In a big company with tens of thousands of employees and thousands of apps, everyone holds dozens of "digital keys" — to email, to payroll, to the customer database. But ask an executive a simple question: "Right now, who holds which keys, and should they?" Most can't answer on the spot. This is the problem IGA (Identity Governance & Administration) was built to solve — a system that constantly answers three questions: who can access what · should they really have that right · and can you prove it to an auditor. It isn't glamorous, but it's required by law, and it's where a lot of money is flowing in.
ServiceNow Launches AI Control Tower for Enterprise AI Governance
ServiceNow introduced new AI governance and workflow security tools called AI Control Tower, Context Engine, and Shift Zero. The products are aimed at helping enterprises manage AI agents with integrated identity, context, and cybersecurity controls. ServiceNow is targeting secure automation, access management, and compliance needs as companies expand AI-driven workflows across their operations. ServiceNow runs cloud software that helps large organizations manage digital workflows across departments, and these new AI governance tools plug directly into systems that already handle IT tickets, HR requests, and operational approvals for customers across North America and other global regions.
Finance Ministry and Digital Economy Ministry Set Up 4 National Central Systems to Block Fraudsters' Money in Real Time
The Ministry of Finance has joined hands with the Ministry of Digital Economy and Society to prepare four national central systems to link data on suspicious transactions between agencies, so that all sectors see the same set of risk data, and to speed up the tracing and freezing of money trails before funds are withdrawn, converted into digital assets or gold, or transferred out of the country. Dr. Ekniti Nitithanprapas, Deputy Prime Minister and Minister of Finance, in his capacity as chairman of the subcommittee on linking financial data to enhance the monitoring and investigation of suspicious financial transactions, disclosed together with Mr. Chaichanok Chidchob, Minister of Digital Economy and Society, that the subcommittee approved guidelines to upgrade the prevention and suppression of suspicious transactions in two areas: raising KYC, CDD and EDD standards to be on par with the world's leading financial centres, and drawing up a National Anti-Fraud Master Plan, whose core structure comprises four national central systems. These are the Data Sharing with Consent system, which exchanges risk data under consent; the Anonymous Financial Data Bureau, a centre for anonymous financial transaction data; the Case Management system, a national incident-reporting management system based on the principle of report once, one route; and the Financial Investigation and Account Action system for linking data and freezing money trails. The subcommittee has assigned the Permanent Secretary of the Ministry of Finance, together with relevant agencies, to design the details of the data structure, operating systems, connection guidelines, responsible parties, as well as the rules and data standards for all four systems, to be completed within 30 days before being submitted to the subcommittee for further consideration.
Salesforce Unveils Trusted Enterprise AI Harness for Agent Governance
Salesforce announced its Trusted Enterprise AI Harness on September 10, 2026, formalizing the agent governance stack into a single platform. The Harness comprises six core capabilities: Trusted Context, Trusted Agency, Trusted Action, Trusted Governance, Trusted Security, and Trusted Models, anchored by a new AI Control Plane that lets organizations discover and register agents, establish identity and policy, manage lifecycles, evaluate performance, and control costs. The control plane is designed to manage both Salesforce and third-party AI agents, following the recent Claudeforce initiative that made Anthropic's Claude the default reasoning engine across the platform. Rohan Kumar, Salesforce's President and Chief Platform and Engineering Officer, said the Agentic Enterprise won't be defined by which model a company chooses but by the trusted, proprietary context it brings to that intelligence. The Harness is not scheduled for general availability until early fiscal year 2028, which begins in February 2027, and pricing details have not been disclosed.
