With more than 25 years of experience across cybersecurity and identity management, John Tolbert has seen the industry evolve from traditional security controls towards increasingly complex digital environments where identity, authentication, fraud prevention, and AI are becoming deeply interconnected.
As Principal Analyst and Director of Cybersecurity Research at KuppingerCole, Tolbert's work spans both established and emerging areas of cybersecurity and identity management. Today, his focus includes identity fabrics, customer identity, authentication, passwordless technology and passkeys, and fraud reduction.
I recently sat down with John for an in-depth interview to discuss the evolution of identity and cybersecurity, the growing role of AI and AI agents, why organisations need to think more seriously about governance and authorisation, and what could define the next era of enterprise technology.
From Cybersecurity to Identity Management
Tolbert's career has spanned multiple industries and more than two decades of cybersecurity and identity management. That breadth of experience gives him a particularly broad perspective on how organisations approach security and technology transformation.
Today, his work as Principal Analyst and Director of Cybersecurity Research at KuppingerCole covers both established cybersecurity challenges and emerging areas that are beginning to reshape the enterprise.
“I’ve been in cybersecurity and identity management for more than 25 years. I worked in accounting, manufacturing, and the aerospace and defense industries before becoming an analyst. My role is now Principal Analyst and Director of Cybersecurity Research, and I’ve covered many standard and emerging topics in both cyber and IAM. My main focus areas are identity fabrics, customer identity, authentication including passwordless and passkeys, and fraud reduction.”
That combination of cybersecurity and identity expertise is particularly relevant as enterprises begin navigating a technology landscape where AI agents, machine identities, and autonomous systems are increasingly interacting with business-critical environments.
Building the Identity Fabric
One of Tolbert's current areas of focus is identity fabrics, an approach that brings together capabilities across the broader identity and access management ecosystem alongside orchestration and integrations.
Rather than treating identity as a collection of isolated tools, the identity fabric concept reflects a wider movement towards consolidation and coordination across enterprise environments.
“I’m working on identity fabrics right now, which synthesises all the capabilities in the broader IAM world plus orchestration and integrations. Next up, I’ll be updating the Fraud Reduction Intelligence Platform (FRIP) report, which addresses the solutions that help detect and prevent many different kinds of fraud. I will be making two separate reports for FRIP: for banking and credit card issuers, and for organisations in the digital marketplace. The fraud actors and techniques can differ between targets.”
The focus on consolidation is also part of a wider architectural shift Tolbert is seeing across enterprise technology.
From AI Hype to Architectural Change
AI is inevitably part of any conversation about enterprise technology today. But Tolbert believes the industry needs to be more precise about what it actually means when it talks about "AI".
While generative AI and large language models have dominated the conversation in recent years, machine learning has been quietly powering applications such as fraud and threat detection for much longer.
At the same time, organisations are reconsidering how their technology environments are structured, increasingly looking to consolidate individual tools onto broader platforms.
“Of course we have to mention “AI”, but I think we should be careful about semantics. The term “AI” has been genericised and misunderstood, sometimes even in the technology world. For the last four years, most discussion about AI has really been about Generative AI, and specifically Large Language Models (LLMs). Machine learning has been doing useful work in fraud detection and threat detection for well over a decade, and that work continues, but it gets little attention now. The other major shift is architectural: organisations are consolidating point tools onto fewer platforms, and in identity that shows up as demand for identity fabrics rather than another single-purpose product.”
For Tolbert, then, the AI conversation is happening alongside a broader architectural consolidation, one that could have significant implications for how enterprises approach identity.
Generative AI Has Gone Mainstream
Of all the technology trends attracting attention, generative AI remains firmly at the top of the list. Tolbert believes that attention is justified, largely because generative AI has moved beyond experimentation and become embedded into real business processes.
But that mainstream adoption also creates new security and identity challenges.
“Generative AI is still receiving the bulk of everyone’s attention, and it is justified because its use has gone mainstream. It has become embedded in key business processes in many organisations. As security and IAM practitioners, we have to find ways to secure it. GenAI usage, especially deploying AI agents, opens its users to new risks.”
As AI agents become more prevalent, those risks are likely to become increasingly difficult to manage using traditional approaches.
AI Governance and the Rising Importance of Cost
For organisations adopting generative AI at scale, security is only one part of the equation. Tolbert believes AI governance should be moving higher up the executive agenda, particularly as the economics of AI change.
“In addition to security, AI governance is something that most organisations should be thinking about now. As GenAI usage (and especially AI agents) proliferates and cost models change, cost containment is becoming a top executive concern.”
This reflects a broader shift in the AI conversation. Enterprises are moving away from simply asking what the technology can do and towards asking how it should be managed, governed, and funded.
The AI Conversation Is Becoming More Commercial
According to Tolbert, one of the most noticeable changes over the last 12 months has been the growing focus on return on investment.
As organisations have gained more experience with generative AI, the initial excitement is increasingly being replaced by practical questions around cost, ownership, governance, and risk.
“Executives are now asking about Return on Investment (ROI) on their GenAI expenses. It has been difficult to quantify, which has been an incentive for some organisations to pause or limit their GenAI initiatives. A year ago the questions were mostly about which model to use and how to keep sensitive data out of it. Now they are about cost per agent, who owns AI governance, and what happens when an agent acts on bad input. Security teams have also shifted from trying to block GenAI use to trying to inventory and monitor it.”
That evolution suggests a maturing market. Instead of treating AI as an isolated innovation project, organisations are increasingly having to consider where it sits within wider business, security, and governance structures.
