Live intel Wed · 29 Jul 2026 · 06:00 ET

ThePerimeter

FOR CIOs & CISOs
VOL. 1 · ISSUE 09 Sponsored by — your logo here — Subscribers: 19,840
// Good morning, defenders.

Two years ago, Okta's own security chief said the quiet part out loud: "We need a track record of zero breaches. That's what builds trust. The score sheet for us needs to be a clean sheet — zero for the next few years." It was an extraordinary admission from the company that holds the front-door keys for 20,000 organizations, and it set a clock running. This week, with Okta posting its strongest financials in years and a stock that's clawed back most of what the 2023 breach cost it, the question is simply: is the sheet clean?

That's the spotlight this issue — Okta, the identity incumbent that got breached at the worst possible moment for an identity company, and has spent two years trying to earn back the one thing it sells. The financials say recovery. The product reviews say "still the standard." The scar tissue, and a live fight over Auth0 pricing, say do your reading first. Plus a month of market movers, led by a $60M bet that the whole category needs replacing. Let's get into it.

01

Market Movers

the last week, distilled — & why it lands on your desk

Funding$60M

Oak steps out of stealth with $60M to rebuild identity for the agent era

Tel Aviv's Oak launched with a $60M seed co-led by Accel, Greylock, and CRV — an unusually large seed, and a telling one. Founder Shai Morag has sold three prior security startups (to Mellanox, Palo Alto, and Tenable), and Oak's pitch is blunt: cloud-era IAM tools were built for a human-only enterprise, and they can't track who — or what — accesses what once AI agents proliferate. It arrived already generally available and deployed at enterprises.

Why it matters: when serial founders and top-tier VCs put a $60M seed against "legacy IAM can't do agents," they're betting your current stack has a gap. Whether or not Oak wins, the thesis is a question to put to your incumbent — this issue's spotlight included.
Breach6.9M

AssuranceAmerica breach hits 6.9M — traced to employee credentials

The US auto insurer disclosed a breach affecting up to 6.9 million people, exposing names, contact details, driver's license numbers, and policy data. TechCrunch called it the largest known exposure of driver's license numbers so far in 2026. The root cause, again: compromised employee credentials — not an exotic exploit.

Why it matters: the through-line of every major breach this month is a stolen login. If your workforce MFA still allows phishable factors, this is the pattern that ends up in your incident report.
M&AMSP

Barracuda buys Evo Security — the identity roll-up reaches the MSP tier

Barracuda acquired Evo Security, an IAM provider built specifically for managed service providers, folding privileged access, identity protection, and ITDR into its BarracudaONE platform. It's a signal that identity consolidation isn't just an enterprise game — the MSP channel, which secures much of the mid-market, is being rolled up too. Meanwhile Europe saw Fourthline and Veridas announce a merger to form an identity-verification heavyweight.

Why it matters: if you rely on an MSP for security, your identity stack may change owners without you noticing. Ask who provides the identity layer underneath your managed services, and what happens to it now.
ThreatShadow AI

WatchGuard: employee behavior is the fastest-growing SMB risk

A new WatchGuard global survey finds shadow AI and unsafe work habits are creating significant, largely unseen risk — employees feeding data into unsanctioned AI tools, reusing credentials, and sidestepping controls. It lands alongside separate reporting on "ghost workers" and hiring deception, where weak identity and skills verification let bad actors into the workforce itself.

Why it matters: your AI-usage policy is only as real as your ability to see and govern it. Sanctioned tooling plus identity-aware access beats a policy PDF nobody reads.
ThreatAI

Researchers document the first fully AI-agent-driven ransomware

Security researchers this month described what they're calling the first ransomware operation run end-to-end by an AI agent — reconnaissance, access, and deployment with minimal human steering. Paired with a wave of AI-agent exploitation stories (OpenClaw agents abused via WhatsApp), the "autonomous attacker" moved from thought experiment to case study.

Why it matters: if attackers can run an agent, the speed of an intrusion compresses. Detection and response windows built around human-paced attackers are now optimistic — and identity is the throttle you control.
RansomwareDB

Deutsche Bank fears rise as a ransomware group posts "evidence"

A ransomware crew posted what it claims is proof of a Deutsche Bank compromise, raising extortion pressure on one of the world's largest banks; the D1R group separately claimed data from Synopsys and Bosch. Whether or not every claim holds, the tactic — public "proof" to force a negotiation — is now standard operating procedure.