Bank of Thailand Joins 11 Financial Associations in Pledge to Curb Gray Capital
The Bank of Thailand, together with financial business operators under its supervision and 11 associations, announced a declaration of intent and a proactive cooperation framework to prevent illicit transactions in the financial sector, known as the Framework for Safeguarding the Financial Sector from Illicit Activities, at a press conference titled "One Intent, United Strength, Protecting Thailand's Financial Sector" on September 10, 2026. Mr. Vitai Ratanakorn, Governor of the Bank of Thailand, said the signing was not merely an MOU or a symbolic gesture, but an agreement with a clear commitment that all parties must genuinely act to raise supervisory standards. The 11 bodies that jointly drafted the cooperation framework are the Thai Bankers' Association, the Association of International Banks, the Government Financial Institutions Association, the Thai E-Payment Association, the Thai Foreign Exchange and Financial Services Association, as well as six associations and clubs of non-bank lenders. They will jointly raise the level of KYC, CDD and EDD, scrutinize high-risk cash transactions, deploy advanced technology to proactively detect abnormal transactions, develop a database of high-risk individuals and connect it to the Central Fraud Registry, produce industry AML/CFT manuals, and use community networks to build financial immunity for vulnerable groups. Mr. Vitai also disclosed that past measures have begun to show concrete results. Requiring that cash withdrawals exceeding 5 million baht undergo screening and verification reduced cash withdrawals in the portion above 5 million baht from about 100 billion baht a month to about 4 billion baht. Meanwhile, supervision of withdrawals and online gold trading above 50 million baht, or gold bars above 2 kilograms, cut such gold withdrawals by about 70 percent. He expects that in October 2026, a measure will take effect requiring those depositing 5 million baht or more in cash to explain the source of funds and provide evidence. At the same time, the Securities and Exchange Commission is in the process of holding a public hearing on regulatory criteria for USDT, with an announcement expected in the next few months. For the next phase, the Bank of Thailand is preparing to upgrade cooperation among five key agencies, namely the Bank of Thailand, the Securities and Exchange Commission, the Anti-Money Laundering Office, the National Anti-Corruption Commission, and the Royal Thai Police, in order to exchange information systematically and across the whole country.
Bank of Thailand Joins Forces with 11 Financial Bodies to Set Joint Framework Against Illicit Transactions
The Bank of Thailand and 11 supervised business associations are jointly driving a cooperative framework to prevent illicit transactions in the financial sector, known as the Framework for Safeguarding the Financial Sector from Illicit Activities, aimed at proactively preventing the financial sector from becoming a channel that supports illegal activity. Mr. Vitai Ratanakorn, Governor of the Bank of Thailand, said the key principle is for all agencies to set direction, policy, and corporate governance to prevent misuse of the financial system, with minimum standards appropriate to each business and continuous improvement of measures as circumstances change. Participating agencies will bring their expertise in data, technology, and capabilities to monitor, detect, and respond to risks, and will exchange information, knowledge, patterns of wrongdoing, warning signals, and best practices among themselves. The businesses that have established this cooperative framework comprise 11 bodies: the Thai Bankers' Association, the Association of International Banks, the Government Financial Institutions Association, the Thai E-Payment Association, the Thai Foreign Exchange and Financial Services Association, as well as six associations and clubs of non-commercial bank business groups. Together they will raise the standard of KYC, CDD, and EDD; scrutinise high-risk cash transactions; deploy advanced technology to proactively detect abnormal transactions; develop a database of high-risk individuals; connect with the Central Fraud Registry; produce industry AML/CFT manuals; and use community networks to build financial immunity for vulnerable groups.
SailPoint raises FY2027 ARR target to $1.38B, outlines FY2029 goals
SailPoint reported fiscal Q2 2027 ARR of $1.231 billion, up 25% year-over-year, and raised its full-year ARR guidance to $1.38 billion while reiterating long-term targets of at least $2.1 billion ARR and at least $800 million in AI-driven ARR by fiscal 2029. The company's AI-driven ARR has already crossed $70 million, and SaaS ARR grew 36% to $847 million, representing 97% of net new ARR. Management highlighted the launch of SailPoint Identity Security with generally available Agentic Fabric, the acquisition of Entro Security, and new connectors for Snowflake, Databricks, and Cursor. CFO Brian Carolan guided Q3 ARR to $1.29 billion, revenue to $328 million, and adjusted EPS of $0.07 to $0.08, while noting that a higher SaaS mix creates a temporary revenue timing headwind of approximately $5 million.
