automation and post-quantum migration planning, helping them identify and address risks across complex environments. With new CBOM import and export capabilities, the Cryptographic Security Platform helps organisations build more complete cryptographic inventories, understand dependencies, and translate cryptographic visibility into operational action. On-premises deployment options For example, organisations can identify cryptographic assets that may be vulnerable or noncompliant, determine which systems and applications depend on them, assess the associated risk, and prioritise remediation efforts. Additionally, the platform can now be deployed as-a-service or on-premises, giving organisations a faster and more flexible way to access the new CBOM capabilities while retaining on-premises deployment options. “A CBOM is more than a static inventory,” said Michael Klieman, Global Vice President of Product Management at Entrust. “Security teams need to connect CBOM data with the systems and applications that depend on cryptography, understand where risk is concentrated and determine what actions to take next. The addition of CBOM support to the platform helps organisations move from documenting cryptographic assets to actively governing and securing them.” Reducing cryptographic risk Once organisations establish visibility into cryptographic assets and dependencies, they must translate that insight into governance, operational resilience, and readiness for future cryptographic change. CSP helps connect discovery with action across each of these areas: Strengthen governance and reduce cryptographic risk: Organisations cannot manage cryptographic risk without understanding where cryptography exists and how assets, systems and applications depend on it. New CBOM import and export capabilities, combined with cryptographic discovery, compliance, and operational health capabilities, help organisations build more complete inventories, correlate inventory data with discovered assets and dependencies, and strengthen governance across keys, certificates, and secrets across the enterprise. Scale certificate operations across complex environments with new Ansible-based capabilities: As certificate volumes grow across public and private PKI environments, organisations need automation that can keep pace with increasingly complex infrastructure. New Ansible-based capabilities extend certificate lifecycle automation, enabling teams to automate certificate deployment and management across highly customised environments at scale, reduce manual effort, and help minimise service disruptions. Prepare for post-quantum and emerging identity requirements with expanded support for composite algorithms and SPIRE-based capabilities: Preparing for post-quantum cryptography starts with understanding where cryptography exists and which systems depend on it. Expanded support for composite algorithms helps organisations pursue phased post-quantum migration strategies while new SPIRE-based capabilities support trusted identities for AI agents and other non-human workloads. CSP is now available as a service or for on-premises deployment, giving organisations greater flexibility to meet operational, security, and data sovereignty requirements. Data sovereignty requirements By connecting cryptographic inventory, governance, automation, and post-quantum readiness in a unified platform, Entrust helps organisations turn cryptographic visibility into action and build the operational foundation for long-term crypto-agility. "Knowing where cryptography lives isn't enough anymore. The number of certificates and other cryptographic material is growing rapidly. Machine and AI identities are multiplying, and the deadline to transition to post-quantum algorithms is closing in. Security teams cannot treat cryptographic inventory as a static exercise. Organisations that connect cryptographic inventory, governance, automation, and post-quantum readiness will be better positioned to manage crypto-agility as standards evolve," said Jennifer Glenn, Research Director for Information and Data Security, IDC.
Entrust, a global pioneer in identity-centric security solutions, announces the Agentic AI Trust Accelerator, a co-development program that will bring together enterprises and integration partners to build the identity and trust infrastructure needed to move autonomous AI projects from pilot to production. Enterprises want to deploy AI agents to do real work, but they lack the trust infrastructure needed to govern autonomous actions across systems, partners, and business processes. Organisations need to know who authorised an agent, what it is allowed to do, and how its actions can be proven after the fact. Strong AI agent governance The need is urgent: 77% of CIOs and CISOs say AI adoption is already outpacing governance capabilities, and 59% cite security and compliance as top barriers to deployment, according to an IBM study. Deloitte has also emphasised that the shift to “human on the loop” is a form of automation that requires strong AI agent governance and oversight. This underscores the broader enterprise need for stronger governance, accountability, and trust controls. “AI agents are advancing faster than the trust infrastructure needed to govern them,” said Anudeep Parhar, Entrust COO for digital infrastructure who is leading the Accelerator. Developing practical approaches “Enterprises need to be able to trust autonomous actions across business processes, partners, and systems. Whether organisations are experimenting with AI agents, deploying initial use cases, or preparing for broader adoption, they need a trust foundation that can scale with them. The Agentic AI Trust Accelerator brings together customers and partners to develop practical approaches for identity, authorisation, cryptographic trust, and accountability that work with their existing platforms. We call this the trust plane for autonomous AI.” The Accelerator Program builds on the company’s deep expertise in identity and cryptographic security to help enterprises take on the challenge of AI agents operating with trust in real-world workflows. Entrust capabilities in identity verification, cryptographic identity, and lifecycle management for keys, certificates, and secrets are fundamental to extending trust and governance for autonomous agents acting across applications, systems, and organisational boundaries. Cryptographically verifiable identity Enterprises need cryptographically verifiable identity and proof of action that can travel across systems, partners, and workflows to complement platform- or policy-driven controls – particularly in regulated sectors. The Entrust Agentic AI Trust Accelerator will help enterprises close that gap with reference architectures, customer-validated use cases, and practical controls for identity, authorisation, and accountability. “As agentic AI becomes embedded in enterprise operations, governance is evolving from a point-in-time exercise to a continuous discipline. While AI agents increasingly perform tasks traditionally associated with human workers, their autonomy introduces new challenges for oversight, accountability, and risk management. Organisations therefore need more than static controls; they need continuous verification throughout the agent lifecycle. The goal is not simply to control AI agents, but to operate with confidence that they are appropriately authorised, governed, and acting within established business, security, and regulatory boundaries," said Emanuel Figueroa, Senior Research Analyst, Identity Security, Worldwide, IDC. Compliance-driven environments Initial work with the Accelerator program will focus on four areas of importance to workflows in regulated and compliance-driven environments: Identity – verifiable human and agent identity, so that every agent action can be traced back to a confirmed human principal and unique agent Authorisation – real-time authorisation, so agents act only within approved policies, roles, and delegated authority, with a "human in the loop" for critical decisions Cryptographic Trust – cryptographic assurance for agent operations, protecting the keys, certificates, and secrets, and signing capabilities agents use to authenticate and transact securely Accountability – proof of action, a cryptographically verifiable record for regulators, customers, and internal risk teams Agentic AI architectures “Agentic AI will reshape how enterprises operate, but trust will determine how quickly organisations can move from experimentation to production,” said Tony Ball, CEO of Entrust. “Entrust is helping customers build the identity, authorisation, and cryptographic foundations required for autonomous systems operating in real-world environments.” Entrust is opening the Accelerator to a limited number of select enterprise customers, financial institutions, cloud and SaaS providers, systems integrators, and other technology partners interested in co-developing trusted agentic AI architectures.