Why it matters: extortion posts are designed to panic your board before your IR team has facts. A pre-agreed comms-and-verification playbook is what keeps a claim from becoming a crisis of its own making.
02

Vendor Spotlight

the pitch vs. the reality, synthesized from the people who run it

Okta
NASDAQ: OKTA · Workforce + Customer Identity (Auth0) · The neutral front door
VERDICT: STRONG RECOVERY — TRUST IS THE OPEN QUESTION
Product / Capability
7.6/10
Implementation Ease
8.3/10
Vendor Stability
7.4/10
Trust & Track Record
6.4/10

Recent News — last 90 days

Earnings FY2026
Status: PUBLIC
~$2.88B revenue, 11% growth, and the profit finally showed up

Okta closed FY2026 at roughly $2.88B in revenue (11% YoY), with non-GAAP operating margin around 25–26% and strong free cash flow — a genuine turn for a company that hadn't posted a quarterly profit since its 2017 IPO. Recent quarters beat consensus handily (Q1 FY27 EPS $0.91 vs. $0.74 expected), current RPO grew double digits, and 20,000+ customers now include large public-sector wins. Market cap sits near $18B.

Read: the financial-stability worry that dogged Okta for years is largely answered. This is a durable, cash-generating platform. The risk in an Okta decision has moved off the balance sheet and onto the trust question below.
Okta Investor Relations ↗
Product · M&A 2025–26
Okta pushes past SSO — governance, PAM, and the Axiom buy

Okta has spent the last year expanding beyond its front-door heritage: Okta Identity Governance (OIG), Privileged Access, and the acquisition of Axiom Security for SaaS security-posture management and real-time session monitoring. Add early AI-agent security products drawing outsized deal sizes, and the pitch is a single unified platform — neutral and independent, not tied to a cloud or productivity suite.

Read: the "SSO vendor" is now a real governance and PAM competitor to SailPoint, CyberArk, and Saviynt. Its neutrality (no Microsoft/Google lock-in) is a genuine differentiator — but you're buying an expanding platform, so scrutinize which modules are mature versus recently acquired.
The scar tissue 2022–2023
The breaches that reset Okta — and the "zero for the next few years" pledge

Okta's recent history is defined by security failures at the worst possible place for an identity company: a 2022 LAPSUS$ intrusion and stolen GitHub source code, then the 2023 support-system breach that Okta first pegged at ~1% of customers before conceding, weeks later, that 100% of its ~18,400 support customers were exposed. BeyondTrust and Cloudflare detected it before Okta did. Security chief David Bradbury's response set the bar: "We need a track record of zero breaches… the score sheet needs to be a clean sheet for the next few years."

Read: this is the crux of the spotlight, and why Trust scores a 6.4 while everything else scores high. The remediation was real and the disclosures more transparent over time — but the pattern of customers detecting breaches first left lasting scar tissue. Ask Okta directly what's changed since, and verify it.
Okta Security (sec.okta.com) ↗
Live gripe ongoing
Auth0 pricing is the recurring complaint — and it's sharp

Okta's developer-identity arm, Auth0, draws consistent fire on cost. G2's top negative tags include "Expensive," "Cost," and "Expensive Pricing"; multiple reviewers cite a jarring price increase (one widely-referenced review calls a ~300% jump "hostile/predatory") and renewals that doubled. Per-user costs escalate steeply as you scale, and enterprise features sit behind higher tiers. A separate verified review flagged unanswered support on a critical issue.

Read: Okta Workforce reviews well (G2 4.5), but Auth0's pricing is the live landmine for anyone building customer identity on it. Model your costs at 2–3x your current user count, and get renewal caps in writing before you commit.
SOURCING: Financials per Okta SEC filings and FY2026 earnings releases. Breach history per Okta's own security post-mortems (sec.okta.com), BeyondTrust and Cloudflare disclosures, and contemporaneous reporting (Cybersecurity Dive, Dark Reading); the Bradbury quote per Cybersecurity Dive. Auth0 pricing sentiment per G2 and AWS Marketplace verified reviews. The 2022–23 breaches are established fact; current security posture is the company's to prove and the buyer's to verify.