Digital Transformation Still Has an Identity Problem
While AI may dominate enterprise technology conversations, Tolbert points out that organisations continue to struggle with some much more fundamental technology challenges.
Identity and access management remain areas where many businesses haven't established the strategies and processes they need.
“Switching away from the topic of GenAI, many organisations still struggle with IAM basics. They don’t have IAM strategies. Fraud eats away at many organisations’ bottom lines. Poor account registration/recovery and authentication processes push customers away and increase security risks. Digital transformation can start with easier-to-achieve milestones such as implementing passkeys for authentication and improving account registration and recovery processes.”
The point is significant because digital transformation doesn't necessarily have to begin with a massive technology overhaul. Improving fundamental identity and authentication experiences can deliver tangible progress while laying the groundwork for broader transformation.
Finding the Right Balance in Technology Adoption
When it comes to successful technology adoption, Tolbert believes organisations need to avoid two extremes.
On one side are huge, complex transformation projects that can take years to deliver. On the other are incremental initiatives that never quite reach completion.
“The most successful projects are those that find the right balance between massive upgrades (the sometimes years-long rip-and-replace types) and those that are approached so incrementally they never seem to finish. I’ve seen both extremes. In the end, it’s a mixture of technology and effective project management.”
That balance between technological capability and effective execution is likely to become even more important as organisations introduce increasingly complex AI and identity technologies.
Cybersecurity and Identity Are Business Enablers
One of the biggest misconceptions Tolbert encounters is the idea that cybersecurity and identity are simply costs.
While security investments are often viewed as defensive spending, he argues that the right technology choices can directly influence customer experiences, reputation, and ultimately revenue.
“That they’re just costs rather than business enablers. Most execs don’t like spending money on cyber and IAM, but technical implementation in both areas can improve user experiences and organisational reputation, which can positively affect revenues. A related misconception is that identity is an IT project rather than a business process. Registration, recovery, and authorization decisions affect customers and employees every day, so those design choices belong with the business owners as much as with IT.”
That last point is particularly important as identity becomes increasingly intertwined with customer experience and business operations. Identity decisions aren't simply technical controls operating behind the scenes, they shape how people interact with an organisation every day.
Humans and AI Will Move Towards a More Complex Partnership
Tolbert expects generative AI to remain a permanent part of enterprise technology, but believes its evolution will come with trade-offs.
Productivity gains are real, but they need to be considered alongside costs, quality, and the additional work AI can sometimes create.
“I think the trajectory we are on now is a good predictor. GenAI is here to stay. It can improve productivity, but it has costs in other areas. For example, organisations can use it for coding, but it does require additional debugging. AI agents will increasingly be used, but how the frontier models’ pricing schemes evolve may affect how many agents deploying organisations are willing to pay for. This in itself may push those who can manage open weight solutions to try those instead.”
As agentic AI becomes more common, these questions around cost and control will become increasingly significant.
But for Tolbert, perhaps the most important issue is not simply how many agents organisations deploy. It is what those agents are actually authorised to do.
The Next Big Identity Challenge: Agentic AI Authorisation
Among the technologies and developments Tolbert is watching most closely, agentic AI authorisation stands out.
As AI agents begin acting on behalf of users and organisations, traditional permission models may no longer be granular enough to safely govern their actions.
“Agentic AI authorisation. How will agent intent be represented and acted upon? Today most agents run with the permissions of the user or service account that launched them, which is far too coarse for the tasks they are being given. What is needed is a way to bind an agent's authorisation to a specific task, for a limited time, with a verifiable record of who delegated what and on whose behalf the agent is acting. That work is underway in the standards community, and it connects directly to the orchestration and policy layers I look at in identity fabrics. I expect it to be one of the harder identity problems of the next few years.”
This could become one of the defining challenges as enterprises move from AI assistants towards genuinely autonomous systems.
An agent may be acting on behalf of a human or service account, but that doesn't necessarily mean it should inherit all of that identity's permissions. The ability to establish what an agent was asked to do, what it was authorised to do, and who authorised it could become fundamental to enterprise AI governance.
Identity Plumbing Will Shape the Next Era of Enterprise Technology
Looking ahead, Tolbert doesn't believe the enterprise AI story is anywhere near finished.
Generative AI still has significant productivity potential, but organisations remain early in their approach to governance, cost management, and security. As those capabilities mature, identity and authorisation could become just as important as the underlying AI models.
“I think we have a long way to go yet with GenAI. The productivity gains are real, but most organisations are still early in governing it, costing it, and securing it, and all of that will take years to mature. The next era will be defined as much by the identity and authorisation plumbing around the models as by the models themselves: which agents exist, who they act for, what they are allowed to do, and how that can be proven after the fact. Organisations that get that right will be able to move automation out of pilots and into production.”
Final Thoughts
The future of AI is also an identity problem.
As organisations move from experimenting with generative AI towards deploying agents capable of taking action, the questions around identity, authorisation, governance, and accountability will become increasingly difficult to ignore.
Tolbert's perspective also serves as a reminder that enterprise transformation isn't always about adopting the newest technology. Organisations still need to get the fundamentals right, from authentication and account recovery to IAM strategy and fraud prevention.
The next phase will require both.
AI may provide the intelligence, but enterprises will need the identity and governance infrastructure to determine who, or what, is allowed to act, on whose behalf, and with what authority.
For organisations that can get that balance right, Tolbert believes the opportunity is significant: moving AI and automation beyond the pilot stage and into the fabric of everyday enterprise operations.
Comments ( 0 )