Making sense of cybersecurity's converging categories

AI is eliminating the dividing lines that once delineated technologies such as vulnerability management and network security. Enterprises have to find a new way to evaluate vendors.

Black Hat 2026 is fading into our rearview mirrors, but hanging out with 23,000 of my fellow cybersecurity enthusiasts has revealed that as organizations drive forward with AI adoption, formerly distinct security categories are beginning to converge.

To help security teams support AI initiatives while optimizing efficiency with a leaner cybersecurity technology stack, here's how I'm seeing this convergence play out.

AI and AI agent noise

We're in the Wild West stage of how cybersecurity is adapting to AI. Security vendors are flooding the market with AI noise that makes it difficult to understand what their products can do. Practically every booth and session at Black Hat had an element of AI security, but the overall messaging made it difficult to figure out what a vendor provides. A vendor's booth sign might claim it "counters AI-driven threats," but understanding what that supplier actually did required a time-consuming conversation.

While episodes like OpenAI AI agents targeting Hugging Face and Anthropic agents going rogue have raised the awareness of threats posed by AI agents, enterprises are still trying to determine how to best defend the expanded attack surface these threats create. Research from Omdia, a division of Informa TechTarget, found that enterprises are most concerned with AI-driven security vulnerabilities and data privacy when it comes to AI agents, but many are inhibited by uncertainty around what form the threats will take. Practitioners can consider frameworks such as the OWASP Top 10 for AI Agents, but the specific techniques and attack paths adversaries will use to exploit potential vulnerabilities are still emerging.

Discrete technology categories are overlapping

Security practitioners consider discrete categories of technology when purchasing tools, often tied to their budgets and funding. These distinct domains span network security; vulnerability management; data security; data protection, including backup and recovery; security operations; identity security and identity and access management (IAM); cloud security; and endpoint security.

But these categories are now converging and overlapping.

Some examples: As an analyst, I cover identity security, data protection and data security. Enterprises need identity resilience to ensure their industry infrastructure -- Active Directory and cloud identity providers -- can recover from ransomware, misconfigurations, accidental changes and cyberattacks. A number of pure-play firms, such as Semperis, Cayosoft and Quest Software, have dominated identity resilience; however data protection platforms, including Cohesity, Commvault, Druva and Rubrik, are adding identity resilience into their data protection platform offerings. While the pure-plays have developed strong functionality for identity resilience, the data protection players entering this space have a "good enough" approach that is quickly improving.

Expect to see more activity in terms of acquisition and organic innovation in the identity resilience space as data protection technologies augment vendors' identity resilience functionality. I plan to study this dynamic further in Omdia research scheduled for publication later this year.

Identity security vendors are also being impacted by AI, and identity players are adding what was once considered data protection functionality to their offerings. AI agents need identity lifecycle management, including AI agent visibility, fine-grained access control, governance and lifecycle management. Enterprises, however, also need to put AI guardrails in place, something that has previously been out of scope for IAM players.

Identity vendors are starting to layer guardrail functionality as customers insist on broader capabilities to solve their challenges. For example, identity security vendor C1 provides identity management and governance for AI agents, but it also provides guardrails to protect against prompt injection attacks, something that previously was considered an AI security rather than an identity security feature.

For enterprises, this technology convergence can result in a more streamlined enterprise technology stack where it makes sense. It could also result in the addition of new best-of-breed tools from nimble innovators that can deliver functionally strong products more quickly.

Expect questions and confusion as enterprises grapple with a crowded marketplace and determine which vendor does what and at what depth before they decide whether best-of-breed or a converged platform is the optimal approach to a given problem.

The optimal stack is still working itself out

The noise is intense right now. Threats posed by AI and AI agents are a major topic of discussion and the vendor community would like your attention. As the scope of these threats become clearer and effective defensive options emerge, the noise will gradually subside and the signal will become clearer.

There is a considerable amount of experimentation going on as enterprises put different vendors through the paces. I do not expect that this will be a winner-takes-all dynamic with broad platforms being the predominate approach. Prior identity security research conducted by Omdia has shown that enterprises frequently have multiple choices in each technology area. Rather than rely on a single vendor or product across their entire environment, organizations frequently deploy multiple products to solve a given problem.

Instead of mounting promotional campaigns that broadly state, "We provide security for AI," security vendors must articulate which layer of the AI security stack they address. It's early days in AI infrastructure cybersecurity and its evolution will take time. I expect next year's Black Hat to show more technological nuance and provide a clearer articulation of value so attendees can better grasp what various offerings provide.

Buckle up and prepare for accelerating change as the world adapts to AI and AI agents that both turbocharge threats as well as boost defenders' capabilities to counter those threats. It is an amazing time to work in cybersecurity; the dynamism can make your head spin. If you are a technology player with a new approach to identity security, data security or data protection, I would like to hear about it. You can reach me on LinkedIn.

Todd Thiemann is a senior analyst covering identity access management and data security for Omdia. He has more than 20 years of experience in cybersecurity marketing and strategy.

Omdia is a division of Informa TechTarget. Its analysts have business relationships with technology vendors.

Dig Deeper on Security Operations & Management