See AI-powered security on full display at GSX 2025 | Sept 29 – Oct 1  Learn More >>

EN

Blog /

July 15, 2026

The $25B Opportunity in Cyber Physical Security: Governing Digital and Physical Access Through One Identity

Enterprises will spend more on identity security this year than ever before. Governance, zero trust, privileged access, workforce identity, the spend now covers nearly every account, entitlement, and cloud role an employee touches. Almost none of it reaches the doors.

Consider what that looks like in practice. An employee whose application access is governed down to the entitlement level walks into the data center on a badge managed in a system the identity team has never seen. A contractor whose network credentials expire with the engagement keeps a working badge for months afterward. Both are routine, and both are governance failures by the standard the same organization applies to its digital estate.

01

Identity Security Won the Digital Perimeter. The Physical One Is Next.

Identity is now the control plane of enterprise security. When the workforce is everywhere and the applications are everywhere, identity is the one constant left to govern.

But identity security today covers only half of what an identity actually holds. Accounts, entitlements, and cloud roles are provisioned, certified, and audited on a regular cycle. Badges, credentials, and facility rights rarely are. The lifecycle and audit discipline that transformed digital security has not yet reached the physical access carried by the same people.

Closing that gap is the opportunity.

02

Two Terms, Briefly: Unified Identity Governance and PIAM

Unified Identity Governance is the goal: digital and physical access governed through a common identity framework. Instead of managing the two domains independently, an organization applies the same lifecycle controls, certifications, and compliance processes to both. One identity record that accounts for everything a person can reach, whether it lives in the cloud or behind a door.

Physical Identity and Access Management (PIAM) is the layer that makes the goal achievable. PIAM is the discipline of managing physical identities, credentials, and facility access through identity-centric governance processes. It sits above the access control hardware: PACS enforces at the door, while PIAM decides who should hold access at all. The full architecture is covered in PIAM vs IAM vs PACS.

03

Why Cyber Physical Convergence Is Accelerating

Attacks Cross the Boundary

Attackers stopped respecting the cyber-physical line years ago. Operational technology like HVAC, building management, even the access control infrastructure itself is now part of the attack surface. A stolen badge combined with live network credentials is a converged attack, and two disconnected security programs mean neither one sees the whole of it. When an incident spans both domains, response depends on being able to see the single identity behind it.

Insider Risk Management Requires Both Views

Insider risk programs built only on digital telemetry are working with half the signal. An employee downloading sensitive files is one data point; the same identity badging into the records room at midnight makes it a pattern. A contractor whose engagement ended last quarter matters far more when the VPN account and the facility badge are both still active. That correlation is only visible when both domains resolve to one identity.

Regulators Expect One Answer, Not Two

Auditors ask the same four questions about the server and the server room: who has access, why, who approved it, and when it was last reviewed. Frameworks from SOX and HIPAA to NIS2 and DORA increasingly treat those as one question about one identity. Organizations that answer from two evidence bases 1. an IGA platform for digital access, 2. badge-system exports for physical, spend more audit hours reconciling them and face more findings.

The Governance Precedent Is Set

A decade of identity governance created expectations that now work in convergence’s favor. Boards and CISOs who can see certification coverage for every application have started noticing that they cannot see it for a single facility. What they are asking for is not new, it is the same identity governance discipline, extended to physical access. Our guide to identity governance covers the foundations.

04

Converged Security Needs a Converged Identity

Convergence attempts often fail when they begin as organizational restructuring. Merging the physical security and cybersecurity departments produces friction faster than results: the teams have different skills, different tools, and different operational tempos, and a new reporting structure changes none of that.

The workable convergence point is identity. A converged identity, a single profile spanning an individual’s digital accounts and physical credentials, gives both teams a shared source of truth without restructuring either one. It extends the identity and access management governance framework to its full scope, so that physical access management simply becomes one more domain the existing framework governs.

05

Why SailPoint Customers Are Positioned to Move First

Few organizations are better placed to capture this than the 3,100+ enterprises already running SailPoint. They already operate the identity lifecycle workflows, certification programs, compliance reporting, and role governance that convergence requires. What those programs lack is reach, every one of those controls stops at digital systems.

The certified Alert Enterprise Guardian for SailPoint integration extends that reach to facilities, badges, mobile credentials, data centers, and restricted areas. The governance foundation already exists; extending it reuses the workflows, policies, and reporting these organizations already run, rather than requiring a parallel program.

06

Sizing It: The PIAM Software Market and Adjacent Spend

The opportunity is the convergence of several markets that have historically been budgeted in separate silos:

Taken together, these converging markets represent an opportunity exceeding $25 billion worldwide. The buyer signal is consistent across all of them: enterprises want a layer that unifies the systems they already own, not another silo.

07

Cyber-Physical Identity Governance: The Operating Model

We call the destination cyber-physical identity governance: identity as the common control plane, with the same lifecycle, certification, and attestation disciplines operating across digital and physical access alike.

The building blocks already exist. Identity platforms such as SailPoint provide the digital governance foundation. Alert Enterprise Guardian provides the PIAM layer. The certified integration connects the two. What changes is the question a security leader can answer. Not just “who has access to this application?” but “what access does this identity have across the entire enterprise?”

08

The Next Decade

Over the next decade, the distinction between physical and digital identity governance will keep eroding. Organizations will consolidate toward unified governance, unified certifications, unified compliance evidence, and unified lifecycle management for a simple reason: maintaining two of each is the more expensive option.

Digital identity governance was the last decade’s transformation. Extending it to the physical world is this one’s.

09

Frequently Asked Questions

What is cyber physical security?

The practice of managing security risks that span digital systems and physical environments as a single problem, including the identity and access governance common to both.

What is cyber-physical identity governance?

An operating model that governs digital and physical access through a single identity framework – one lifecycle, one certification discipline, one audit trail.

What is driving cyber physical convergence?

Attacks that cross the cyber-physical boundary, insider risk that spans both domains, regulatory expectations for unified access evidence, and the precedent set by a decade of digital identity governance.

How large is the opportunity?

The convergence of identity governance, the PIAM software market, physical security technology, compliance, and critical infrastructure protection represents an opportunity we estimate at more than $25 billion globally.

Which industries benefit most?

Financial services, healthcare, manufacturing, energy, technology, critical infrastructure, government, and higher education sectors with large physical estates and demanding compliance regimes.

en_USEnglish