IDC - Experts & Thought Leaders

Latest International Data Corporation (IDC) news & announcements

Entrust enhances cryptographic security platform

Entrust announces new capabilities for its Cryptographic Security Platform (CSP) that help organisations turn Cryptographic Bill of Materials (CBOMs) data into action. Government agencies, financial institutions, healthcare organisations, and other critical infrastructure operators are navigating increased cyber threats, shorter certificate lifecycles, the rapid growth of machine and AI identities, evolving compliance requirements, and the transition to post-quantum cryptography. Evolving compliance requirements Managing these changes depends on a comprehensive view of where cryptography resides and how assets and systems depend on it. Growing focus on cryptographic inventory and post-quantum readiness from industry groups, standards bodies, and regulators around the world, including the recent U.S. Executive Order and the EU’s DORA and NIS2 regulations requiring CBOMs-based inventories, reinforces the need for organisations to understand their cryptographic assets, dependencies and risk exposure. Organisations can now connect cryptographic discovery and inventory with governance, automation and post-quantum migration planning, helping them identify and address risks across complex environments. With new CBOM import and export capabilities, the Cryptographic Security Platform helps organisations build more complete cryptographic inventories, understand dependencies, and translate cryptographic visibility into operational action. On-premises deployment options For example, organisations can identify cryptographic assets that may be vulnerable or noncompliant, determine which systems and applications depend on them, assess the associated risk, and prioritise remediation efforts. Additionally, the platform can now be deployed as-a-service or on-premises, giving organisations a faster and more flexible way to access the new CBOM capabilities while retaining on-premises deployment options. “A CBOM is more than a static inventory,” said Michael Klieman, Global Vice President of Product Management at Entrust. “Security teams need to connect CBOM data with the systems and applications that depend on cryptography, understand where risk is concentrated and determine what actions to take next. The addition of CBOM support to the platform helps organisations move from documenting cryptographic assets to actively governing and securing them.” Reducing cryptographic risk Once organisations establish visibility into cryptographic assets and dependencies, they must translate that insight into governance, operational resilience, and readiness for future cryptographic change. CSP helps connect discovery with action across each of these areas: Strengthen governance and reduce cryptographic risk: Organisations cannot manage cryptographic risk without understanding where cryptography exists and how assets, systems and applications depend on it. New CBOM import and export capabilities, combined with cryptographic discovery, compliance, and operational health capabilities, help organisations build more complete inventories, correlate inventory data with discovered assets and dependencies, and strengthen governance across keys, certificates, and secrets across the enterprise. Scale certificate operations across complex environments with new Ansible-based capabilities: As certificate volumes grow across public and private PKI environments, organisations need automation that can keep pace with increasingly complex infrastructure. New Ansible-based capabilities extend certificate lifecycle automation, enabling teams to automate certificate deployment and management across highly customised environments at scale, reduce manual effort, and help minimise service disruptions. Prepare for post-quantum and emerging identity requirements with expanded support for composite algorithms and SPIRE-based capabilities: Preparing for post-quantum cryptography starts with understanding where cryptography exists and which systems depend on it. Expanded support for composite algorithms helps organisations pursue phased post-quantum migration strategies while new SPIRE-based capabilities support trusted identities for AI agents and other non-human workloads. CSP is now available as a service or for on-premises deployment, giving organisations greater flexibility to meet operational, security, and data sovereignty requirements. Data sovereignty requirements By connecting cryptographic inventory, governance, automation, and post-quantum readiness in a unified platform, Entrust helps organisations turn cryptographic visibility into action and build the operational foundation for long-term crypto-agility. "Knowing where cryptography lives isn't enough anymore. The number of certificates and other cryptographic material is growing rapidly. Machine and AI identities are multiplying, and the deadline to transition to post-quantum algorithms is closing in. Security teams cannot treat cryptographic inventory as a static exercise. Organisations that connect cryptographic inventory, governance, automation, and post-quantum readiness will be better positioned to manage crypto-agility as standards evolve," said Jennifer Glenn, Research Director for Information and Data Security, IDC.

