CrowdStrike remains firmly behind the security information and event management (SIEM) market despite recent upheaval across the space that has opened up more opportunities for more broadly applicable extended detection and response (XDR) platforms.
The SIEM space looks much different today than it looked when the year began.
Cisco closed on its $28 billion Splunk acquisition, and reoriented its overall business to take advantage of that deal; LogRhythm and Exabeam combined their SIEM and user and entity behavior analytics (UEBA) efforts; and Palo Alto Networks acquired IBM’s QRadar assets.
Ajit Sancheti, SIEM lead at CrowdStrike, told SDxCentral in an interview that these moves have opened up opportunities for the vendor.
“There's been so much turmoil in the SIEM space. In the last six to nine months, companies have been acquired and merged and sold. Assets have been sold,” Sancheti said. “So all of that has happened, and every one of those customers has said, ‘let me rethink my SIEM,’ and that's why this business is accelerating for us, and we're seeing it across the board. Obviously, some of the larger companies are taking measured steps as they should, but the smaller companies it's been an easy decision.”
Gartner echoed this motion as part of its most recent quartering of the SIEM market.
“Gartner has seen evidence that the SIEM market itself has been disrupted by external forces that cause clients to rethink the role of a SIEM, and how to select the best technology for them,” the firm wrote as part of its most recent SIEM Magic Quadrant report.
Gartner noted the SIEM market grew from $5.03 billion in sales in 2022, to $5.7 billion in 2023, marking a 13% annual growth rate. However, that growth was down from the 22% between 2021 and 2022, with Gartner placing the SIEM space on the “Plateau of Productivity” as part of its “Hype Cycle for Security Operations 2023” report.
Is there an XDR-SIEM acronym battle? One acronym that has caused some of this existential querying is the continued push around XDR.
Forrester Principal Analyst Allie Mellen in a recent report explained that “many XDR providers have reached a point of integration and product capability where customers can start realizing the SIEM replacement vision, even if XDR still can’t compete for more niche SIEM use cases such as compliance, federated search, and heavy customization.”
“The XDR market is the first market that shows true promise to significantly augment, if not outright replace, the SIEM market,” Mellen added. “It promises big changes for security operations to reduce SIEM costs, enhance detection, and improve analyst experience.”
Sancheti’s view is that XDR has been absorbed into CrowdStrike’s other cybersecurity segments.
“I think that XDR got subsumed by the AI-native [security operations center] because it was very limiting for customers,” Sancheti said. “Very often customers will say, ‘I love the detection they're giving me with XDR, but I want my own customized detections. I want to build my own customized responses. I had my own customized data source, and XDR was a little bit more narrow.’ It was great to help companies that had very few data sources, well defined ones, but most enterprises have so much more data sources, so much propriety stuff that happens that it was very difficult. So our XDR got fully subsumed into the next generation SIEM.”
Forrester’s most recent XDR Wave report listed CrowdStrike as a segment leader alongside Microsoft and Palo Alto Networks, adding that CrowdStrike’s most recent Raptor update put it in a “positions it to win in the XDR market.”
AI to help security analysts Sancheti, for his part, is more enthused about recent CrowdStrike updates targeted at enhancing the artificial intelligence (AI) capabilities of its core Falcon platform. These include the ability to use AI for automated parsing of data sets; detection engineering; and to support security orchestration, automation, and response (SOAR).
But these are just the first steps as CrowdStrike further integrates AI into its platform.
“There's going to be a lot more content correlation rules, things that you get out of box and that a lot of enterprises have had a hard time with the SIEM because they couldn't use anything that was out of box,” Sancheti explained. “Our goal is to get so much of that to be robust and usable, that enterprises can get so much value out of out of box.”
Sancheti also touched on ways to further build on current adoption of its embedded SOAR capabilities and to also integrate additional data sources that can be customized by the user.
“Ultimately, our goal is to revolutionize the security analyst’s experience,” Sancheti said of these AI-focused efforts. “Make them do the high value work and enable them to do it in a way that makes them confident they can do it faster and protect the enterprise better.”
Comments