
Work Here?
BeyondTrust provides cybersecurity software for organizations. Its products include Privileged Access Management (PAM), which controls and monitors access to critical systems; Vulnerability Management, which finds and helps remediate security weaknesses; and Endpoint Protection, which secures devices from threats. The offerings are delivered as software and managed services, and the company works with large enterprises, government agencies, and partners to provide an integrated security platform. Its goal is to reduce cyber risk by preventing unauthorized access, detecting and fixing weaknesses, and protecting endpoints for safer IT operations.
Industries
Enterprise Software
Cybersecurity
Company Size
1,001-5,000
Company Stage
Acquired
Total Funding
$12.1M
Headquarters
Johns Creek, Georgia
Founded
1985
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Total Funding
$12.1M
Below
Industry Average
Funded Over
4 Rounds
Flexible Work Hours
Hybrid Work Options
BeyondTrust has unveiled the first native capabilities of its Pathfinder platform at Black Hat USA 2026. The platform extends privilege management beyond traditional human administrators to all identities capable of exercising privileged access, including AI agents and workloads. The initial wave includes PathfinderAI & MCP Server, AI Agent Security, NHI Governance, and Workload Credentials. These tools help organisations discover, prioritise, govern, and protect privileged access across human and non-human identities. Research from BeyondTrust Phantom Labs found enterprise AI agents grew more than 460% year over year. The company noted that attackers increasingly abuse trusted identity relationships to move laterally and access sensitive data. "We are the company that has long defined how to secure privileged action," said Marc Maiffret, chief technology officer at BeyondTrust.
BeyondTrust Introduces NHI Governance for AI and Non-Human Identities. On: July 22, 2026 BeyondTrust has announced NHI Governance, a new solution on the BeyondTrust Pathfinder platform that governs non-human identities operating across cloud, SaaS, endpoints, and on-premises environments. As service accounts, API keys, OAuth clients, workload identities, and AI agents continue to proliferate across enterprise environments, NHI Governance extends the privileged access discipline BeyondTrust has applied to human access for more than two decades to the identities that now outnumber employees in nearly every organization and remain largely ungoverned. The Problem: The Privileged Surface Changed. Controls Didn't Keep Up. Service accounts, API keys, OAuth clients, workload identities, and AI agents now hold most of the standing privilege in the enterprise, and they outnumber the people. BeyondTrust Phantom Labs research found that non-human identities already vastly outnumber human ones, with enterprise AI agents growing more than 460% year over year. Almost none are ever assigned an owner; their privileges are rarely reviewed, attested, or rightsized; and their credentials are seldom rotated or retired. They are granted access on the day they are created and often retain that access indefinitely. The industry's response has been to inventory them. But a longer list is not a control. The risk was never just that an identity exists; it is also, and especially, the privilege that identity holds and everything that privilege can reach. The recent wave of SaaS-to-SaaS software supply chain attacks made that abundantly clear. Attackers increasingly compromise the OAuth tokens trusted between applications, allowing legitimate access to data at scale. No malware, no escalation, no human in the loop. Every action reads as authorized because it was. Discovery and visibility alone do not stop an attack. Stopping the exfiltration requires controls to be executed ahead of the incident: access already scoped down, the token already rotated, or the unused identity already retired before the attacker arrived. "Seeing non-human identities was only half the equation," said Marc Maiffret, Chief Technology Officer, BeyondTrust. "The other half is doing something about the privilege they carry at scale: deciding who owns each one, pulling back the privilege they aren't using, and retiring the ones that should not exist. And doing so without requiring teams to address them one by one with the limited time they have. That's not paperwork you bolt onto a tool built for employee onboarding. That's managing non-human identities at machine scale." Helping Customers Move from an Inventory List to Real Control NHI Governance is built to execute the non-human equivalent of joiner, mover, leaver actions that actually reduce risk, in the right order: * Establish ownership. Every non-human identity is assigned to a person or a team who is accountable for it, so nothing runs unowned. * Enforce least privilege. Lock down the identities that hold real privilege, and constrain what each one can reach, closing the paths to privilege it was never meant to have. * Decommission NHIs. Retire the stale, orphaned, and abandoned identities that make up most of the ungoverned population, so the attack surface shrinks instead of growing unchecked. * Secure AI Agents. Bring them under the same controls, with their own credentials and their own access. Built on Two Decades of Privilege Enforcement For more than two decades, BeyondTrust has helped organizations reduce identity-based risk by governing privileged access across their most critical systems. Non-human identities are no exception. Identity Security Insights already provides industry-leading visibility and intelligence across non-human identities and the privileges they hold, while BeyondTrust Password Safe secures, manages, and rotates the credentials behind them. NHI Governance builds on that foundation by turning visibility and credential management into lifecycle governance that establishes ownership, enforces least privilege, and reduces identity-based risk. Part of the BeyondTrust Pathfinder platform, NHI Governance builds on the recent introduction of AI Agent Security, further unifying discovery, governance, and enforcement within a single platform to secure privilege consistently across every identity capable of privileged action. 2026-07-22