Wolters Kluwer and Hitachi Cyber Partner on GRC Solutions
Wolters Kluwer has announced a collaboration with Hitachi Cyber to deliver integrated governance, risk, and compliance solutions, combining TeamMate Risk & Compliance software with Hitachi Cyber's GRC and privacy services. The partnership aims to help organizations strengthen resilience, improve visibility, and reduce operational burden. Hitachi Cyber will resell TeamMate software and provide professional and managed services. The first joint customer is a global healthcare technology company. The collaboration targets highly regulated industries including financial services, healthcare, government, critical infrastructure, energy, and technology.
SailPoint Integrates Identity Data with CrowdStrike Falcon Next-Gen SIEM
SailPoint, Inc. announced at Fal.Con 2026 an expansion of its partnership with CrowdStrike, integrating SailPoint SecOps Identity Intelligence into CrowdStrike Falcon Next-Gen SIEM to enrich investigations with identity governance and access context. The integration brings SailPoint identity data for human, machine, and AI agent identities into Falcon Next-Gen SIEM, allowing security teams to correlate this data with endpoint, identity, cloud, and other telemetry. This enables analysts to investigate identity-related activity faster and respond to threats without switching between tools. SailPoint SecOps Identity Intelligence is now available on the CrowdStrike Marketplace, and the integration was showcased at SailPoint's booth #1754 at Fal.Con.
Enterprise Software Stocks Rally as Salesforce CEO Declares End of SaaSpocalypse
Enterprise software and cybersecurity stocks rallied sharply on Thursday, driven by strong earnings and a shift in the AI narrative. The iShares Expanded Tech-Software Sector ETF (IGV) surged over 6%, on track for its largest single-day gain since April 9, 2025, when it jumped 11.7%. The rally began after Salesforce and CrowdStrike reported better-than-expected second-quarter results, with Salesforce CEO Marc Benioff declaring, "This nonsense of this SaaSpocalypse, I think it's time for it to stop." ServiceNow surged 9%, Workday rose nearly 4%, and Adobe and Autodesk each climbed 6%. Cybersecurity names led the gains, with CrowdStrike up 18%, Okta rocketing over 25%, and SailPoint surging nearly 14%. Palantir increased 4% as its Maven Smart System is on track to generate at least $1 billion in annual recurring revenue, while UiPath climbed nearly 9% ahead of its earnings report.
SAP Issues Critical Security Patches and Earns Supply Chain Leadership Recognition
SAP issued critical security patches for its Commerce Cloud and Manufacturing Integration and Intelligence solutions, addressing severe vulnerabilities for enterprise users. The company was also named a Leader in the inaugural Gartner Magic Quadrant for Supply Chain Management Suites and recognized as a Leader in the IDC MarketScape for AI-Enabled Order Orchestration and Fulfillment Applications. These developments highlight how quickly AI-driven and cloud-heavy supply chains are evolving, with SAP's €208.3 billion market position placing it at the center of enterprise applications and business solutions. The rapid response to maximum severity issues signals the risk that security gaps pose to SAP's push for deeper customer integration and higher recurring revenue from cloud and AI offerings, while the leadership positions support the narrative that SAP is becoming more embedded in digital and autonomous supply chains.
