By NHI Mgmt Group Editorial TeamBased on SSH Communications Security: “SSH Communications Security announces intention to enter into strategic partnership with Leonardo, backed by an EUR 20 million share issue to Leonardo” (June 30, 2025)

TL;DR: Identity, access, and defence security are converging into a more platform-like market structure, with SSH Communications Security saying its proposed partnership with Leonardo includes a EUR 20 million share issue, a 24.55% ownership stake, and market rights tied to zero trust privileged access management and quantum-safe encryption.


At a glance

What this is: This is a strategic partnership announcement in which SSH Communications Security plans a share issue and market rights arrangement with Leonardo, with privileged access and quantum-safe encryption as the operational focus.

Why it matters: It matters because defence and government access governance increasingly depends on who controls privileged pathways, distribution rights, and assurance boundaries across human, system, and network identities.

By the numbers:

  • The Leonardo Share Issue would give Leonardo an ownership stake of 24.55% in SSH.
  • The subscription price represents a 49.6% premium over the five-day volume-weighted average share price.

Context

SSH Communications Security’s planned partnership with Leonardo is a corporate and governance event, not a technical product launch. The article ties together a directed share issue, shareholder rights, and market access in areas where privileged access management and quantum-safe encryption are positioned for defence and government use.

For identity practitioners, the practical question is how commercial control, distribution rights, and access governance interact when security tooling is embedded in regulated sectors. This is especially relevant where privileged access is part of a wider trust boundary spanning operators, systems, and high-value environments.

The announcement is typical of a market where identity control is no longer just an internal security discipline. It is becoming part of strategic alignment, route-to-market control, and sector-specific assurance, which changes how access governance should be evaluated at programme level.


Key questions

Q: How should teams handle privileged access governance when ownership or market rights change?

A: Treat the change as a governance event, not only a commercial one. Recheck third-party assurance, administrative accountability, and escalation paths where privileged access capabilities depend on partner relationships, exclusive rights, or shifting ownership. The key question is whether the operating model still gives security and compliance teams the same control over lifecycle, auditability, and support commitments.

Q: How should procurement teams evaluate access security tools in defence and government environments?

A: They should evaluate jurisdictional assurance, audit evidence, support continuity, and exit flexibility alongside core access controls. In these environments, the commercial model can affect operational trust as much as the technology. That is why governance criteria need to include ownership structure and ecosystem dependence.

Q: What are the warning signs that a privileged access programme is drifting into vendor dependency?

A: Look for control decisions that increasingly depend on reseller rights, exclusive market terms, or partner ownership rather than your own governance model. If security, legal, and procurement teams cannot clearly explain who can change support, deployment, or access conditions, the programme has moved beyond pure technology evaluation and into dependency management.

Q: Should organisations evaluate quantum-safe encryption and privileged access together?

A: Yes, when both are part of the same trust boundary. Quantum-safe encryption protects the durability of communications and stored trust, while privileged access management governs who can use elevated paths today. If they are managed separately, organisations can miss dependencies between session control, key protection, and long-term assurance.


Technical breakdown

Why privileged access becomes a governance issue in strategic partnerships

Privileged access management is not only about controlling administrator sessions. In strategic partnerships, it also becomes a governance layer that determines who can distribute, influence, or operationalise access pathways in sensitive environments. When a vendor positions zero trust privileged access management for defence and government markets, the control surface expands from technical entitlements to commercial and organisational authority. That matters because access decisions, product positioning, and sector permissions can reinforce each other. Practitioners should read such partnerships as signals about where control of elevated access is moving in the market.

Practical implication: review whether your privileged access model separates technical control from commercial and channel influence.

How market rights can reshape identity governance expectations

Rights of first offer and first refusal are not identity controls, but they matter because they shape who can steer future ownership and, by extension, control the operating context for sensitive security capabilities. When a security vendor’s access-control proposition is paired with exclusivity in defence and government sectors, governance questions shift from feature evaluation to dependency management. The issue is not simply whether the tool works. The issue is whether concentration of ownership, distribution rights, and sector access creates new assurance assumptions that procurement, compliance, and architecture teams need to account for.

Practical implication: assess whether ownership and market-rights changes alter your third-party assurance assumptions.

Quantum-safe encryption and privileged access are converging operational concerns

Quantum-safe encryption and privileged access management sit in different layers, but the article links them because both are about protecting high-value trust paths. Privileged access governs who can reach critical systems today, while quantum-safe encryption addresses the durability of protection over time. In defence and government settings, those controls increasingly travel together because one protects the session boundary and the other protects the communication boundary. That combination points to a broader programme shift: organisations are buying trust continuity, not just access control features.

Practical implication: align privileged access and cryptographic roadmaps instead of treating them as separate programmes.


NHI Mgmt Group analysis

Privileged access governance is becoming a market structure issue, not just a control issue. When a security vendor’s defence-sector partnership is coupled with ownership change and market rights, access governance extends beyond policy and tooling. The control question becomes who can shape privileged pathways across the commercial chain, not only who can administer them. For practitioners, that means third-party governance must include route-to-market and ownership concentration.