Top Privileged Access Management solutions named Champions in Info-Tech Research Group's 2026 Data Quadrant Report. Jul 10, 2026, 13:06 ET The 2026 Privileged Access Management Data Quadrant Report from Info-Tech Research Group, powered by SoftwareReviews, recognizes Segura, Devolutions PAM, BeyondTrust Platform, and WALLIX PAM as Champions. Based on verified end-user feedback, the report highlights solutions that help organizations strengthen identity security, improve privileged access visibility, and reduce the risk of unauthorized access. ARLINGTON, Va., July 10, 2026 /PRNewswire/ - As identity-related threats, hybrid environments, and expanding third-party access heighten enterprise risk, organizations are increasingly investing in privileged access management (PAM) solutions to protect critical assets, secure privileged identities, and strengthen access governance. Info-Tech Research Group's 2026 Privileged Access Management Data Quadrant Report highlights the leading PAM vendors as Champions based on verified end-user insights gathered through the firm's SoftwareReviews platform. PAM solutions help organizations secure, manage, and monitor privileged accounts and credentials across the enterprise. Capabilities such as credential vaulting, least-privilege enforcement, privileged session management, just-in-time access, password rotation, and centralized auditing help security teams reduce identity-related risks while improving visibility, compliance, and operational control. Info-Tech's Data Quadrant is a comprehensive software evaluation tool that ranks products based on verified user feedback across key dimensions, including likelihood to recommend, feature rankings, net emotional footprint score, and vendor capabilities. These dimensions are aggregated into a Composite Score (CS), which reflects overall user satisfaction and determines placement within the Data Quadrant. The firm's methodology ensures that rankings are based entirely on authentic user reviews, free from analyst opinions or vendor influence. * Segura, 9.1 CS, recognized for its Just-in-Time (JIT) Access capabilities. * Devolutions PAM, 8.4 CS, highly rated for its agentless deployment capabilities. * BeyondTrust Identity Security Privileged Access Portfolio, 8.3 CS, earned high marks for business value created. * WALLIX PAM, 8.2 CS, recognized for privileged password management. "Effective privileged access management solutions give organizations greater control over privileged accounts and help security teams safeguard critical systems, enable just-in-time and just-enough access, and reduce the risk of unauthorized activity," says Carlos Rivera, principal advisory director at Info-Tech Research Group. "As identity-related threats continue to evolve, organizations are prioritizing platforms that combine credential management, visibility, and streamlined access controls to strengthen overall cybersecurity resilience." User assessments of software categories on SoftwareReviews provide an accurate and detailed view of the constantly changing market. Info-Tech's reports are informed by data from users and IT professionals with intimate experience with the software across the procurement, implementation, and maintenance processes. To learn more about Info-Tech's Vendor Awards, including how Data Quadrant and Emotional Footprint recognition are determined using verified end-user feedback and the underlying evaluation criteria, visit Info-Tech's Vendor Awards page, powered by SoftwareReviews. About Info-Tech Research Group Info-Tech Research Group is the "get things done" partner for over 30,000 IT, HR, and marketing leaders worldwide. The fastest growing research and advisory firm, Info-Tech enables leaders to make well-informed decisions and transform their organizations through AI, strategic foresight, step-by-step methodologies, practical tools, industry-leading advisory, and training programs. For nearly 30 years, tens of thousands of private and public organizations have trusted Info-Tech to lead their most important initiatives through periods of change and deliver outcomes that truly matter. To learn more about Info-Tech's HR research and advisory services, visit McLean & Company, and for data-driven software buying insights and vendor evaluations, visit the firm's SoftwareReviews platform. Media professionals can register for unrestricted access to research across IT, HR, and software, as well as hundreds of industry analysts through the firm's Media Insiders program. To gain access, contact [email protected]. For information about Info-Tech Research Group or to access the latest research, visit infotech.com and connect via LinkedIn and X. SOURCE Info-Tech Research Group