Department of Land Transport moves to plug data leak loophole, reviews access rights and pursues criminal charges
The Department of Land Transport is rushing to plug loopholes after discovering a leak of vehicle registration data, preparing to review data access rights for government agencies and to pursue criminal charges decisively against those who illicitly use the data. Mr. Sorapong Paitoonpong, Director-General of the Department of Land Transport, revealed that suspicious IP addresses were detected making abnormal data queries from three user accounts: the Bangkok Noi district municipal enforcement unit, the Expressway Authority of Thailand, and the Surasee Task Force. The Ministry of Transport has ordered a temporary suspension of these accounts, coordinated with the Cyber Crime Investigation Bureau to investigate, and required all agencies connected through the e-Service system to reset their passwords. The department collaborated with the National Cyber Security Agency and the Cyber Crime Investigation Bureau to successfully block the unusual access channels within the same day. It confirmed that the leaked data is only basic information and cannot be used for transactions without identity verification, and warned the public not to fall prey to criminals who may use vehicle data to impersonate others.
AutoRABIT Urges Salesforce Teams to Review Six Security Areas After Breach Claims
AutoRABIT issued guidance for organizations to review controls governing Salesforce data access, exposure, monitoring, governance, and recovery, following recent high-profile breach claims including those linked to the ShinyHunters group. The company recommends that Salesforce teams immediately review guest-user access, permissions and least privilege, configuration risk, secure code and custom logic, monitoring and audit visibility, and recovery readiness. AutoRABIT CISO Jason Lord stated that risk lives across access, configuration, custom code, connected apps, release activity, and recovery readiness, and that enterprise leaders need precise security controls to govern that complexity. Deputy CISO Justin Hazard added that teams should actively verify guest access, tighten permissions, review configurations, scan custom code, confirm monitoring, and test recovery readiness now, rather than waiting for a breach.
SailPoint completes acquisition of Entro Security to strengthen non-human identity management
SailPoint has completed its acquisition of Entro Security, a firm specializing in non-human identity and credential security. The deal, announced on June 29, integrates Entro's technology with SailPoint's platform to create a unified control plane for managing the lifecycles and security of all identities, including human, machine, and autonomous AI agents. Entro's capabilities provide granular visibility into developer environments by automatically discovering secrets, tokens, and certificates buried in codebases, CI/CD pipelines, and container registries. The combined solution bridges high-level governance workflows with proactive runtime defense, enabling security teams to monitor token behavior, detect anomalies, and intercept malicious AI activity in real time. The integration is available immediately.
Telos wins Air Force deal for intelligence system support
Telos has received a contract award to support the U.S. Air Force Distributed Common Ground System, the Air Force’s primary intelligence, surveillance, and reconnaissance planning, collection, processing, exploitation, analysis, and dissemination system. Under the contract, Telos will provide perpetual licenses for Xacta.ai, along with support services and maintenance for its Xacta platform, including Xacta 360 and Xacta.io. The award further expands the Air Force's use of Telos' cyber governance, risk, and compliance solutions.
Captain Compliance and Drata Announce Official Partnership
Captain Compliance and Drata have announced an official partnership to help companies build a stronger security and privacy compliance stack. The partnership combines Drata’s agentic trust management and compliance automation platform with Captain Compliance’s privacy compliance software, which handles consent management, cookie compliance, DSAR workflows, privacy policies, vendor disclosures, and continuous website monitoring. Companies can now pair Drata’s automation for frameworks like SOC 2, ISO 27001, and HIPAA with Captain Compliance’s operational privacy tools to address both security and privacy requirements in one integrated approach. The collaboration aims to reduce manual work, strengthen compliance posture, and support faster customer trust reviews for startups, SaaS companies, healthcare, and financial services firms.
Truist Securities Reiterates Buy on SailPoint, Keeps $18 Price Target
Truist Securities reiterated a Buy rating on SailPoint with a price target of $18, implying over 42% upside from current levels. The firm met with management on analyst day, where the company outlined a growth framework centered on agentic identity, real-time governance, and a smoother migration from IdentityIQ to ISC. Truist highlighted SailPoint's broad product portfolio, improving AI pipeline momentum, and multiple paths to reach fiscal 2029 goals, which include at least $2.1 billion in ARR, $800 million in AI-related ARR, and more than 22% adjusted operating margin. Successful execution on migrations and monetizing new AI offerings will be key to watch.