Identity Briefing.
Identity AttacksAI & Agent IdentityAuthenticationStandards & RegulationVendor MovesCommunity & Events
vendor moves · ai & agent identity

Okta buys Permiso and keeps walking towards the SOC

The ITDR acquisition brings identity risk signals and behavioural analytics in-house, and Okta is explicit that the destination is the security operations centre.

Okta has signed a definitive agreement to acquire Permiso Security.

Permiso is an identity security company specialising in identity threat detection across multi-cloud environments, covering human, non-human and agentic identities. Okta plans to fold Permiso's identity risk signals, behavioural analytics and threat detections into its own ITDR capabilities.

The direction is the story, not the deal

Okta is not being subtle about where this goes. The company itself frames the acquisition as expanding its footprint into the core security operations centre.

That is a meaningful shift in self-definition. An identity provider's traditional job is to decide whether an authentication should succeed. A SOC's job is to work out which of the authentications that did succeed were actually the attacker. Okta is buying its way further into the second question.

Once phishing-resistant authentication is widespread, the interesting security signal is no longer whether the login succeeded. It is what the successfully authenticated session then did.

The Black Hat research covered elsewhere in this issue makes the same point from the attacker's side. Every one of those techniques produced a valid authentication. Detection of what happens after the login stops being a nice-to-have when the login itself can be satisfied by malware on an endpoint.

The non-human coverage is the part to watch

Permiso's coverage of non-human and agentic identities is the detail most relevant to the current moment.

Behavioural analytics for human users is well-trodden ground. Behavioural baselines for service accounts, workloads and agents are much less mature, and they are exactly what our New York panellists said regulators are now asking about. An inventory of non-human identities tells you what exists. Detection tells you when one of them starts behaving unlike itself.

What it means if you are a buyer

Two practical considerations.

  • Overlap with what you already run. If you have an existing ITDR or identity analytics investment, this is the sort of acquisition that eventually shows up as a bundled capability in a renewal conversation. Worth knowing which of your current controls it duplicates before that conversation, not during it.

  • Where detections land. Identity threat detections are only useful if they reach the people who respond to alerts. If your SOC and your identity team sit in different reporting lines with different tooling, buying more identity detection does not fix the handover, and the handover is usually the weak part.

The wider market read is straightforward. Identity vendors are moving into security operations, and security vendors are moving into identity. The consolidation is happening from both directions, which usually means the category boundary was never real.

Source

Get Identity Briefing

Independent analysis for identity practitioners. Fortnightly and free.

Join identity architects, IAM leads and security leaders worldwide.