Megatrend · Cybersecurity & Digital Trust
When the walls disappear, what protects a company isn't its location — it's the question "who are you?"
In a world where everyone works from anywhere and every app lives in the cloud, the first checkpoint of security is no longer "which building are you connecting from." It's "who are you, and can you prove it?" — this is the business of proving identity and opening the door only to the right person: log in once and get into every app (SSO), confirm yourself in two layers (MFA), and the "issuer of digital ID cards" that every app agrees to trust. This field has one slogan that explains everything: "identity is the new perimeter."
01What it is — identity is the new perimeter
Think about going into a big concert. You don't show your ticket at every food stall or every restroom door — you show it once at the entrance, and they put a wristband on you. After that, every spot in the venue just glances at your wrist to know you've already been checked. This node is the one that makes that wristband for the digital world — a system that proves "who you are" once, then issues a "pass" that every app accepts.
In IT, this comes in three pieces you run into every day: SSO (Single Sign-On — log in once, get into every app), MFA (Multi-Factor Authentication — confirm yourself in two layers, like a password + a code on your phone), and the lead behind the scenes, the identity provider (IdP), or "issuer of digital ID cards," that every app agrees to trust. If the IdP says "this really is John," apps like Gmail, Slack, and Salesforce open the door right away, with no need to ask for a password again.
Why has this become so much more important? Because security used to be measured by location — if you were connecting from inside the office, you were trusted. But once everyone works from home and apps all move to the cloud, "inside the office" loses its meaning. The only thing that can still tell who should access what is identity. That's where the line the whole field repeats comes from: "identity is the new perimeter" — the old castle wall is replaced by a checkpoint of identity that travels with each person, everywhere.
On the megatrend map, this node is a sub-branch under Identity & Access Management (IAM) within the big trend Cybersecurity & Digital Trust, with two siblings that do different jobs — Privileged Access Management (PAM), which guards the keys to the most important rooms, and Identity Governance (IGA), which watches over who should have which rights. This node is the "front door" that everyone has to pass through in their daily logins.
SSO = log in at one place, get into every connected app, no need to remember multiple passwords · MFA = confirm yourself in more than one layer (something you know = password + something you have = phone/key + something you are = fingerprint/face) to stop someone who only stole the password · Identity Provider = the central system that holds identities and issues the "pass" other apps trust — the heart that SSO and MFA run through.
02Why it matters — every hack starts by stealing a login
There's a fact that made the whole security field pour money into identity: most modern attacks don't start by breaking through the wall, they start by walking in the front door with a stolen key. The Verizon DBIR 2025 report found that the use of stolen passwords was the starting point of 22% of breaches, and in the first quarter of 2025, over 56% of breaches came from passwords leaked where there was no MFA standing guard.
When "logging in" became the main battlefield, money flowed into this market fast. The global IAM market is worth about $26 billion in 2025 and is expected to reach ~$42.6 billion by 2030 — growing about 10–12% a year, with some firms estimating as far as $65 billion by 2034. More important than the numbers is the reason it grows: every organization in the world moving to the cloud has to invest in this before anything else, because if the identity checkpoint fails, everything else fails with it.
In economic terms, this matters because it's a "fixed tax" of the digital age — whether your business is a bank, a hospital, or an online store, everyone needs an identity-verification system, and once you pick a vendor it's hard to move (every employee and every app is wired in). So whoever holds the identity checkpoint earns steady, predictable subscription revenue — a prime spot that both Microsoft and startups want to grab.
03How it works (user → issuer → pass → app)
The heart of SSO lies in a simple mechanism called federation ("pooling trust") — instead of each app holding your password itself, all apps agree together that "we won't ask for the password ourselves, we'll trust the pass that the central issuer (IdP) has signed." Look at these four steps — it's what happens in a fraction of a second every time you press "Sign in with…"
Behind this pass are common standards that every camp speaks alike — SAML (the older one that big organizations have long used) and OIDC/OAuth (the newer, lighter one suited to mobile and modern apps — it's what sits behind the "Sign in with Google/Apple" button you press so often). Because they're open standards every app supports, the central issuer can plug into thousands of apps without rewriting one by one — and that's what makes this business stronger the bigger it gets (the more apps connected, the harder it is for customers to switch).
04Where it sits in the security world
This node is the "front door" of cloud-era security. But the front door alone isn't enough — it has to work in concert with the other branches of IAM and the whole security field to close the loop.
