Live intel Wed · 26 Aug 2026 · 06:00 ET

ThePerimeter

FOR CIOs & CISOs
VOL. 1 · ISSUE 13 Sponsored by — your logo here — Subscribers: 23,040
// Good morning, defenders.

KuppingerCole published its 2026 Identity and Access Governance Leadership Compass this week, and named SailPoint an Overall Leader. In related news, water remains wet, the sun came up in the east, and somewhere a vendor marketing team is already resizing the badge for a LinkedIn banner. We say this with affection — the recognition is real and mostly deserved — but there is a running joke in this industry that the analyst-report press release template has a permanent <INSERT VENDOR> field and SailPoint's legal team has just autofilled it since roughly 2011.

Underneath the badge, though, this week had some genuinely useful signal: IBM put the average breach at a record $4.99M, seven of the last twelve funded security startups are building for agents and non-human identities, and attackers walked into Abbott through an environment it had bought four months earlier — which is a very expensive way to learn that M&A creates identity debt. Then our vendor assessment: Veza, now ServiceNow's $1.2B identity bet. Great product, genuinely differentiated graph, and an employee-review record for its go-to-market org that ranks in the bottom four percent of every company RepVue tracks. Both of those things are true, which is what makes it worth 2,000 words. Let's get into it.

01

Market Movers

the week, distilled — & why it lands on your desk

Analysts4/4

KuppingerCole names SailPoint Overall Leader — again

The 2026 Identity and Access Governance Leadership Compass landed this week with SailPoint taking Overall Leader alongside Product, Innovation and Market leadership — the clean sweep. KuppingerCole credits all-around functionality, market presence and financial strength, with the innovation score driven by investment in emerging capability. To be fair to everyone involved: this is a genuinely strong result, and it is also SailPoint's roughly annual tradition. The company has held Leader status across these reports for years, which is either powerful validation of durable category leadership or evidence that the incumbent with the biggest install base tends to score well on criteria that reward install base. Probably both.

Why it matters: analyst leadership is a real signal and a lagging one. It tells you a vendor is safe to shortlist; it does not tell you whether the newest module works. Use the Compass to build the list, then use references to cut it — and notice which vendors show up as Leaders in categories they entered eighteen months ago.
Breach cost$4.99M

IBM: average breach hits a record $4.99M, and phishing leads for the fourth straight year

IBM's 2026 Cost of a Data Breach put the global average at $4.99M and the US average at $11.5M — both records. Phishing was the top initial vector for the fourth consecutive year, which after four years stops being a finding and starts being a personality trait. The buried numbers are better: 63% of breached organizations had no AI governance policy, and 97% of those reporting an AI-related incident lacked proper AI access controls. Organizations using AI and automation extensively in security operations saved an average of $1.9M per breach and cut lifecycles by 80 days.

Why it matters: that 97% figure is the most quotable number in security this year and it points directly at access control, not model safety. If you need one slide to justify an agent-governance budget, this is it.
BreachM&A

Attackers got into Abbott through a company it had just bought

Abbott closed its $21B acquisition of Exact Sciences on March 23. By mid-June, attackers were inside the legacy Exact Sciences environment; Abbott confirmed the incident July 16, scoped to a limited number of internal systems in its Cancer Diagnostics business. The sequence is the lesson — roughly twelve weeks between "we own this now" and "someone else is in it."

Why it matters: every acquisition is an identity migration you inherit rather than design. Orphaned accounts, unmapped privilege, two directories nobody has reconciled. If your company is acquisitive, day-one identity integration deserves the same urgency as day-one financial consolidation, and almost never gets it.
Funding7 of 12

$1.09B across 12 security rounds — and seven are building for agents

Twelve qualifying cybersecurity funding deals between July 15 and August 4 raised roughly $1.09B, with Horizon3.ai, ThreatLocker and Glow capturing about 57% of it. The structural detail: seven of the twelve directly protect AI agents, AI-enabled applications, or non-human identities. Onyx Security's Series B brought its total to $153M. Agentic identity has gone from a category thesis to the default thing a security startup is funded to build.