BeyondTrust extends privileged access leadership with release of NHI Governance for every non-human and AI identity. * BeyondTrust launches Pathfinder NHI Governance, extending privileged access control to the non-human and AI identities that run modern environments * New Pathfinder module enables organisations to establish ownership, enforce least privilege, govern AI agents, and reduce risk across service accounts, API keys, workload identities, OAuth clients, and other non-human identities * Built on more than two decades of privilege control expertise, NHI Governance shifts organisations from simply discovering non-human identities to actively governing the privilege they hold BeyondTrust, the global leader in privilege-centric identity security protecting Paths to Privilege(TM), today announced NHI Governance, a new solution on the BeyondTrust Pathfinder platform that governs non-human identities operating across cloud, SaaS, endpoints, and on-premises environments. As service accounts, API keys, OAuth clients, workload identities, and AI agents continue to proliferate across enterprise environments, NHI Governance extends the privileged access discipline BeyondTrust has applied to human access for more than two decades to the identities that now outnumber employees in nearly every organisation and remain largely ungoverned. The problem: the privileged surface changed. Controls didn't keep up. Service accounts, API keys, OAuth clients, workload identities, and AI agents now hold most of the standing privilege in the enterprise, and they outnumber the people. BeyondTrust Phantom Labs(TM) research found that non-human identities already vastly outnumber human ones, with enterprise AI agents growing more than 460% year over year. Almost none are ever assigned an owner; their privileges are rarely reviewed, attested, or rightsized; and their credentials are seldom rotated or retired. They are granted access on the day they are created and often retain that access indefinitely. The industry's response has been to inventory them. But a longer list is not a control. The risk was never just that an identity exists; it is also, and especially, the privilege that identity holds and everything that privilege can reach. The recent wave of SaaS-to-SaaS software supply chain attacks made that abundantly clear. Attackers increasingly compromise the OAuth tokens trusted between applications, allowing legitimate access to data at scale. No malware, no escalation, no human in the loop. Every action reads as authorised because it was. Discovery and visibility alone do not stop an attack. Stopping the exfiltration requires controls to be executed ahead of the incident: access already scoped down, the token already rotated, or the unused identity already retired before the attacker arrived. "Seeing non-human identities was only half the equation," said Marc Maiffret, Chief Technology Officer, BeyondTrust. "The other half is doing something about the privilege they carry at scale: deciding who owns each one, pulling back the privilege they aren't using, and retiring the ones that should not exist. And doing so without requiring teams to address them one by one with the limited time they have. That's not paperwork you bolt onto a tool built for employee onboarding. That's managing non-human identities at machine scale." Helping customers move from an inventory list to real control. NHI Governance is built to execute the non-human equivalent of joiner, mover, leaver actions that actually reduce risk, in the right order: * Establish ownership. Every non-human identity is assigned to a person or a team who is accountable for it, so nothing runs unowned. * Enforce least privilege. Lock down the identities that hold real privilege, and constrain what each one can reach, closing the paths to privilege it was never meant to have. * Decommission NHIs. Retire the stale, orphaned, and abandoned identities that make up most of the ungoverned population, so the attack surface shrinks instead of growing unchecked. * Secure AI Agents. Bring them under the same controls, with their own credentials and their own access. Built on two decades of privilege enforcement. For more than two decades, BeyondTrust has helped organisations reduce identity-based risk by governing privileged access across their most critical systems. Non-human identities are no exception. Identity Security Insights(R) already provides industry-leading visibility and intelligence across non-human identities and the privileges they hold, while BeyondTrust Password Safe(R) secures, manages, and rotates the credentials behind them. NHI Governance builds on that foundation by turning visibility and credential management into lifecycle governance that establishes ownership, enforces least privilege, and reduces identity-based risk. Part of the BeyondTrust Pathfinder platform, NHI Governance builds on the recent introduction of AI Agent Security, further unifying discovery, governance, and enforcement within a single platform to secure privilege consistently across every identity capable of privileged action. Availability. NHI Governance is planned for US general availability in Fall 2026, with other global regions to follow. Learn how BeyondTrust helps organisations discover, govern, and secure AI agents and non-human identities with AI Security Posture Management at beyondtrust.com/solutions/ai-security-posture-management.