- Paired with PAM (the keys to the important rooms): this node handles the logins of ordinary people, while PAM handles the "high-power accounts" (the system admins who, if breached, mean disaster) — together these two layers cover identity from the ordinary employee to the admin
- Paired with IGA (who should have which rights): the front door checks "who you are," while IGA answers "so what should you be able to access" and sweeps away rights that are no longer needed — without IGA, one person can pile up too many rights until it becomes a hole
- The foundation of zero trust / SASE: the principle "trust no one until they prove themselves" can't work at all without a strong identity system answering who is who — IAM is the base layer that all of zero trust stands on
- Accelerated by AI on both sides: AI helps catch suspicious logins (from odd countries, at odd hours) more cleverly, but also lets hackers craft phishing emails and impersonations more convincingly — and crucially, the new wave of AI agents becomes another kind of "user" that needs its own identity and rights (see the future chapter)
05Where it stands now
This arena has the most interesting matchup in the security field: "the giant that throws it in for free" versus "the neutral specialist." On the giant's side is Microsoft with Entra ID (formerly Azure AD) — the largest identity system in the world, verifying over 30 billion times a day and covering about 1.2 billion identities. Its weapon isn't the best technology, it's "it comes in the Microsoft 365 package your company already pays for" — so a huge number of organizations use Microsoft's because it's effectively free.
On the other side is Okta, which sells a "neutral" stance — tied to no software camp, able to connect apps of any brand, making it the choice for organizations that don't want to entrust all their identity to Microsoft. Today Okta manages identity for over 19,450 customers, with revenue of about $682 million a quarter, growing ~13%. Then there's a third pole just forming — the fund Thoma Bravo bought Ping Identity ($2.8 billion) and merged it with ForgeRock ($2.3 billion) to build a rival big enough to take on the first two.
But the game doesn't end at scale, because many customers worry about "putting all their eggs in one basket" — if email, apps, and the identity system are all Microsoft's alone, then whenever Microsoft is breached (which has happened in several Entra/Azure AD hacks), everything collapses at once. This is the gap that Okta, Ping, and identity specialists sell into — "neutrality and deep security that a freebie can't give you."
And like other tech fields, each country has its own local leader — in Japan there's HENNGE, which helps Japanese organizations securely manage logins to SaaS apps, while China and Korea have their own domestic players, reflecting that "identity" is something many countries want to keep in their own hands for reasons of digital sovereignty.
06The road ahead — a passwordless world, and AI needs an identity too
The clearest first direction is the death of the password. Passwords are the biggest weakness — easy to steal, easy to trick, people reuse them. The answer gaining momentum is the passkey (a digital key tied to your device, unlocked with your fingerprint/face — it can't be stolen because there's no "code" to steal). The FIDO Alliance reports that over 1 billion people have already activated a passkey, and over 15 billion accounts already support them. Crucially, passkeys log in successfully 93% of the time versus ~63% for traditional passwords — more convenient and safer at the same time.
The second direction is the one flipping the whole field's premise: AI agents need an identity too. As companies start using AI assistants that work in people's place (booking tickets, pulling data, ordering payments), each agent is a "user" that has to prove itself and get only the rights it needs. The startling number: machine and software identities already outnumber humans by 80 to 1, and AI agents will push that even higher — this is the new arena where CyberArk, Microsoft, and Palo Alto are racing to set the standard for "identity for AI."
The third direction is the line between "employee identity" and "customer identity" (CIAM) growing ever sharper. The employee side stresses security and control, while the customer side (like signing up and logging into a bank or store app) stresses "a smooth experience that can still prove you're the real person" — opening a new arena for players like Clear Secure, who bring real face/identity verification onto the online world.
07Challenges & risks
The first risk is the shadow of Microsoft. When the giant throws an identity system into a package customers already pay for, independent players have to prove constantly that "what you pay extra for is better than the freebie, and where." This is a pressure that doesn't go away, and it's why Okta has to rush to expand into machine identity, customer identity, and deep security to escape being price-compared with "the free thing."
The second risk is trust is everything — and it's fragile. This product sells "security," so being breached even once hits far harder than for an ordinary product. Both Okta and Microsoft have faced incidents of their identity systems being breached that shook customer trust — in a business where you're "the keeper of everyone's keys," a reputation built over years can vanish in a single event.
The third risk is concentration and consolidation. This arena is consolidating fast — Thoma Bravo merged Ping+ForgeRock, CyberArk bought Venafi and is itself being bought by Palo Alto. The direction is toward only a few winners left standing. Good for the big players with full lineups, but it squeezes small specialists into finding a foothold or being swallowed. And for customers, relying too much on a single identity provider is itself a "single point of failure" risk.
In short: this node is the story of how "identity" became both the last and the first line of defense in the cloud era — when the castle walls disappear, what keeps outsiders away from the data is a simple question that gets harder to answer every day: "who are you, and can you prove it?" Whoever can answer that for the whole world most safely and smoothly holds the keys to the entire digital economy.