Entrust, a global pioneer in identity-centric security, today introduced a new approach to preventing account takeover in the age of AI. As attackers increasingly target high-risk moments like account recovery, device changes, and large transactions, organisations need to modernise authentication from verifying access to verifying the real human behind the transaction. The Entrust Biometric Authentication solution brings identity-centric assurance to these critical interactions, helping organisations reduce fraud while delivering fast, easy end-user experiences. “Too many organisations are treating authentication as a login problem, but attackers have already moved beyond access,” said Mike Baxter, Chief Technology & Product Officer at Entrust. Adaptive risk-based authentication “Preventing account takeover in the age of AI requires confirming the person behind every interaction. Entrust helps organisations apply the right level of assurance at the right moments while delivering secure, low-friction experiences.” The need is urgent, with AI-driven attacks contributing to dramatic increases in fraud and cybercrime. Global businesses lost an average of 7.7% of annual revenue to fraud with account takeover responsible for nearly one-third of those losses. At the same time, one in five biometric fraud attempts now involve AI-generated deepfakes. The Entrust Biometric Authentication solution meets this challenge with identity assurance that combines biometric identity verification with adaptive risk-based authentication. This provides a crucial check against presentation, injection, and deepfake attacks by requiring identity assurance at key moments like onboarding, account recovery, device changes, and large transactions. A unified approach to identity assurance Unlike fragmented point solutions that address onboarding, authentication, and fraud prevention separately, the Entrust Biometric Authentication solution takes the verified identity that is established at enrollment and extends it across every access point and interaction. By anchoring a biometric check to that trusted identity, organisations can make consistent, high confidence authentication decisions. The solution helps organisations: Apply the right level of identity assurance based on risk to fight account takeover attacks. Reduce unnecessary account lockouts from password and one-time passcode failures. Enhance protection against presentation, injection, and deepfake attacks Minimise manual reviews and support calls through secure self-service authentication Deliver consistent, auditable identity assurance across the user lifecycle Improve the user experience with fast, intuitive biometric experiences. The Entrust Biometric Authentication solution uses three authentication methods, each designed for different levels of risk: Biometric Passkey – provides biometric authentication at high-risk moments by binding authentication to a verified human identity. Face Authentication – makes everyday verification and step-up authentication faster and more secure by replacing one-time passcodes (OTPs) with an easy biometric check. Motion Authentication – helps defend against deepfake, replay, and injection attacks in high-assurance use cases with ISO 30107-3 PAD Level 1 & 2 conformant liveness detection, independently tested by iBeta Quality Assurance.
Insights & Opinions from thought leaders at Entrust Inc.
In the simplest terms, technology modernisation accelerates when older systems become too expensive to maintain or fail to support modern standards. Market competition pushes businesses to update their technologies to meet rising customer demands. Additionally, the rapid shift toward cloud-based infrastructures and artificial intelligence creates a fear of missing out, forcing companies to adapt or risk irrelevance. Focusing on the physical security market, we asked our Expert Panel Roundtable: What factors are accelerating technology modernisation in security?
Traditional security models protected a perimeter like a castle moat, assuming anyone inside was safe. Zero trust removes that implicit trust entirely, recognising that threats can exist both outside and inside a facility. Zero trust is a routine and accepted concept in cybersecurity. Given the importance of information technology and the increasing convergence of physical and logical security, the tenet is becoming a dominant principle in physical security, too. We asked our Expert Panel Roundtable: Briefly define zero trust and explain how it impacts physical security.
Emphasising proactive rather than reactive security shifts the focus from dealing with crises and damage control to prevention. Advantages of a proactive approach include cost efficiency, better business continuity, and fewer crises that draw attention away from strategic improvements. Staying ahead of threats is a core mission of the security department, and technology has evolved to enable security professionals to deliver on that mission better than ever. We asked our Expert Panel Roundtable: How are security systems transitioning from reactive to proactive, and what is the benefit?
Security technologies promote real-time awareness in K-12 schools
DownloadTechnology's role in securing banks and financial institutions
DownloadIntegrated systems enable critical and compliant security for transportation
DownloadModernising physical access control
DownloadAccess. Intrusion. One estate.
Download