The Pitch vs. The Reality

What Okta says
  • The neutral, independent identity platform — no cloud or productivity-suite lock-in
  • One platform: workforce SSO/MFA, customer identity (Auth0), governance, PAM
  • Security is now the top priority, rebuilt "from the top down" since 2023
  • Best-in-class SSO/MFA at scale, trusted by 20,000+ orgs and major governments
What practitioners report
  • SSO/MFA genuinely excel — G2 4.5, top marks for ease of use and rollout at scale
  • Governance, PAM, and Agent Security are newer and thinner-proven — limited GA track record
  • Neutrality is a real edge for multi-cloud shops wary of Microsoft Entra lock-in
  • Auth0 pricing draws sharp fire — steep tier jumps, big renewal increases, "predatory" claims
  • Employees flag smart teams and a strong product, but unclear leadership and constant pivots
  • The breach history still shapes buyer conversations; trust is earned back slowly

Community Pulse — synthesized signal

G2 · Okta Workforce 4.5/5 · 1,164 reviews
"It makes it straightforward to roll out SSO, MFA, and user lifecycle management at scale."
— mid-market reviewer · Okta scores 9.3 ease of use and 9.6 on SSO, among the strongest in the category. The core workforce product is genuinely well-liked; this is not a company with a product problem
strongly positive
G2 / AWS · Auth0 (customer identity) 4.3/5 · pricing flag
"They were already expensive, then raised pricing 300% — including for existing customers. Unheard of and predatory after you've invested in the platform."
— verified Auth0 review · pricing is the dominant complaint: "Expensive," "Cost," and "Expensive Pricing" are top negative tags, with steep per-user escalation and renewal jumps. One review flagged unanswered support on a critical issue
good product, cost pain
Security Community · the trust question qualitative · cautious
"We need a track record of zero breaches. That's what builds trust. The score sheet needs to be a clean sheet for the next few years." — Okta's own CSO
— the 2023 support-system breach went from "1% of customers" to "100%" over a few weeks, and BeyondTrust and Cloudflare caught it before Okta did. The remediation has been real and disclosures more transparent since — but security teams still bring extra monitoring rather than trusting the vendor by default
rebuilding, not rebuilt
Analyst / Financial Signal ~$18B mkt cap
"Solid results, raised guidance, strong new-product adoption and public-sector wins — the stock has recovered most of the breach-era drawdown."
— synthesized from FY2026 earnings coverage; ~$2.88B revenue, 11% growth, now consistently profitable on a non-GAAP basis. The financial-durability question that once shadowed Okta is largely settled
strong & recovering
Glassdoor · Employee Signal culture · mixed
"Strong team but outdated technology and lower pay… leader in identity space, smart co-workers — but an old monolith to work on." + "Leadership lacks ability to prioritize; high-priority projects had little value or came from off-the-cuff CEO/CRO decisions. Whiplash trying to juggle constant pivots."
— two recent reviews (a current staff engineer and a former employee, 2026). The consistent, product-relevant theme isn't compensation — it's unclear leadership and constant re-prioritization, echoed across multiple reviews. Separate accounts describe toxic individual managers on specific teams; those read as team-level rather than clearly company-wide, so we weight them lower — but the "constant pivots / off-the-cuff decisions" signal is corroborated enough to matter
smart people, shaky steering
Competitive Position · neutrality qualitative · differentiator
"The independent, neutral option — the identity layer that isn't trying to sell you a cloud or an office suite too."
— Okta's clearest strategic edge against Microsoft Entra (bundled, hard to refuse) and the governance incumbents. For multi-cloud and vendor-diversification-minded shops, neutrality is a genuine reason it stays on shortlists
real differentiator
METHOD: Synthesized across G2 (Okta Workforce 1,164 reviews; Auth0 235+ reviews), AWS Marketplace verified reviews, Glassdoor employee reviews, FY2026 earnings coverage, and Okta's own breach post-mortems as of Jul 2026. A note on scoring: Product / Capability sits at 7.6, below where the workforce SSO/MFA reviews alone would put it — core auth is excellent, but Okta's newer platform expansion (IGA, PAM, Agent Security) isn't GA-proven at scale yet, and we score the platform Okta is selling you, not just the module it's famous for. Implementation scores high and is well-supported. We nudged Vendor Stability to 7.4 because recent Glassdoor reviews show a consistent, product-relevant theme — smart people and a strong product, but unclear leadership and constant re-prioritization ("off-the-cuff CEO/CRO decisions," "whiplash"). Employee sentiment is a leading indicator of roadmap coherence, so it belongs in the stability read, not just the culture footnote. Reports of toxic individual managers appear team-level rather than clearly systemic and are weighted lower. Trust & Track Record (6.4) is a separate axis reflecting the 2022–23 breach record specifically — for an identity vendor, being breached is uniquely disqualifying in a way it isn't for other software. All three score notes are editorial judgments, stated plainly so you can weight them yourself. Financials are company-reported; breach facts are established record.