Why it matters: your inbound vendor pitches are about to get very repetitive. The upside is real pricing leverage in a crowded field; the downside is that most of these companies won't exist in three years. Buy the problem, not the round size.
M&A~400

The consolidation tape keeps running — roughly 400 deals year-to-date

SecurityWeek's tracker has catalogued about 400 cybersecurity transactions in 2026. The anchors: Google/Wiz at $32B (closed March), Palo Alto/CyberArk at $25B (closed February), ServiceNow/Armis at $7.75B (closed April), Accenture's $4.175B Dragos-runZero-NetRise package. Note the buyer mix — a hyperscaler, a security platform, a workflow platform, and a consultancy. When Accenture starts buying security software outright, the class of well-capitalized acquirers just got meaningfully larger.

Why it matters: we keep saying this and it keeps being true: get change-of-control terms in writing. At 400 deals a year, the odds your vendor stays independent through your contract term are not what you assume.
Ops8

Ceva Logistics ransomware disrupts eight European warehouses

An incident affecting European contract logistics operations at eight Ceva warehouses caused shipment delays for multiple customers. Separately this week: a Chrome V8 type-confusion bug enabling sandbox escape and control-flow hijacking, a 22-patch release heavy on code execution and privilege escalation, and the Head Mare hacktivist group exploiting bugs to deploy PhantomCore malware.

Why it matters: the third-party operational hit is the one that reaches your customers without touching your network. Ask your logistics and fulfilment partners the same identity questions you ask your SaaS vendors — most organizations never have.
02

Vendor Spotlight

the pitch vs. the reality, synthesized from the people who run it

Veza
Acquired by ServiceNow (NYSE: NOW) · ~$1.2B, closed Mar 2, 2026 · Access Graph · NHI + SaaS access + ISPM
VERDICT: EXCELLENT PRODUCT, TROUBLED ENGINE, NEW OWNER
Product / Capability
8.2/10
Implementation Ease
7.5/10
Vendor Stability
8.0/10
Culture & Leadership Signal
3.2/10

Recent News — the acquisition and what preceded it

M&A · closed Announced Dec 2, 2025
Closed Mar 2, 2026
~$1.2B cash
ServiceNow bought Veza for ~$1.2B — and the 10-Q tells you what it really paid for

ServiceNow's FY2026 10-Q discloses the acquisition of Veza Technologies for approximately $1.2 billion, substantially in cash. The purchase-price allocation is the interesting part: $356M in intangible assets, $826M in goodwill. That ratio says ServiceNow paid roughly seven times more for market position, team and strategic fit than for identifiable technology — normal for a category land-grab, but worth knowing when a vendor tells you the valuation validates the product.

Context on the price: Veza had raised $235M total and was valued at $808M after a $108M Series D earlier in 2025. So ServiceNow paid roughly a 50% premium to the last private mark. Strategically it slots Veza into the ServiceNow AI Control Tower to govern what AI agents can access, and adds identity context to Vulnerability Response, Incident Response and Integrated Risk Management.

Read: for existing Veza customers this is mostly good news — counterparty risk essentially disappears. The open question is roadmap: you are now a feature of a workflow platform's security portfolio rather than the whole company's reason to exist.
ServiceNow 10-Q · purchase price allocation ↗
Product since 2022
The Access Graph is the real asset — and it's genuinely differentiated

Veza's patented Access Graph maps and analyzes access relationships across human, machine and AI identities, answering not "who has an account" but "who can take what action on what data." That authorization-centric framing is materially different from directory-centric IGA, and it's why Forbes noted no other software giant had pursued a standalone, authorization-centric platform purpose-built for non-human identity governance. Even the harshest employee reviews concede the point: "Technology is solid." "The product is genuinely better than competitors — I've checked."

