I've spent over 20 years in cybersecurity across endpoint, gateway, malware analysis, PKI and encryption, data protection, PQC, identity, authentication, CIAM, decentralized identity, and more recently, machine identity, or what the market now calls NHI. I came to identity as a cybersecurity person first, and that shapes how I think about everything that follows.
It starts with the threat landscape
When I think about identity security, I always start with the threat landscape. Why? Trust. It would be nice if we could trust everyone (and everything!) online. I mean, why bother with authentication, ITDR, PAM, and so on? Well, it’s because the internet and digital realm come with risks.
Attackers are here to stay, whether they are insiders, outsiders, nation-states, or all three (crazy, right!).
With all of that, it’s critical to know what attackers actually do, and how they do it. What patterns are they exploiting? Today, there are simply too many variables in an attacker's favor. It's no longer a question of whether you're vulnerable; it's whether you're worth the effort to attack.
So where do we start? Not by throwing our hands up. We start with who and what, in other words, identity.
Good cybersecurity posture, strong privacy controls, and effective risk and compliance begin and end with identity. Identity directly correlates to trust, the foundation of digital business. From ransomware and nation-state attacks to complex living-off-the-land techniques, strong identity security can mitigate many of the most damaging attack patterns through visibility, discovery, and enforcement. All of this has to be balanced against productivity, ensuring consumers, citizens, employees, and partners can access what they need, when they need it, without friction.
The goal of cybersecurity
Trust may be the capstone of a cybersecurity program, but it must be balanced with productivity. While productivity is important to any organization, the fast-moving, identity-centric cybersecurity landscape makes it integral. However, all of this is meaningless unless it connects to the business and helps it move forward. Modern infrastructure is digital, and trust must follow suit. Without trust, the applications and interfaces that we depend on every day become unusable. Identity is part of the steel-and-concrete foundation of a digital business, so the rise of identity products within cybersecurity platforms and beyond makes sense. And now that we see many new cybersecurity players entering the identity space, they tend to focus on zero trust. As a firm believer myself, I know the term has its challenges. It’s easy to interpret “zero trust” as “I shouldn’t trust anything”, but that’s far from the intended meaning. In reality, zero trust asks organizations to establish and maintain trust in any entity they conduct business with, whether it's an employee, partner, customer, or non-human agentic identity.
Ultimately, cybersecurity must prioritize building trust and enabling business outcomes over vanity metrics like vulnerability counts or tool-obsessed KPIs. True success is measured by the safety and trustworthiness of interactions across all human and non-human entities, not just by the technology deployed.
One way I like to illustrate this is an example about going to the airport. Do you go to the airport because you enjoy going through security? Of course not. We go to the airport because we're trying to get somewhere (and sadly, Star Trek teleporters aren’t available). Airport security is a necessary part of the flying process that allows us to get where we’re going safely, securely, and with (hopefully) minimal disruption. Identity security should function in the same way. Organizations need a holistic, integrated approach that lets them customize rules and regulations to best fit their needs (kind of like how TSA Pre-Check saves you time). Airports aside, the legacy cybersecurity approach of tacking on another point product to solve another newly discovered problem, while tempting, doesn't scale well across many organizations today. We see this with cybersecurity and CISO burnout. In an era of AI-driven threats, it’s clear that simply throwing more tools and KPIs at the problem is no longer a viable strategy. Instead of getting lost in a mountain of tools or KPIs, we must focus on the true goal of cyber and identity security: enabling digital trust so the business can transact, expand, and take advantage of digital business.
Why now
The market is telling us something. Look at the identity acquisitions over the past year, especially in machine identity. This isn't new to me; during my time at Gartner, my colleague Erik Wahlstrom and I did early research on PKI and certificate management. We saw where things were heading as digital transformation accelerated: more automation, more bots, more RPA, and clients asking for better identity controls. This led Erik and me to define the machine identity management market, otherwise known as “NHI”. As such, none of us were surprised by the agentic AI movement. The pace, in some respects, has surprised even those of us who called it early, but the underlying principle hasn't changed. Agentic AI is the forcing function accelerating identity security's evolution.
Here's the interesting part. Every major identity platform in the market today was built for productivity, not security. Gartner's own definition of IAM says it plainly: giving the right access, for the right reasons, at the right times, to enable the right business outcomes. That definition shaped the entire industry: IGA, PAM, access management, ITDR, and machine identity. An entire ecosystem has been built around the joiner, mover, leaver framework.
That framework is necessary. But it's no longer sufficient.
What's missing is the adversary. Identity has to answer not just "who should have access," but "who is behaving like a threat right now"; whether that's an external actor, a compromised account, or an insider. A threat is a threat, regardless of source, and identity is a fundamental control to catch it. Many vendors have transitioned to calling themselves "identity security" companies. But you don't earn that label with a rebrand; you earn it through investment in technology, people, process, and a genuine security vision, put into practice.
What about cybersecurity platforms entering the identity game via multi-billion-dollar acquisitions? This is hardly surprising. As I’ve noted, the threat landscape dictates that identity is at the center of modern attacks. For the past decade, I’ve argued in countless presentations that many security platforms — endpoint, data protection, and beyond — lack critical insight into identity, often leaving organizations vulnerable to breaches. In fact, one of my final research notes at Gartner leaned into being provocative, as they then pointed out that “ransomware is not a Malware issue; it is a Data Access issue,” underscoring that access is fundamentally a function of identity alongside the deep connection and interdependence of identity and data.
Overall, I applaud these cyber platforms for investing in identity security; it truly takes a village to secure the world. However, while many organizations will benefit from this approach, identity is a different game.
