Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

SSH and Leonardo partnership: what it means for privileged access governance


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 3218
Topic starter  

TL;DR: Identity, access, and defence security are converging into a more platform-like market structure, with SSH Communications Security saying its proposed partnership with Leonardo includes a EUR 20 million share issue, a 24.55% ownership stake, and market rights tied to zero trust privileged access management and quantum-safe encryption.

NHIMG editorial — based on content published by SSH Communications Security: its proposed strategic partnership with Leonardo and related share issue announcement

By the numbers:

  • Leonardo would hold 24.55% of SSH after completion of the share issue.

Questions worth separating out

Q: What does the SSH and Leonardo partnership mean for privileged access governance?

A: It shows that privileged access management is increasingly being shaped by capital, channel strategy, and regulated-sector distribution, not just by technical features.

Q: Should security teams care when an identity vendor forms a strategic partnership with a larger industrial company?

A: Yes, because the governance risk is no longer limited to product capability.

Q: Why does quantum-safe encryption not replace privileged access management?

A: Quantum-safe encryption protects data against future cryptographic risk, but it does not control who can obtain elevated access or how administrative sessions are governed.

Practitioner guidance

  • Reassess vendor concentration risk Review whether your PAM or access governance roadmap depends on a supplier whose market strategy is now tied to strategic ownership and sector-specific exclusivity.
  • Separate cryptographic and identity governance workstreams Keep quantum-safe migration planning distinct from privileged access review, credential lifecycle management, and session control.
  • Validate sovereignty and procurement constraints early For regulated or public-sector deployments, confirm where hosting, support, and administrative control will sit after any partnership changes.

What's in the full analysis

SSH Communications Security's full announcement covers the transactional and commercial detail this post intentionally leaves at the strategic level:

  • Terms of the directed share issue, including the subscription price, share count, and ownership impact.
  • Board conditions, approval requirements, and foreign acquisition clearance considerations.
  • The ROFO and ROFR arrangement with Accendo Capital and Mr. Tatu Ylönen.
  • The stated market access structure for defence and government sectors.

👉 Read SSH Communications Security's announcement on the Leonardo partnership and share issue →

SSH and Leonardo partnership: what it means for privileged access governance?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 weeks ago
Posts: 1804
 

Strategic security partnerships are becoming a distribution model for identity tooling. This transaction is not just about capital injection. It shows how access governance vendors are increasingly being positioned inside broader defence and security ecosystems, where market reach, channel access, and procurement alignment matter as much as product capability. For practitioners, that means supplier evaluation now has to include ownership structure and downstream market dependence, not only control coverage.

A few things that frame the scale:

  • Only 5.7% of organisations have full visibility into their service accounts, according to the Ultimate Guide to NHIs.
  • Another finding from our research shows that 97% of NHIs carry excessive privileges, which broadens the attack surface and makes governance drift harder to detect.

A question worth separating out:

Q: How should procurement teams evaluate access security tools in defence and government environments?

A: They should evaluate jurisdictional assurance, audit evidence, support continuity, and exit flexibility alongside core access controls. In these environments, the commercial model can affect operational trust as much as the technology. That is why governance criteria need to include ownership structure and ecosystem dependence.

👉 Read our full editorial: SSH and Leonardo partnership signals pressure on privileged access governance



   
ReplyQuote
Share: