KuppingerCole published its 2026 Identity and Access Governance Leadership Compass this week, and named SailPoint an Overall Leader. In related news, water remains wet, the sun came up in the east, and somewhere a vendor marketing team is already resizing the badge for a LinkedIn banner. We say this with affection — the recognition is real and mostly deserved — but there is a running joke in this industry that the analyst-report press release template has a permanent <INSERT VENDOR> field and SailPoint's legal team has just autofilled it since roughly 2011.
Underneath the badge, though, this week had some genuinely useful signal: IBM put the average breach at a record $4.99M, seven of the last twelve funded security startups are building for agents and non-human identities, and attackers walked into Abbott through an environment it had bought four months earlier — which is a very expensive way to learn that M&A creates identity debt. Then our vendor assessment: Veza, now ServiceNow's $1.2B identity bet. Great product, genuinely differentiated graph, and an employee-review record for its go-to-market org that ranks in the bottom four percent of every company RepVue tracks. Both of those things are true, which is what makes it worth 2,000 words. Let's get into it.
the week, distilled — & why it lands on your desk
The 2026 Identity and Access Governance Leadership Compass landed this week with SailPoint taking Overall Leader alongside Product, Innovation and Market leadership — the clean sweep. KuppingerCole credits all-around functionality, market presence and financial strength, with the innovation score driven by investment in emerging capability. To be fair to everyone involved: this is a genuinely strong result, and it is also SailPoint's roughly annual tradition. The company has held Leader status across these reports for years, which is either powerful validation of durable category leadership or evidence that the incumbent with the biggest install base tends to score well on criteria that reward install base. Probably both.
IBM's 2026 Cost of a Data Breach put the global average at $4.99M and the US average at $11.5M — both records. Phishing was the top initial vector for the fourth consecutive year, which after four years stops being a finding and starts being a personality trait. The buried numbers are better: 63% of breached organizations had no AI governance policy, and 97% of those reporting an AI-related incident lacked proper AI access controls. Organizations using AI and automation extensively in security operations saved an average of $1.9M per breach and cut lifecycles by 80 days.
Abbott closed its $21B acquisition of Exact Sciences on March 23. By mid-June, attackers were inside the legacy Exact Sciences environment; Abbott confirmed the incident July 16, scoped to a limited number of internal systems in its Cancer Diagnostics business. The sequence is the lesson — roughly twelve weeks between "we own this now" and "someone else is in it."
Twelve qualifying cybersecurity funding deals between July 15 and August 4 raised roughly $1.09B, with Horizon3.ai, ThreatLocker and Glow capturing about 57% of it. The structural detail: seven of the twelve directly protect AI agents, AI-enabled applications, or non-human identities. Onyx Security's Series B brought its total to $153M. Agentic identity has gone from a category thesis to the default thing a security startup is funded to build.
SecurityWeek's tracker has catalogued about 400 cybersecurity transactions in 2026. The anchors: Google/Wiz at $32B (closed March), Palo Alto/CyberArk at $25B (closed February), ServiceNow/Armis at $7.75B (closed April), Accenture's $4.175B Dragos-runZero-NetRise package. Note the buyer mix — a hyperscaler, a security platform, a workflow platform, and a consultancy. When Accenture starts buying security software outright, the class of well-capitalized acquirers just got meaningfully larger.
An incident affecting European contract logistics operations at eight Ceva warehouses caused shipment delays for multiple customers. Separately this week: a Chrome V8 type-confusion bug enabling sandbox escape and control-flow hijacking, a 22-patch release heavy on code execution and privilege escalation, and the Head Mare hacktivist group exploiting bugs to deploy PhantomCore malware.
the pitch vs. the reality, synthesized from the people who run it
ServiceNow's FY2026 10-Q discloses the acquisition of Veza Technologies for approximately $1.2 billion, substantially in cash. The purchase-price allocation is the interesting part: $356M in intangible assets, $826M in goodwill. That ratio says ServiceNow paid roughly seven times more for market position, team and strategic fit than for identifiable technology — normal for a category land-grab, but worth knowing when a vendor tells you the valuation validates the product.
Context on the price: Veza had raised $235M total and was valued at $808M after a $108M Series D earlier in 2025. So ServiceNow paid roughly a 50% premium to the last private mark. Strategically it slots Veza into the ServiceNow AI Control Tower to govern what AI agents can access, and adds identity context to Vulnerability Response, Incident Response and Integrated Risk Management.