The Signal Read

Trajectory: a strong core, an unproven expansion. Strip away the history and Okta's workforce heritage is genuinely excellent: category-leading SSO and MFA (G2 4.5), a real neutrality advantage over a bundled Microsoft Entra, and — finally — the financials of a durable public company. But the platform story Okta is now selling — governance, PAM, and Agent Security bundled in as "one platform" — leans heavily on products that are newer and thinner-proven, with limited GA track record next to the 15-year-old SSO core. That gap is why the product score sits at 7.6 rather than higher: the foundation is excellent, but you're being sold a platform, and part of that platform hasn't been tested at scale yet.

But you can't strip away the history, and for an identity vendor you shouldn't. Okta got breached at the one place a security company can least afford it, more than once, and the 2023 incident's "1% → 100% of customers" revision — caught by BeyondTrust and Cloudflare before Okta's own detection — is exactly the kind of thing that makes a CISO keep independent monitoring on their own IdP. That's why we broke out Trust & Track Record as its own score and marked it 6.4 while everything else sits high. Add a consistent employee signal — strong product and smart people, but "constant pivots" and "off-the-cuff CEO/CRO decisions" that nudged our stability read down too — and the picture is a capable platform whose steering is worth watching. The recovery is real; so is the scar tissue and the internal churn. All of it is true at once.

The live, practical gripe is Auth0 pricing. If you're building customer identity, model costs at 2–3x your current user count and get renewal caps in writing — the "300% increase" reviews aren't outliers, they're a pattern. Net: a strong buy on capability, a "verify the security posture yourself" on trust, and a "read the contract twice" on cost. For a multi-cloud shop that values neutrality, that can still be the right answer — with eyes open.

Buy the story if…
  • You want best-in-class SSO/MFA and value a neutral, non-Microsoft identity layer
  • You're multi-cloud and wary of Entra lock-in — neutrality is a real differentiator
  • You want one vendor moving across workforce, customer, governance, and PAM
  • Financial durability matters — this is now a profitable, ~$18B public company
Do your homework on…
  • Security posture — ask specifically what's changed since 2023, and verify, don't take it on faith
  • Auth0 costs — model at 2–3x users and get renewal caps in writing before you sign
  • Which platform modules are mature vs. recently acquired (e.g. Axiom) — buy the proven ones first
  • GA status and reference customers for IGA, PAM, and Agent Security specifically — don't buy the roadmap
03

The Stack

a category, tool, or idea worth knowing this week

Buying discipline

For an identity vendor, breach history is a product attribute

With most software, a past breach is a footnote. With the vendor that holds your authentication, it's central — because the failure mode is your entire access layer. When you evaluate an identity provider, weight their track record and, crucially, their disclosure behavior (did they tell customers, or did customers tell them?) as heavily as the feature matrix. Then keep independent monitoring on your IdP regardless of who it is.

Emerging category

Agent access mapping

Oak's $60M seed is the loudest of several bets on the same gap: as AI agents proliferate, nobody can answer "which agent accessed what, and when?" Legacy IAM was built to map humans to apps, not agents to tools. Whether you buy a startup or press your incumbent, get a straight answer on how non-human and agent access is discovered and governed — not just authenticated.

Control to revisit

The extortion-post playbook

The Deutsche Bank "evidence" post is this week's reminder: attackers now weaponize the disclosure itself, dropping partial "proof" to panic your board before your IR team has facts. A pre-agreed verification-and-comms playbook — who confirms, who speaks, what you say before you know — is what keeps an unverified claim from becoming its own crisis.

04

Boardroom

one line to sound three moves ahead in your next exec meeting

Say this

Ask your identity vendor the question they hope you won't

Every identity provider will show you a feature matrix. Fewer will volunteer their breach history and — more tellingly — how they found out about it. When you're picking the vendor that holds the keys to everything, their disclosure behavior under pressure is a better predictor of your future incident experience than any capability chart. Make it an explicit evaluation criterion, not an awkward afterthought.

"Before we sign with any identity vendor, I want their breach history and their disclosure timeline in writing. The company that tells its customers first is the one I trust with our front door."
05

Overheard

a spicy anonymized take from the community this week

"We still run Okta. We also still run our own monitoring on top of Okta, because last time they found out from Cloudflare. Both of those things are going to stay true for a while."
— security lead, enterprise SaaS · overheard in a peer Slack, lightly paraphrased