Read: when critics who are actively warning people away from a company still volunteer that the product is good, believe them about the product. Effective-permissions analysis at this depth remains rare.
Integration risk analyst view
KuppingerCole: Veza strengthens visibility, but doesn't close the governance gap

KuppingerCole's own analysis of the deal is measured and worth reading before you assume ServiceNow now "does IAM." Its argument: ServiceNow's great strength is workflows — structured, configurable, efficient — while identity governance deals in policy conflicts, risk models, separation of duties, legacy systems, privilege sprawl and complex on-premises applications. Veza adds a powerful access-visibility layer, particularly in cloud and SaaS. It does not eliminate the hard parts. Others flagged the practical risk: ensuring the Access Graph performs at enterprise scale across hybrid estates.

Read: "we'll just use ServiceNow for identity now" is the expensive assumption of 2027. Veza is strongest in cloud and SaaS; if your estate is heavy on legacy on-prem entitlements, scope carefully and pilot at real scale.
The other record 2023 –
2026
A go-to-market organization rated in the bottom 4% for culture and leadership

Veza's public employee-review record is unusually poor for a company with an outcome this good, and unusually consistent across two independent platforms and multiple years. On RepVue, across 29 verified ratings (86% verified, unclaimed profile), Veza scores 2.7/5 overall and 1.8/5 for culture and leadership — ranked #5,452 of 5,680 companies. Reported quota attainment sits at 15% of reps. On Glassdoor, the company rates 3.7/5 across 144 reviews — respectable, and in line with the IT industry average — but CEO approval is 58%, and the sales function specifically rates 1.5/5 with 13% CEO approval.

Read: the aggregate ratings are the defensible part, and they're stark. Fifteen percent quota attainment and a bottom-4% culture ranking are not opinions; they're what verified reviewers reported. What they mean for you as a customer is the subject of the pulse section below.
SOURCING: Deal value, closing date and purchase-price allocation per ServiceNow's FY2026 Form 10-Q filed with the SEC. Prior valuation ($808M post-Series D, $235M raised) per SecurityWeek. Strategic rationale per ServiceNow and Veza press materials. Integration analysis per KuppingerCole's published blog on the acquisition and Forbes/Moor Insights. Employee sentiment per RepVue (29 verified ratings) and Glassdoor (144 reviews) as of Aug 2026 — both unclaimed or unmanaged profiles. Individual reviews are anonymous opinions and are not independently verified; we cite aggregate scores as the primary evidence and quote individual reviews as illustrative sentiment only. Veza and ServiceNow were not contacted prior to publication and no representative reviewed this assessment.

The Pitch vs. The Reality

What Veza / ServiceNow say
  • The Access Graph shows who can take what action on what data — not just who has an account
  • AI-native, authorization-centric, built for human, machine and AI identities from the start
  • Inside ServiceNow: a "true single pane of glass, with control of every identity in your organization"
  • Enhances AI Control Tower by governing what AI agents can access and do
What the evidence shows
  • The technology is well-regarded, including by people actively criticizing the company
  • Strongest in cloud and SaaS; hybrid and legacy on-prem scale is the open engineering question
  • Analysts caution the deal adds visibility without closing the governance gap
  • Engineering reviews are genuinely positive; go-to-market reviews are among the worst we've assessed
  • 15% reported quota attainment suggests a sales motion that has not been working