Defence and government use cases raise the assurance bar for access-control programmes. These sectors do not evaluate privileged access in isolation from sovereignty, lifecycle control, and trust boundary management. A partnership that positions zero trust privileged access management for those markets signals that identity governance is being pulled into procurement, legal, and operating model decisions. Practitioners should treat that as a sign that governance scopes are widening.

Named concept: privileged access dependency drift. This is the gradual shift from evaluating privileged access as a standalone technical capability to depending on a broader ecosystem of ownership, distribution, and sector rights. The article illustrates that drift by tying product positioning to shareholder structure and exclusive market arrangements. Practitioners should recognise that access assurance can be weakened by business dependencies even when the technical control set looks unchanged.

Quantum-safe encryption does not replace privileged access governance, it raises the standard for it. The article pairs the two because long-lived trust in sensitive environments depends on both access discipline and cryptographic resilience. That combination matters most where operators, systems, and communications all sit inside the same assurance boundary. For practitioners, the implication is to evaluate whether their current programme treats these as separate workstreams when the market is already linking them.

Platform-style consolidation is changing what identity security buyers must scrutinise. The more identity and defence capabilities move into strategic partnerships and ownership structures, the more buyers need to ask who governs lifecycle, rights, and accountability across the ecosystem. This does not reduce the importance of the control. It increases the importance of the operating model around it. Practitioners should scrutinise governance conditions as closely as product claims.

What this signals

Privileged access dependency drift: The article is a reminder that access governance can start to depend on ownership, channel rights, and sector positioning rather than only on technical policy. That matters because third-party changes can alter the assurance boundary even when controls appear unchanged.

Defence and government programmes should expect more scrutiny of who can shape privileged access pathways, support commitments, and deployment rights. The governance question is no longer only whether elevated access is protected, but whether the surrounding commercial structure preserves accountability across its lifecycle.


For practitioners

  • Review third-party privileged access dependencies Map where privileged access capabilities depend on partner rights, distribution arrangements, or ownership changes that could affect operational continuity or assurance boundaries.
  • Separate technical control from commercial control Document which parts of your privileged access programme are owned by security architecture versus procurement, legal, and vendor management functions.
  • Reassess defence-sector assurance assumptions Check whether any privileged access tooling used in regulated or sensitive environments requires additional review because sector access, resale, or exclusivity terms have changed.
  • Align encryption and access roadmaps Coordinate quantum-safe encryption planning with privileged access lifecycle decisions so the trust boundary is reviewed as one programme rather than two disconnected tracks.

Key takeaways

  • This partnership announcement shows that privileged access governance is being shaped by ownership, distribution rights, and sector access, not only by technical controls.
  • The article states that SSH would raise approximately EUR 20 million and that Leonardo would hold a 24.55% stake if the share issue completes.
  • Practitioners should reassess third-party assurance, accountability, and programme dependencies when privileged access tooling becomes part of broader strategic alignment.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIPrivileged access governance is the central theme of the partnership announcement.
NHI-03 — Vulnerable Third-Party NHIThe article centres on partner rights and market access in a third-party relationship.
Recommendation — Review elevated access paths against NHI-05 and reduce unnecessary privilege in sensitive environments. Assess partner-controlled access arrangements under NHI-03 before expanding deployment or resale scope.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe announcement is about how access permissions and authorizations are governed across organisations.
Recommendation — Align privileged access governance with PR.AA-05 so entitlements remain explicit and reviewable.
NIST Zero Trust (SP 800-207)Least privilege — Least privilegeZero trust privileged access management is explicitly part of the partnership positioning.
Recommendation — Apply least-privilege architecture to privileged sessions and partner-operated access paths.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeThe topic is elevated access control and entitlement discipline in sensitive environments.
Recommendation — Use AC-6 to constrain administrative access and separate duties across privileged workflows.

Key terms

  • Dynamic Privileged Access Governance: Dynamic privileged access governance is the practice of applying access controls that adapt to changing cloud conditions, user context, and task requirements. It replaces static, long-lived entitlements with policies that can issue, monitor, and revoke privilege in a way that better matches the pace of cloud operations.
  • Third-party access dependence: Third-party access dependence is the operational reliance on external vendors, contractors, partners, or service providers to perform business functions or access systems and data. It creates identity risk because access is often granted outside direct employee controls, requiring strong governance, least privilege, monitoring, and periodic review of accounts, credentials, and permissions.
  • Quantum-safe encryption: Quantum-safe encryption refers to cryptographic methods designed to remain resistant to future quantum attacks. It protects data confidentiality, but it does not manage who can access systems, elevate privilege, or operate administrative functions, so it must be governed alongside identity and access controls.
  • Ownership Concentration: A condition where one human account owns many AI identities or related non-human accounts. This concentrates risk because compromising that one account can expose every agent it controls, turning a single identity failure into a wider enterprise incident.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 8, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org