TL;DR: Identity, access, and defence security are converging into a more platform-like market structure, with SSH Communications Security saying its proposed partnership with Leonardo includes a EUR 20 million share issue, a 24.55% ownership stake, and market rights tied to zero trust privileged access management and quantum-safe encryption.
Editorial analysis by NHI Mgmt Group, based on content published by SSH Communications Security: “SSH Communications Security announces intention to enter into strategic partnership with Leonardo, backed by an EUR 20 million share issue to Leonardo”.
By the numbers:
- The Leonardo Share Issue would give Leonardo an ownership stake of 24.55% in SSH.
- The subscription price represents a 49.6% premium over the five-day volume-weighted average share price.
Key questions
Q: How should teams handle privileged access governance when ownership or market rights change?
A: Treat the change as a governance event, not only a commercial one.
Q: How should procurement teams evaluate access security tools in defence and government environments?
A: They should evaluate jurisdictional assurance, audit evidence, support continuity, and exit flexibility alongside core access controls.
Q: What are the warning signs that a privileged access programme is drifting into vendor dependency?
A: Look for control decisions that increasingly depend on reseller rights, exclusive market terms, or partner ownership rather than your own governance model.
Practitioner guidance
- Review third-party privileged access dependencies Map where privileged access capabilities depend on partner rights, distribution arrangements, or ownership changes that could affect operational continuity or assurance boundaries.
- Separate technical control from commercial control Document which parts of your privileged access programme are owned by security architecture versus procurement, legal, and vendor management functions.
- Reassess defence-sector assurance assumptions Check whether any privileged access tooling used in regulated or sensitive environments requires additional review because sector access, resale, or exclusivity terms have changed.
Bottom line: This partnership announcement shows that privileged access governance is being shaped by ownership, distribution rights, and sector access, not only by technical controls.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Privileged access governance is becoming a market structure issue, not just a control issue. When a security vendor’s defence-sector partnership is coupled with ownership change and market rights, access governance extends beyond policy and tooling. The control question becomes who can shape privileged pathways across the commercial chain, not only who can administer them. For practitioners, that means third-party governance must include route-to-market and ownership concentration.
A question worth separating out:
Q: Should organisations evaluate quantum-safe encryption and privileged access together?
A: Yes, when both are part of the same trust boundary. Quantum-safe encryption protects the durability of communications and stored trust, while privileged access management governs who can use elevated paths today. If they are managed separately, organisations can miss dependencies between session control, key protection, and long-term assurance.
👉 Read our full editorial: SSH and Leonardo partnership signals pressure on privileged access governance