DigiCert's AI trust secures autonomous agents

DigiCert, a pioneer in intelligent trust, introduces a new AI Trust architecture designed to help organisations secure AI systems and their outputs. The company is also unveiling new capabilities to help secure autonomous agents and AI models, along with separate capabilities to provide verifiable content authenticity in the age of AI. Artificial intelligence is accelerating innovation at an unprecedented pace while simultaneously breaking traditional models of trust. Autonomous agents act across enterprise systems at machine speed; AI models introduce new supply chain and IP risks; and digital content can no longer be trusted at face value. At the core of this challenge is a lack of cryptographically verifiable control over AI systems. Specifically, what they are, what they are authorised to do, and what they produce. Embedding cryptographic verification “AI has created a new trust challenge,” said Amit Sinha, CEO of DigiCert. “Organisations are relying on agents, models, and content they can’t always verify. At DigiCert, our purpose is to give people confidence in the security, privacy, and authenticity of their digital interactions. With our AI Trust solution, we help organisations confirm what’s real, secure, and approved so AI can be used with confidence.” To address this challenge, DigiCert is introducing a unified trust layer that spans AI agents, models, and content. By embedding cryptographic verification across the AI lifecycle, organisations can enforce identity-based governance for autonomous systems, validate model integrity, and establish content provenance all within a single, cohesive framework. This unified approach is realised through new DigiCert ONE enhancements: Ensuring verifiable origin Content Trust Manager enables organisations to cryptographically sign and verify digital content, providing tamper-evident provenance and transparency using the C2PA standard, which is adopted by Adobe, Microsoft, Google and more. This allows organisations to prove where content originated, how it was created, and whether it has been altered, helping combat misinformation, brand impersonation, and AI-generated fraud while strengthening confidence in digital media. Taking content authenticity even further, organisations can establish trust at the moment of capture through cryptographic signing and timestamping enabled by embedded C2PA certificates on trusted devices. Delivered through DigiCert Device Trust Manager, this capability allows imaging device manufacturers to embed trust directly into devices such as cameras, microscopes, and scanners. Content can be signed and timestamped at the source, ensuring verifiable origin and authenticity from the start and preserving trust throughout the content lifecycle. Audit autonomous systems AI Agent Trust - Provides discovery, identity, governance, and lifecycle management for AI agents, enabling organisations to authenticate, authorise, and audit autonomous systems. By issuing cryptographic identities and enforcing policy-based controls, DigiCert enables enterprises to govern AI agents like a new digital workforce, ensuring every action is attributable, controlled, and aligned with security and compliance requirements. AI Model Trust - Delivers cryptographic protection and verification for AI models, including secure packaging, signing, and runtime validation. By establishing a verifiable chain of custody for models, from development through deployment, organisations can create models that have not been tampered with, are running in trusted environments, and are handling sensitive data securely, even in distributed or third-party infrastructure. Automated trust architecture Together, these innovations help organisations move from fragmented, manual approaches with an automated trust architecture that delivers verifiable identity, tamper-evident integrity, and continuous validation across AI systems. “AI is forcing organisations to rethink trust from the ground up,” said Jennifer Glenn, Research Director for IDC Security and Trust Group. “Bringing cryptographic assurance to AI systems gives enterprises the ability to independently verify identity, integrity, and provenance of content, enabling these organisations to build trustworthy AI at scale.” Proven PKI principles With a unified AI Trust foundation, organisations can reduce reputational and regulatory risk while accelerating responsible AI adoption. They gain the ability to verify content provenance, ensure model integrity, and govern AI agents with accountability, transforming security and compliance from reactive processes into measurable, audit-ready capabilities. As AI adoption accelerates, the ability to establish and verify trust will become a defining requirement for enterprise success. DigiCert is defining the trust infrastructure required for AI, extending proven PKI principles to agents, models, and content.

Rapid7's AI-powered threat detection solution

Rapid7, Inc., a pioneer in threat detection and exposure management, announced the launch of Incident Command, a powerful new next-gen SIEM extending the capabilities of its Command Platform, purpose-built to transform how security teams detect, investigate, and respond to threats. Incident Command unifies preventative attack and exposure management together with threat detection and response, all powered by Agentic AI workflows trained on playbooks designed by Rapid7’s own SOC experts, and refined through continuous real-world application. Intelligence Hub to deliver a seamless user experience Incident Command brings attack surface context through Surface Command and curated threat intelligence Built on the Command Platform’s data mesh, Incident Command brings attack surface context through Surface Command and curated threat intelligence with Intelligence Hub to deliver a seamless user experience that enables every analyst to operate like an expert, every action to be informed by context, and every response to be faster, smarter, and simpler. "The launch of Incident Command is a leap toward our mission to simplify access to security outcomes," said Corey Thomas, CEO of Rapid7, adding "Security teams are under scrutiny to deliver measurable impact across their risk and response programs. We built the Command Platform to unify all customer data — not just what we collect — so that organisations get the facts from the beginning and reduce their time to action." Key features of Incident Command Corey Thomas added: "Incident Command, our upgraded next-gen SIEM, gives customers the benefit of the Command Platform plus broadened access to our decades of SOC expertise with agentic AI integrated within the workflows they use every day." With Incident Command, security teams operate within a closed-loop feedback model, combining AI-powered threat detection with deep exposure visibility, automating triage with 99.93% accuracy, and saving 200+ SOC hours per week. Key features of Incident Command include: Agentic AI, built by and for the SOC: Unlike black-box “AI” tools, Rapid7’s AI is trained on years of detection, investigation, and response data from its 24/7 MDR operations, enabling transparent, analyst-assistive triage and investigation workflows with 99.93% benign disposition accuracy. It doesn't just classify, it guides, recommends, and adapts with every use. Unified analyst experience: Incident Command brings together historically siloed SIEM, SOAR, ASM, and threat intelligence functions into one intuitive interface. Analysts can investigate with deep threat, exposure, and asset context in a single view — no context switching required. Open and integrated data mesh: Powered by Surface Command and the Command Platform’s data mesh, customers can unify Rapid7 and third-party telemetry without complex integrations, gaining end-to-end visibility across their hybrid environments. Deeply embedded threat intelligence: Expertly vetted threat intelligence is integrated within Incident Command for the most actionable, relevant, and context-rich insights for targeted detection, threat hunts, and incident response. Threat intelligence and AI automation "With Incident Command, Rapid7 is marrying exposure management capabilities with threat detection and this is a differentiator in a crowded SIEM market," said Michelle Abraham, Senior Research Director at IDC. Michelle Abraham adds, "By bringing detection automation, internal and external attack surface visibility, threat intelligence, and AI automation into one platform, Rapid7 is offering security analysts a solution that reduces complexity, connects data, and streamlines investigations, which improves analyst workflows." Rapid7 is showcasing Incident Command at Black Hat USA, August 6-7 in Las Vegas, both in the Business Hall (Booth #5042) and at The Border Grill in Mandalay Bay from 9 am to 6 pm on August 6.