As mentioned above, Gartner’s definition of IAM focuses on productivity: ensuring users and machines have the right access at the right times to drive business outcomes. While cybersecurity is certainly intertwined, effective identity management must balance that security with business enablement. A key challenge for cybersecurity-focused vendors is connecting their solutions to broader business value. Identity has always been directly tied to enablement — from passwordless authentication and FIDO to IGA, JIT, and SSO. These innovations were born in the identity world, and while they require a balance with cybersecurity, the focus on driving business value, risk management, and compliance is the native language of successful organizations that view identity as a strategic enabler of digital trust and business.
I've seen this evolution before
In my previous role as Chief Identity Officer (CIO) and Head of Identity and Cybersecurity Convergence, I had the privilege of guiding a company through this exact type of transition — defining a critical frontier in identity and access management. Specifically, on customer identity management (CIAM) and the convergence of identity verification, authentication, orchestration, and other often siloed functions manifesting as stand-alone products.
By having an intimate understanding of the evolving threat landscape, product/market gaps, and shifting client needs, it was clear that the legacy approach to CIAM was ill-suited for the mobile, cloud, and increasingly AI-enabled world.
While long-standing legacy players existed in the market, the vision and roadmap became clear to me. In order to disrupt the market and push the evolution forward, we started with analysts. The first step was to ensure the criteria and market direction aligned with our vision and were backed by evidence. So we set a goal: achieve leadership positions with top industry influencers and analysts.
To achieve our goal of attaining leadership positions across the KuppingerCole Leadership Compass, Forrester CIAM Wave, and Gartner Magic Quadrant for Access Management, I knew a superficial rebrand wouldn't be enough. Moving from a participant in the conversation to a recognized leader required years of dedicated work: understanding real customer needs, identifying market gaps, and building our case to prospects, clients, and analysts with hard evidence rather than mere arguments.
The evolution was necessitated by a fundamental shift: Customer identity had long been treated as a forked use case of core access management rather than a standalone discipline. Forcing factors like mobile adoption, cloud migration, and GDPR made it clear that data storage, privacy, and identity had to be treated as first-class, purpose-built problems. Large IAM vendors suffering multiple serious outages proved that point and influenced regulatory shifts like EU DORA, introducing hard requirements for cyber-resilience. Together, these factors acted as a natural forcing function, pushing CIAM offerings beyond the limitations of 20-year-old architectures.
Working alongside an incredible team to shape our vision, roadmap, and strategy ultimately led to recognition in three KuppingerCole Leadership Compasses, a Leader position in the Forrester CIAM Wave, and a first-time debut in the Gartner Magic Quadrant for Access Management — ahead of companies many times our size (both in people, resources, and revenue). That experience is exactly why I recognize this same pattern forming once again, this time within the broader holistic identity security category, and specifically in machine and agentic identity.
Why Saviynt
A long-term view of where the market is headed, rooted firmly in what clients need today, is ultimately what drew me here. Over the years, I've had the privilege of unique vantage points as an analyst, and through close relationships across investors, practitioners, CISOs, CIOs, and founders building genuinely interesting approaches to hard problems. From that perspective, Saviynt stood out. It’s consistent, results-driven, and builds from the right vision. The recent numbers supported that trend, and this is just the beginning.
It starts with the leaders, Sachin, and extends through people I've long respected — Paul Z., Henrique T., David L., Jim R., and others. Many of whom I've watched move to Saviynt and took note of exactly why. Culture eats strategy for breakfast, and the team Saviynt has built told me everything I needed to know about whether this is the right company, at the right time.
The market is evolving, and as a former analyst who loves conducting AI-driven Monte Carlo simulations, my bet is on Saviynt becoming a global powerhouse in identity security and digital trust.
What I'll be doing
I'll be joining Saviynt's leadership team in strategy, but also getting out and doing another thing I love, and that’s advising prospects, clients, partners, and analysts as a function of a Field CISO. Coverage-wise, I’ll initially focus on agentic AI and machine identity within the broader identity security landscape, and work closely with our product leaders, analysts, industry influencers, clients, CISOs, IAM leaders, and practitioners. I won't be a stranger to most of you. I'll be at the same events, on the same stages, in the same rooms where we've always crossed paths.
That includes my friends across the analyst community; you remain a critical part of how this market gets shaped, defined, and built. Working together to help the market and its practitioners reach true maturity, and unlocking the benefits we've talked about for years: automation, new digital channels, genuine transformation for both human and machine identity.
It takes a village, inside Saviynt, and across the customers, partners, and analysts who shape this space from the outside.
I'm excited for what's ahead. The problems are real, the team is strong, and I'm ready to get to work.
A note from Henrique Teixeira
We are thrilled to welcome David Mahdi to Saviynt as our new VP of Cybersecurity Strategy and Field CISO.
Since I joined Saviynt two and a half years ago, strategy has been fundamental to driving our transformation and growth. From building toward a $3B valuation and $300M ARR and launching Zuma, to entering and leading emerging markets like NHI and agentic AI. That kind of momentum doesn't happen by accident.
David is exactly the person we need to carry this to the next level. He co-authored the machine identity market itself. Not as an observer, but as an architect of how the industry came to understand and define it. He has the most impressive pulse on where this industry is today and where it's heading. And he brings a rare combination of analytical rigor, practitioner empathy, and genuine security vision that is hard to find.
I am proud to have him here. David is the leader Saviynt needs to take on the challenges our clients face and help design our solutions strategy for the AI era.
Welcome, David. Let's get to work.
Henrique Teixeira
SVP, Strategy

.png)