As the threat landscape expands in size and complexity, enterprises are grappling with whether to use “first-party or pure-play” security providers, said Aiden Walden, senior director of consulting systems engineering at Fortinet.
During a vendor webinar, Walden called out a common misconception that cloud hyperscalers put the appropriate security in place, pointing to Microsoft’s firewalls as a chief example.
The options Microsoft offers for its Azure cloud provide some key capabilities, like intrusion detection systems (IDS), transport layer security (TLS), and Uniform Resource Locator filtering for web categories, according to Fortinet Consulting Cloud Architect John McDonough.
But the “immature” Azure firewall often requires add-ons for many capabilities to be activated and its tools are “only okay” compared to solutions from pure-play security vendors, McDonough added.
‘First-Party or Pure-Play’ SecurityDell’Oro Group Research Director Mauricio Sanchez said this competition exists between all the “key endpoint security vendors” and hyperscalers, and not only with firewalls but for other security tools as well.
Sanchez explained that on a technical front, branded security products that have been around for a longer time are more mature and often have longer feature sets.
“It's no great surprise that if you look at it from a data sheet perspective you're gonna find more knobs and levers in the branded solution than you will see inside that hyperscaler solution,” he said.
But the hyperscaler solution “continues to evolve,” Sanchez added, and that's a “strategic threat” to the branded vendors.
Even as hyperscalers catch up to branded solutions, they already have the upper hand in some ways. Deploying security features already built into cloud offerings is simple for developers – which Sanchez said is probably “the biggest threat” to pure-play security providers.
“It's so easy to – as part of the cloud purchase – insert the Azure firewall or the [Amazon Web Services] firewall, perhaps even the Google firewall,” he noted. “Their firewall is always there. So it's very simple for the developer to say yeah, I need a firewall, and just check the box, and off to the races they go.”
Sanchez pointed to Palo Alto Networks as a vendor that has made a major point of strategy out of focusing on “the right partnerships and showing up at the right instances during the purchasing process to make sure that at least they calibrate up or at least come to parity to the amount of exposure that the in-house solutions have,” and indicated that other pure-play providers should do the same.
Choosing a Provider PathAside from the level of sophistication between products, Sanchez said the other element that enterprises should consider when choosing their security architectures is “the management piece.”
Vendors like Fortinet and Palo Alto Networks enable consistent policy management for enterprises. “If you're used to the warts and to the idiosyncrasies of a particular vendor then there's that benefit that you can now manage everything and have a firewall architecture that's pretty uniform across your Enterprise,” Sanchez said.
“That's always a kind of a beachhead to prevent the in-house solutions from getting too far,” he added.
The other strategic barrier that hyperscalers face is difficulty hosting solutions on other clouds. “If you are multicloud or thinking of multicloud, which of course 90% of the people are, then you should just recognize that before you get too deep into it,” Sanchez said.
Operating within Azure cloud, for example, but also having enclaves in other environments increases the level of complexity and requires a solution that encompasses those different environments and enables policy to be managed from a central point.
“Nonetheless, the in-house solutions, just by virtue of the ease of transaction, they're getting a fair amount of revenue just because of the exposure they get,” he added.
The SASE RelationshipGartner’s term for the convergence of networking and security as a cloud-delivered service — secure access service edge (SASE) — includes security services edge (SSE), a cloud-delivered security suite that packs zero-trust network access (ZTNA), cloud-access security broker (Cloud Access Security Broker), secure web gateway (SWG), and firewall-as-a-service (FaaS).
Walden said organizations need to be thinking more broadly than just their choice of firewall, to their entire security fabric – and SASE can be that built-in security fabric.
He added SASE is a “great all-in-one solution,” but that whether the architecture is ideal depends on each organization’s specific needs. “If you’re an organization that has a predilection toward consuming [Software-as-a-Service] and you really want to not manage infrastructure, SASE is a great solution,” Walden said. SASE optimizes access to other SaaS services as a “complement to cloud environments.”
SASE can also encompass various remote-worker use cases with a “full-stack approach to security,” Walden noted.
“That’s what SASE is meant to be, [it’s] all encompassing. So I think SASE is a great solution and a great alternative if you are resource constrained within your security practice,” he said.
Comments