Community Pulse — synthesized signal

RepVue · Sales Organization 1.8/5 culture & leadership
"Product Market Fit is solid and the strategic vision appears set up for success… the founder/CEO is very involved in deals. Sales process is in flux a lot."
— verified sales professional. Aggregate across 29 verified ratings: 2.7/5 overall, RepVue score 71.37, culture and leadership ranked #5,452 of 5,680 companies, quota attainment 15%. Product-market fit rates 3.4/5 (#202 of 381) — meaningfully better than the culture score, which is the whole pattern in two numbers
bottom 4% for culture
Glassdoor · the CEO question 58% CEO approval
"The company has a great product, but leadership choices, particularly at the top, significantly impact morale and workplace culture. There is a pattern of unprofessional behavior and public criticism from the CEO that has been demotivating and counterproductive for the team."
— one of many reviews naming the same theme across multiple years: heavy founder involvement in day-to-day work, described by one reviewer as a "trust building phase" during which the CEO closely inspects output, with the duration depending on seniority. 58% CEO approval is well below the norm for a well-funded startup; the sales function specifically registers 13%
consistent theme, multi-year
Glassdoor · Engineering 4.5+ on most axes
"Solving extremely challenging problems in a high-demand industry. Working on the core product offers fantastic exposure to modern cloud and AI security architecture."
this is the counterweight and it matters. Software engineers rate Veza around 4.5 for work-life balance, 4.7 for diversity and inclusion, 4.5 for culture and values and 4.8 for career opportunities. The same company that ranks bottom-4% for sales culture has an engineering org that reads as genuinely healthy. Whatever is happening here is function-specific, not company-wide
strongly positive
The dissent · positive reviews genuine, not sparse
"I've been in Sales for 10+ years and Veza, hands down, has the best Sales and Executive leadership I've experienced. I read negative reviews before joining. I can wholeheartedly say the CEO and his team are personally invested in your growth."
— we include this deliberately and without spin. Positive reviews exist, are substantive, and some explicitly rebut the negative ones. Overall Glassdoor sits at 3.7/5 — in line with the IT industry average of 3.8. A demanding founder-led culture reads as "invested" to some people and "controlling" to others, and both experiences are real
real counter-evidence
The buyer's question what changes now
"Hopefully ServiceNow, that acquired Veza, realizes this and makes some course corrections before it's too late." / "The pace can be relentless… I hope this will change with the acquisition."
— multiple reviewers explicitly framed the acquisition as a potential fix. That's the practical lens for a buyer: most of what's documented here concerns a private company's go-to-market org that now reports into a $200B+ public company with its own leadership structure and HR apparatus. Whether it persists is genuinely unknown — and worth asking about directly
open question
METHOD: Synthesized from RepVue (29 verified ratings), Glassdoor (144 reviews), ServiceNow SEC filings, KuppingerCole's published deal analysis, and company materials as of Aug 2026. A note on the fourth axis. We scored Culture & Leadership Signal at 3.2 — our lowest on any axis to date — and we want to be precise about what that does and does not mean. It rests on aggregate figures, not on the harshest individual reviews: 1.8/5 for culture and leadership on RepVue (a percentile ranking, not a quote), 15% reported quota attainment, and 58% CEO approval on Glassdoor. Those numbers are consistent across two independent platforms and several years. We have deliberately not reproduced the most personally abusive characterizations of the CEO that appear in these reviews; they are anonymous, unverifiable, and reprinting them would be gossip rather than analysis. We have also weighted the strongly positive engineering ratings and the substantive positive reviews, which is why Product scores 8.2 and this axis is not lower. Our read is that this reflects a demanding founder-led go-to-market culture with a real retention and attainment problem — not a verdict on any individual.

The Signal Read

Trajectory: a very good product that just got a much better owner — and an organizational question that came along with it. Let's be clear about the product, because it deserves it. The Access Graph is one of the genuinely differentiated pieces of technology in this market. Mapping effective permissions across human, machine and AI identities to answer "who can take what action on what data" is harder than it sounds and most IGA platforms still can't do it well. ServiceNow paying $1.2B for a company last marked at $808M is a real vote, and slotting it under AI Control Tower to govern agent access is a coherent strategy rather than a land-grab.

The organizational record is the complication, and it's unusual enough to warrant the space. We have assessed seven vendors in this newsletter. None has had a public employee-review record like this one — not because individual reviews are harsher, but because the aggregates are: bottom 4% of all companies RepVue tracks for culture and leadership, 15% quota attainment, 58% CEO approval. Those are structural numbers, consistent across platforms and years, and they describe an organization that was difficult to work in even while building something valuable.

