03 Aug Barracuda identity protection
Identity Protection at the Center of Cyber Resilience. Barracuda Acquires Evo Security
Identity protection is becoming one of the most important areas of cybersecurity. Barracuda has acquired Evo Security, an IAM provider designed for managed service providers. Evo Security technologies are expected to extend BarracudaONE with privileged access management, access control and identity threat detection.
The acquisition was announced on July 7, 2026. According to Barracuda, combining the two companies will support the development of a unified identity protection platform. The solution is intended for partners, MSPs and their customers.
Why is identity protection becoming increasingly important?
Identity has become one of the main targets of cyberattacks. Criminals do not always need to break through technical security controls. Instead, they often use compromised login credentials.
Citing the IBM X-Force Intelligence Index, Barracuda points to a 71% increase in attacks involving stolen credentials. This represents an important shift. Attackers are increasingly gaining access as seemingly legitimate users.
Artificial intelligence can also accelerate this process. It helps create more convincing phishing messages. It also makes it easier to automate login attempts using stolen passwords.
Barracuda also highlights the threat of fake voice recordings. They can imitate company executives. As a result, criminals may try to persuade recipients to take urgent financial action.
Therefore, identity protection cannot be limited to passwords and basic authentication. It should also include access control, administrative privileges and responses to unusual behavior.
Why do administrator accounts require special protection?
After compromising an account, an attacker will often try to gain higher privileges. Administrative access can make it possible to change configurations. It may also allow an attacker to disable security controls or deploy ransomware.
Standing administrative privileges create a particular risk. A user has them at all times, even when they are not currently required.
For this reason, Barracuda points to the just-in-time model. Under this approach, administrative access is granted only for a limited period. Each operation can be recorded. Once the task is completed, the privileges are automatically removed.
As a result, compromised login credentials do not necessarily give an attacker full administrator rights.
What does Evo Security bring to Barracuda?
Evo Security provides Identity and Access Management solutions. The company designed its technologies primarily for MSPs.
Evo Security solutions are expected to extend BarracudaONE with Privileged Access Management capabilities. PAM controls access to accounts and resources with elevated privileges.
Barracuda also plans to introduce automated privilege elevation. The mechanism is expected to assess access requests based on user behavior and context.
Routine activities may be approved automatically. Unusual requests, however, may be blocked or sent for additional verification.
As a result, identity protection is expected to cover the entire process:
- Verifying the user’s identity.
- Granting the appropriate level of access.
- Controlling administrative privileges.
- Detecting suspicious logins.
- Responding to attempted access misuse.
How is identity protection expected to work in BarracudaONE?
Barracuda describes several layers of protection. Together, they are intended to secure users, data and infrastructure.
PAM and secure authentication
Evo Security capabilities are expected to reduce standing administrator privileges. Privileged access will be granted only when it is required.
In addition, PAM is intended to make privilege escalation more difficult. This is important even when an attacker has valid login credentials.
Access based on the principle of least privilege
Barracuda SecureEdge ZTNA limits access to specific applications. The user does not receive broad access to the entire network.
This reduces the number of resources available after login. At the same time, the organization can limit the potential impact of a compromised account.
Protection of Microsoft Entra ID environments
Barracuda Entra ID Backup protects identity infrastructure. This includes users, groups and environment configuration.
A backup can help after accidental data deletion. It may also be needed after malicious changes or a ransomware attack.
Threat detection with Managed XDR
Barracuda Managed XDR analyzes signals from multiple sources. These include endpoints, networks, cloud environments and identity systems.
Barracuda also plans to use authentication and privilege change data from Evo Security. This is expected to help detect account compromise, privilege escalation and lateral movement.
Identity protection will therefore combine access control with analysis of user behavior.
What could the response to an attack look like?
Barracuda presents an example scenario. An attacker compromises an employee’s credentials. The attacker then attempts to gain administrator rights and deploy ransomware.
In this case, PAM is expected to block the privilege escalation attempt. Standing administrator rights are not available.
SecureEdge ZTNA, in turn, limits access to approved applications. The attacker therefore does not automatically gain access to the entire network.
Managed XDR then analyzes the login and the behavior of the device. In this way, the system may detect unusual activity.
An automated response may include isolating the device. It may also invalidate active sessions and rotate credentials.
If the attacker deletes or changes elements of Microsoft Entra ID, Entra ID Backup may allow them to be restored.
However, this is the target model of solution integration described by Barracuda. It does not mean that all planned integrations are already available.
Identity protection for AI agents
Barracuda focuses not only on human users. Non-human identities are also becoming increasingly important.
Organizations are starting to use AI agents. These agents can perform tasks independently and access infrastructure.
Such an agent also needs defined privileges. However, overly broad access can create additional risk.
Barracuda therefore highlights the need for temporary and limited access. Privileges should cover only a specific task. Once the task is completed, access should be automatically revoked.
As a result, identity protection is expected to cover both people and automated processes.
What does the acquisition mean for partners and MSPs?
Evo Security develops solutions for multi-tenant environments. This is especially important for managed service providers.
A partner can manage multiple customers from one environment. There is no need to manage each organization through a separate tool.
The combination of BarracudaONE and Evo Security is expected to help partners offer a broader range of services. These may include:
- identity management,
- PAM,
- ZTNA,
- Entra ID backup,
- threat detection.
According to Barracuda, this approach may reduce the number of tools in use. At the same time, it may simplify the management of security across multiple customer environments.
For MSPs, identity protection may become another managed service. A partner can combine technology with ongoing management, monitoring and incident response.
Identity protection as part of cyber resilience
The acquisition of Evo Security shows the direction in which BarracudaONE is developing. Identity protection is expected to connect authentication, access control, data protection and threat detection.
However, it does not replace email, network, application or endpoint security. Instead, it adds control over who uses resources and what permissions they have.
For organizations, this may help limit the impact of account compromise. For partners, it may create an opportunity to develop new identity and access services.
Important product development disclaimer
Barracuda states that some of the capabilities described relate to the planned direction of product development. This information does not represent a commitment to deliver specific features by a particular date.
In addition, the scope of integration may change. Purchasing decisions should therefore be based on features that are available and officially confirmed when a project is being prepared.
Would you like to discuss identity protection, privileged access or Microsoft Entra ID security? Contact the Kappa Data Polska team.