Veza's patented Access Graph maps and analyzes access relationships across human, machine and AI identities, answering not "who has an account" but "who can take what action on what data." That authorization-centric framing is materially different from directory-centric IGA, and it's why Forbes noted no other software giant had pursued a standalone, authorization-centric platform purpose-built for non-human identity governance. Even the harshest employee reviews concede the point: "Technology is solid." "The product is genuinely better than competitors — I've checked."
KuppingerCole's own analysis of the deal is measured and worth reading before you assume ServiceNow now "does IAM." Its argument: ServiceNow's great strength is workflows — structured, configurable, efficient — while identity governance deals in policy conflicts, risk models, separation of duties, legacy systems, privilege sprawl and complex on-premises applications. Veza adds a powerful access-visibility layer, particularly in cloud and SaaS. It does not eliminate the hard parts. Others flagged the practical risk: ensuring the Access Graph performs at enterprise scale across hybrid estates.
Veza's public employee-review record is unusually poor for a company with an outcome this good, and unusually consistent across two independent platforms and multiple years. On RepVue, across 29 verified ratings (86% verified, unclaimed profile), Veza scores 2.7/5 overall and 1.8/5 for culture and leadership — ranked #5,452 of 5,680 companies. Reported quota attainment sits at 15% of reps. On Glassdoor, the company rates 3.7/5 across 144 reviews — respectable, and in line with the IT industry average — but CEO approval is 58%, and the sales function specifically rates 1.5/5 with 13% CEO approval.
Trajectory: a very good product that just got a much better owner — and an organizational question that came along with it. Let's be clear about the product, because it deserves it. The Access Graph is one of the genuinely differentiated pieces of technology in this market. Mapping effective permissions across human, machine and AI identities to answer "who can take what action on what data" is harder than it sounds and most IGA platforms still can't do it well. ServiceNow paying $1.2B for a company last marked at $808M is a real vote, and slotting it under AI Control Tower to govern agent access is a coherent strategy rather than a land-grab.
The organizational record is the complication, and it's unusual enough to warrant the space. We have assessed seven vendors in this newsletter. None has had a public employee-review record like this one — not because individual reviews are harsher, but because the aggregates are: bottom 4% of all companies RepVue tracks for culture and leadership, 15% quota attainment, 58% CEO approval. Those are structural numbers, consistent across platforms and years, and they describe an organization that was difficult to work in even while building something valuable.
But read the split carefully, because it's the most interesting thing here. Engineering rates the place at 4.5–4.8 across every axis. Sales rates it 1.5 with 13% CEO approval. That is not a company in uniform crisis; it is a company where one function appears to have worked well and another appears to have been a difficult place to be. For a buyer, that distinction matters enormously — the people building your product were, by their own account, doing fine. Fifteen percent quota attainment tells you more about churn in your account team than about whether the software works.
So what do you actually do with this? Not "avoid Veza" — the product is good and the counterparty risk just went to near zero. Instead: assume account-team turnover and negotiate accordingly. Get named technical resources and escalation paths in the contract rather than relying on the relationship. Ask directly what has changed under ServiceNow ownership, and ask ServiceNow, not the Veza team. And pilot the Access Graph against your hybrid estate specifically, because that's where the analyst caution lands and where a cloud-native graph is most likely to strain.
a category, tool, or idea worth knowing this week
This issue's spotlight is the case study: one company, 4.8 from engineers and 1.5 from sellers. The blended 3.7 would have told you nothing. Filter by role before you draw a conclusion — engineering sentiment predicts product quality and roadmap velocity, go-to-market sentiment predicts whether your account team survives the contract term. Those are different risks and they deserve different mitigations.
Abbott closed an acquisition in March and had attackers in the acquired environment by June. Every deal hands you a second directory, an unmapped privilege model, and a population of accounts nobody owns. If your company is acquisitive, build a standing identity-integration playbook — discovery, ownership assignment, privileged-account reconciliation, orphan cleanup — and get it triggered by deal close rather than by the first audit.
Per IBM's 2026 breach report, 97% of organizations reporting an AI-related security incident lacked proper AI access controls, and 63% of breached organizations had no AI governance policy at all. If you have been struggling to explain why agent governance is an access problem rather than a model-safety problem, that pair of numbers does it in one slide.
one line to sound three moves ahead in your next exec meeting
Your board understands acquisitions as financial events with integration costs. They rarely hear identity framed as one of those costs — and then a company like Abbott closes a $21B deal in March and has intruders inside the acquired environment by June. That's a twelve-week window between closing and compromise. Bring it up before your company's next deal, not after.
a spicy anonymized take from the community this week