📊 Key Data
  • 201% QoQ increase in bookings for FusionAuth
  • 10 explicit signals used in Intelligent MFA for risk assessment
  • Double the rate of security incidents reported by organizations using shared multi-tenant identity infrastructure
🎯 Expert Consensus

Experts would likely conclude that the demand for explainable, auditable security solutions is growing significantly, particularly in regulated industries where transparency and control are critical.

12 days ago
Beyond the Black Box: Why Explainable Security is the New Mandate

Beyond the Black Box: Why Explainable Security is the New Mandate

BOULDER, Colo. – July 09, 2026 – In the world of enterprise technology, a quiet but profound shift is underway. For years, the mantra was to trust the cloud, embrace the algorithm, and outsource complexity. But a growing contingent of organizations is now pushing back, demanding not just security, but understandable, auditable, and controllable security. This trend was cast into sharp relief this week as identity management firm FusionAuth announced both record-breaking growth and a new product that directly challenges the "black box" paradigm.

The company, which specializes in customer identity and access management (CIAM), reported a staggering 201% quarter-over-quarter increase in bookings. This financial momentum coincides with the launch of FusionAuth 1.68, which introduces "Intelligent MFA," a risk-based authentication engine. While adaptive authentication is not new, FusionAuth's approach is a deliberate departure from the market's trajectory, prioritizing deterministic rules and transparency over the opaque machine learning models favored by many large-scale SaaS providers. It’s a move that suggests a significant portion of the market is no longer satisfied with being told a security decision was made simply because "the algorithm decided."

The Problem with Opaque Trust

For security and compliance teams, the rise of AI-driven security tools has been a double-edged sword. On one hand, these systems can analyze vast amounts of data to detect threats humans might miss. On the other, they often operate as inscrutable black boxes. When a legitimate user is blocked or a fraudulent one is let through, understanding why the system made its decision can be nearly impossible.

This lack of transparency creates significant business and regulatory risk. As FusionAuth CEO Brian Bell articulated in the announcement, "When a regulator, a board member, or a customer asks why a login was flagged, 'the algorithm decided' isn't an answer. Organizations are rethinking their identity stack not just for security but for accountability."

This is the core problem FusionAuth aims to solve. In regulated industries like finance, healthcare, and government, the ability to document and explain every step of a security process is not a luxury; it's a legal and operational necessity. An auditor will not be satisfied with a shrug and a reference to a proprietary risk model. They need to see the policy, the data that triggered it, and the resulting action. The opacity of many cloud-native, multi-tenant security solutions makes this level of granular auditability a significant challenge.

A Shift Towards Explainable Authentication

FusionAuth's Intelligent MFA is engineered as a direct response to this challenge. Instead of a complex, ever-changing machine learning model, the system uses a deterministic, rules-based engine that evaluates every login against 10 explicit and configurable signals. These signals provide a practical, common-sense basis for risk assessment, including factors like an unrecognized device, an IP address on a blocklist, "impossible travel" (e.g., logins from different continents in an hour), or access from a dormant account.

Each login is assigned a low, medium, or high risk score based on these signals. A high-risk event, such as a login from a new device in a different country, automatically triggers a multi-factor authentication (MFA) challenge. A low-risk event, like a user logging in from their usual device on the corporate network, proceeds without interruption.

The critical difference is what happens next. For security teams, the entire process is logged and auditable. They can see exactly which signals were triggered and why the composite risk score was assigned. This transparency transforms authentication from a mystical art into a repeatable science. "Security teams do not just need stronger authentication. They need authentication they can explain," Bell added. This explainability is the foundation for building trust—not just with users, but with auditors, executives, and regulators.

Reclaiming Control Over Critical Infrastructure

The strong commercial performance reported by FusionAuth suggests its message of control and transparency is resonating deeply. The 201% QoQ bookings growth points to a market that is actively seeking alternatives to the one-size-fits-all, shared-infrastructure model. This isn't just about features; it's about fundamental architecture.

FusionAuth has long championed a flexible deployment model, allowing customers to run its platform on-premises, in a private cloud, or in a dedicated cloud instance—anywhere the customer maintains control. This stands in contrast to the multi-tenant SaaS model where customer data and logic co-mingle with thousands of other organizations on shared infrastructure.

The company buttresses this argument with data from its "2026 State of AI and Identity Report." The report found that organizations using shared multi-tenant identity infrastructure reported confirmed security incidents at more than double the rate of organizations using self-hosted or isolated deployments. While correlation is not causation, the finding amplifies a growing concern among CISOs: in a shared model, you inherit the risks of your noisiest neighbors, and your ability to isolate and control your environment is inherently limited.

This desire for control is about more than just security posture. It's about data sovereignty, performance tuning, and cost predictability. As identity becomes the central control plane for applications, APIs, and even AI agents, handing the keys to a third-party black box is becoming an increasingly untenable proposition for many. As Bell noted, "Deployment model, data control, auditability, and user experience are no longer separate conversations. They are all part of the same identity risk equation."

Balancing Security and User Experience

Ultimately, the most secure system is useless if users refuse to adopt it. The constant friction of legacy security measures has given rise to "MFA fatigue," where frustrated users reflexively approve any authentication request, inadvertently enabling attackers. Intelligent, adaptive authentication promises a solution.

By challenging users only when specific risk is detected, systems like FusionAuth's Intelligent MFA aim to make security invisible for the vast majority of legitimate interactions. This creates a better user experience, which in turn leads to better security outcomes, as users are less likely to seek frustrating workarounds.

While competitors like Okta and Auth0 also offer sophisticated adaptive MFA, FusionAuth is making a clear bet that for a significant and growing segment of the market, the combination of deterministic rules, radical transparency, and deployment control is the winning formula. It’s a strategy that trades the mystique of AI-powered magic for the grounded reality of an auditable, explainable, and controllable system. For leaders who value execution over hype, this shift represents a welcome return to first principles in securing critical infrastructure.

Topics & Related

Sector:
Cybersecurity
Software & SaaS
Event:
Product Launch
Theme:
Identity & Access Management

📝 This article is still being updated

Are you a relevant expert who could contribute your opinion or insights to this article? We'd love to hear from you. We will give you full credit for your contribution.

Contribute Your Expertise →
UAID: 42327