Apollo Global Management, which manages more than a trillion dollars, confirmed this week that an attacker got into its cloud systems by calling the helpdesk and impersonating IT staff. No malware, no exploit — a phone call and a password reset. Read that as the tell: an identity stack is only as strong as the person answering the support line. Fitting that this week's AI Shortlist Index runs identity and access management — the measured answers have their own identity problem. Quieter doors opened too: two more named CISOs, a 3.75-million-patient healthcare breach confirmed to federal regulators, and a Pentagon compliance review leaving contractors guessing whether to spend now or wait.

🎯 Buying Windows

This week's windows: 3 security-leadership changes · 2 disclosed incidents · 1 compliance clock · 3 rounds with a security reason.

Apollo Global Management (disclosed incident, Aug 21): confirmed that a helpdesk-impersonation phone scheme accessed its cloud platforms in July, exposing employee and investor names, addresses, and Social Security numbers. Why the window: A confirmed breach at a trillion-dollar-plus manager puts identity and helpdesk-verification controls under board scrutiny, at the firm and every portfolio company sharing its vendors. They buy first: phishing-resistant MFA and helpdesk identity-verification tooling. Motion: CISO platform-led. source

Marriott International (security-leadership change, Aug 19): named a new SVP and Chief Information Security Officer, succeeding the previous CISO and reporting to the CIO. Why the window: A new CISO at a company with a well-documented breach history usually re-baselines the vendor stack within two quarters; incumbent renewals go competitive again. They buy first: guest-data protection, endpoint detection, and third-party risk tooling. Motion: CISO platform-led. source

A market-wide clock (Aug 20): CMMC Phase 2 third-party certification, set for Nov 10, 2026, stays suspended pending a cost review through mid-September; Phase 1 self-assessment and NIST 800-171 Rev. 2 remain mandatory. Why the window: The roughly 300,000-company defense industrial base is deciding now whether to spend on full certification readiness or wait — that uncertainty alone is driving demand for flexible self-assessment tooling. They buy first: NIST 800-171 self-assessment and GRC tooling that does not assume one certification outcome. Motion: CISO platform-led. source

Also opened: CareCloud (incident: cloud security posture management and data-loss prevention) · Allied Universal (new CISO: SOC/XDR consolidation and identity tooling) · Vensure Employer Solutions (new CISO: GRC platform and data-protection tooling) · Rillet (funded: SOC 2 compliance automation and financial-data access controls) · Helcim (funded: PCI compliance automation and merchant-data protection) · Fasset (funded: KYC/AML tooling and wallet-custody security).

Quiet class this week: no buyer-side M&A-integration windows cleared our verification bar. Brinqa’s acquisition of PlexTrac is real news, but it is vendor-side consolidation — covered under Vendor Moves instead.

🤖 The AI Shortlist Index — IAM week

Four engines, the same buyer question. How many put each vendor in their top 5, measured this week:

#

Vendor

On engines

1

Okta

4/4

2

Microsoft (Entra ID / Entra / Azure AD)

4/4

3

Ping Identity

4/4

4

SailPoint

3/4

5

CyberArk

3/4

6

IBM Security Verify

1/4

7

ForgeRock (merged into Ping, 2023)

1/4

Three brands sweep all four engines; only Okta and Ping Identity do it under one name. Microsoft sweeps under three names, including Azure Active Directory, retired in 2023. A fragmented name is a fragmented score. And ChatGPT lists ForgeRock, merged into Ping Identity in 2023, alongside Ping itself. Engine answers lag the market by years; that is why we measure. Method: one prompt per engine, temperature 0, measured Aug 24. Next week: AppSec.

🧭 Vendor Moves

5 vendor moves tracked across the market this week: 2 feature releases, 1 acquisition, 1 funding round, 1 launch.

The three that matter: Brinqa acquired PlexTrac, merging exposure management with pentest reporting into one CTEM platform serving 3,000-plus combined customers. That pushes its category another step toward platform consolidation. Your move: if you sell standalone pentest reporting or exposure management, expect Brinqa's combined base to start asking why you are not bundled too. source

Anthropic opened a public beta of an agentic vulnerability scanner for Enterprise customers and put $35M in credits behind open-source security maintainers. That takes an established vendor into an adjacent category — battlecards against it just aged a quarter. source

TopHat Security closed a Series A to expand its OT and critical-infrastructure digital-twin security platform. source

Also: Tufin (AI-powered network security automation, TOS 5.3) · Intezer (no-SOAR automation builder for its AI SOC platform).

📈 The Number: 2 of 7. Seven IAM brands make at least one engine's top five this week; only Okta and Ping Identity sweep all four under a single name. Microsoft sweeps too, under three different names. And ChatGPT's list carries two ghosts: Azure Active Directory, a name retired in 2023, and ForgeRock, merged into Ping Identity in 2023. Source: Cyber GTM Signals, measured Aug 24, 2026.

The Play

If you sell into identity, access, or helpdesk-verification tooling: Apollo's breach is an open door, not a competitor's problem. Every account team in that category should be calling companies with the same call-center-heavy support model this week, not next quarter. Lead with the mechanism, a voice call that beat an MFA reset flow, not the brand name. Apollo is not your prospect, but every CISO who read about it this week is asking their own team the same question.

Our call: At least one more S&P 500 or Fortune 500 financial-services or asset-management firm discloses a comparable helpdesk-impersonation breach before the end of Q3 2026. The same threat cluster has already been reported targeting Blackstone, Bain Capital, TPG, Clearlake, Bridgewater, CME Group, and Moody's — Apollo is the first to confirm publicly, not the last.

— Martin

Want to see what the AI assistants say about your brand? Reply with your domain — we'll run your AI-visibility audit and send you the shareable report. No pitch, one report.

The version of this email with names, scores, and your own AI-answer share is what GTMfusion sends its users every Monday. Start your 14-day trial →

Forwarded this? Subscribe here. Know a security CMO who should read it? Forward it — this newsletter grows by referral, not by ads.

Cyber GTM Signals · a GTMfusion publication