What to do about the BeyondTrust Remote Access bug. Does your helpdesk use BeyondTrust Remote Support or Privileged Remote Access? Then there is a patch you need this week. BeyondTrust has disclosed a privileged remote access vulnerability that lets an attacker skip the login screen entirely on unpatched appliances. Three related flaws came out alongside it. Here is what actually matters and what to do about it. Table of Contents What was found. BeyondTrust's advisory, BT26-03, lists four issues in Remote Support and PRA versions 25.3.2 and earlier. Two of them, CVE-2026-40138 and CVE-2026-40139, are pre-authentication bypasses. Both score 9.2 out of 10 on BeyondTrust's own CVSS 4.0 scale. Neither requires a username, a password or any prior access. An attacker who can reach the appliance over the network can walk straight past the login. In some configurations they can land on an account with elevated privileges. A third flaw, CVE-2026-40140, can be used to crash the appliance through malformed network traffic. The fourth, CVE-2026-40141, lets someone who already has a low-privilege account reach data they should not be able to touch. All four are fixed in version 25.3.3. Understanding this privileged remote access vulnerability. The two most severe flaws share a common thread: they need no credentials at all. That matters because it removes the usual first line of defence. Password policies, multi-factor authentication and account lockouts do nothing here. They cannot stop a bug that bypasses the login screen itself. Until you patch, the only real protection is limiting who can reach the appliance over the network at all. Who needs to act on this privileged remote access vulnerability. If you use the cloud-hosted version of Remote Support or PRA, there is good news. BeyondTrust says the fix already shipped to your instance in April, well before this week's public advisory. Still, confirm this with your account team. Do not just assume it happened silently in the background. If you run a self-hosted appliance, the update does not apply itself. Check your current version against 25.3.3. If you are behind, schedule the upgrade as a priority patch rather than folding it into the next routine maintenance window. Two of the four flaws need no credentials at all, so "we'll get to it next month" is not a safe answer here. Why this particular vendor deserves extra attention. This is not BeyondTrust's first serious incident. In December 2024, the Chinese state-backed group Silk Typhoon breached BeyondTrust's own systems using a pair of zero-day flaws. They stole an API key and used it to reach seventeen customer Remote Support instances. One of those belonged to the US Treasury Department. Then, in February 2026, a separate bug in the same product line, CVE-2026-1731, was added to CISA's Known Exploited Vulnerabilities list. Attackers had started using it against real targets. This is the third major security event tied to this product family in under eighteen months. That pattern alone justifies treating any new BeyondTrust advisory as urgent rather than routine. A short checklist for this privileged remote access vulnerability. Confirm your Remote Support and PRA version now, not at the next patch cycle. Anything at 25.3.2 or below needs the update. Check whether your appliance is exposed directly to the internet. If it does not need to be, put it behind a VPN or restrict access to known IP ranges instead. Review recent authentication logs on the appliance for anything unusual, particularly successful logins from unfamiliar locations or at odd hours. A bypass of this kind can look like normal admin activity to anyone not specifically looking for it. Ask your supplier, whether that is BeyondTrust or another remote access vendor, how they test these products before release. Also ask how quickly a cloud fix reaches self-hosted customers. The months-long gap between the April cloud patch and this week's public disclosure is worth questioning directly. What about the two lower-severity flaws? It is tempting to focus only on the two 9.2-rated bugs and treat the other pair as an afterthought. Resist that urge. CVE-2026-40140, the denial-of-service flaw, can take your remote support capability offline. That is the last thing you want during an active incident elsewhere on the network. CVE-2026-40141 matters for a different reason. It shows that even a low-privilege helpdesk account can become a route to data it was never meant to see. That includes accounts handed to a junior technician or a contractor. All four issues get fixed by the same upgrade, so there is no reason to patch selectively. The bigger point. This privileged remote access vulnerability is a reminder of what these tools are for. Remote support and privileged access tools are built to grant deep, trusted control over your systems. That is precisely why they are such an attractive target. A vulnerability here carries more weight than an equivalent bug in a less privileged application. Patching promptly matters, but so does limiting what these tools can reach and watching how they are used. The next flaw in this category will not announce itself in advance either. Honest updates, straight to your inbox. Unsubscribe any time. Rebecca is a dedicated cybersecurity writer who specialises in transforming complex technical concepts into clear, accessible content. With a strong background in IT and a passion for digital security, she produces insightful articles, guides, and thought-pieces that bridge the gap between technical experts and wider audiences.
Find jobs on Simplify and start your career today
Industries
Enterprise Software
Cybersecurity
Company Size
1,001-5,000
Company Stage
Acquired
Total Funding
$12.1M
Headquarters
Johns Creek, Georgia
Founded
1985
Find jobs on Simplify and start your career today