But read the split carefully, because it's the most interesting thing here. Engineering rates the place at 4.5–4.8 across every axis. Sales rates it 1.5 with 13% CEO approval. That is not a company in uniform crisis; it is a company where one function appears to have worked well and another appears to have been a difficult place to be. For a buyer, that distinction matters enormously — the people building your product were, by their own account, doing fine. Fifteen percent quota attainment tells you more about churn in your account team than about whether the software works.

So what do you actually do with this? Not "avoid Veza" — the product is good and the counterparty risk just went to near zero. Instead: assume account-team turnover and negotiate accordingly. Get named technical resources and escalation paths in the contract rather than relying on the relationship. Ask directly what has changed under ServiceNow ownership, and ask ServiceNow, not the Veza team. And pilot the Access Graph against your hybrid estate specifically, because that's where the analyst caution lands and where a cloud-native graph is most likely to strain.

Buy the story if…
  • You need genuine effective-permissions analysis, not directory-level "who has an account"
  • You're a ServiceNow shop — the workflow and AI Control Tower integration is the real thesis here
  • Your estate skews cloud and SaaS, where the Access Graph is strongest
  • Vendor durability matters — you're now buying from a $200B+ public company
Do your homework on…
  • Hybrid and legacy on-prem scale — pilot the graph against your real entitlement sprawl, not a cloud demo
  • Assume account-team churn; get named technical contacts and escalation paths written into the contract
  • Ask ServiceNow directly what has changed operationally since close, and what the integration roadmap commits to
  • Don't assume ServiceNow now "does IAM" — Veza adds visibility, not a complete governance program
  • Clarify pricing under the ServiceNow model before renewal; platform bundling cuts both ways
03

The Stack

a category, tool, or idea worth knowing this week

Diligence technique

Read employee reviews by function, not by average

This issue's spotlight is the case study: one company, 4.8 from engineers and 1.5 from sellers. The blended 3.7 would have told you nothing. Filter by role before you draw a conclusion — engineering sentiment predicts product quality and roadmap velocity, go-to-market sentiment predicts whether your account team survives the contract term. Those are different risks and they deserve different mitigations.

Control to revisit

Day-one identity integration for M&A

Abbott closed an acquisition in March and had attackers in the acquired environment by June. Every deal hands you a second directory, an unmapped privilege model, and a population of accounts nobody owns. If your company is acquisitive, build a standing identity-integration playbook — discovery, ownership assignment, privileged-account reconciliation, orphan cleanup — and get it triggered by deal close rather than by the first audit.

Number to steal

97%

Per IBM's 2026 breach report, 97% of organizations reporting an AI-related security incident lacked proper AI access controls, and 63% of breached organizations had no AI governance policy at all. If you have been struggling to explain why agent governance is an access problem rather than a model-safety problem, that pair of numbers does it in one slide.

04

Boardroom

one line to sound three moves ahead in your next exec meeting

Say this

Put a number on what an acquisition does to your identity risk

Your board understands acquisitions as financial events with integration costs. They rarely hear identity framed as one of those costs — and then a company like Abbott closes a $21B deal in March and has intruders inside the acquired environment by June. That's a twelve-week window between closing and compromise. Bring it up before your company's next deal, not after.

"Every acquisition we close hands us an unmapped directory and a population of privileged accounts nobody owns. I'd like identity integration funded at close, alongside financial consolidation — because the alternative is discovering it at the same time an attacker does."
05

Overheard

a spicy anonymized take from the community this week

"Got the vendor's analyst-report email at 6am, the badge graphic at 9, the LinkedIn post from their CRO at 11, and a calendar invite from my rep at noon to "walk through what the recognition means for us." What it means is you're a Leader in a category you've led for a decade. Send the renewal quote instead."
— identity director, insurance · overheard in a peer Slack, lightly paraphrased