"Innovation is only halfway to a solution. Basically, you also need to make sure that the customer can consume this innovation." — Shlomo Kramer, founder and CEO of Cato Networks, in a conversation with SDxCentral CEO Matt Palmer.
Kramer was talking about innovation in the context of digitally transforming the IT security industry. Our top stories of the year reflect both the ongoing need for transformation and the current transformation efforts being made.
The No. 1 security story, about an ongoing shakeup in security leadership, shows how much pressure is being applied on CISOs. And hey, they're human just like the rest of us. Working under that kind of pressure isn't sustainable for anyone — fingers crossed that 2024 is a better year all around.
Our second top story is about using the pre-mortem process to anticipate cyberbreaches. Sounds like an innovative idea — start with a pretend breach, then have your team work backward to figure out how the breach occurred (and thereby uncover any potential cracks in your zero-trust defenses before the bad guys can).
Here are the top 10 security stories of 2023, based on aggregate page views:
1. The great CISO resignation: Why security leaders are quitting in drovesResearch from anti-data-exfiltration and ransomware prevention company BlackFog revealed that nearly one-third (32%) of CISOs or IT cybersecurity leaders in the U.S. and UK were considering leaving their current organization. Nine in 10 CISOs report being “moderately” or “tremendously” stressed, according to another study, and average CISO tenure is just two years and two months.
“The CISO is the leader of the front line of defense against threat actors,” said Rick Crandall, chairman of the National Cybersecurity Center’s Cyber Committee, which recently made a call to action to reverse what some are calling the "Great CISO Resignation." This issue is concerning, experts warn — because what happens when there’s nobody guarding the gate and rallying the troops?
2. How a pre-mortem can tell you what’s wrong with zero trustWhat would happen if, let’s say, an organization had fully implemented zero trust and yet at some point several years into the future had a breach? What would be the likely reasons?
That’s the question that Wolfgang Goerlich, advisory CISO at Cisco, explored at the RSA Conference 2023 in a session aptly named “Conducting a Pre-Mortem on the Next Zero Trust Breach.” Goerlich explained that a pre-mortem is a way to imagine a future where operations have failed in some way and there is a process to work backwards to determine what went wrong.
“If we assume we’re going to fail, we can come up with some good scenarios and good strategies,” Goerlich said.
3. Carbon Black breaks from VMware, embarks on independent journey within BroadcomFollowing Broadcom closing its $69 billion acquisition of VMware last month, Jason Rolleston, VP and GM of Carbon Black at Broadcom, announced Carbon Black became a standalone business unit, operating all core business functions in coordination with Broadcom, which allows it to gain a new level of independence and increase its focus to address cybersecurity demands.
“While we will report into Broadcom, we are responsible for our own success, which is an exciting proposition,” he added. “We were successful within VMware, and now our future is brighter than ever as we focus on our customers’ critical cybersecurity challenges without distraction.”
4. VMware separates Carbon Black and NSX businesses – what it means to youIn April, before the acquisition by Broadcom was completed, VMware reorganized its Networking and Advanced Security business group following the departure of its ex-SVP Tom Gillis. The group was split and returned to two separate units. That is, the Carbon Black and NSX businesses operate independently.
The vendor combined the Carbon Black business and the networking and security business group to form the Networking and Advanced Security business group (NASBG) under Gillis. The integration of NSX and Carbon Black services provided a network-level analysis that monitors the anomalous pattern across transitions, servers and networks, Gillis told SDxCentral in an earlier interview.
5. Former Palo Alto Networks employees launch security startup, raise $51 millionA trio of former Palo Alto Networks employees formally announced their startup, Gutsy, after a year of development. Alongside the startup emerging from its stealth mode, the company announced a staggering $51 million seed round led by YL Ventures and Mayfield.
The basic premise of Gutsy is simple: to help organizations use process mining techniques to better understand, remediate and optimize security processes.
6. Behind the firewalls: A day in the life of a Palo Alto Networks SOC analystPalo Alto Networks’ internal security operations center (SOC) ingests more than 36 billion events and 75 terabytes of data per day, yet it’s run by only 10 analysts. Created in 2017, Palo Alto Networks’ internal SOC comprises 22 full-time employees, including those 10 analysts responsible for security alerts, incident response and threat hunting. The rest of the team is on the engineering side, configuring and maintaining cybersecurity tools that enable those analysts. The team is responsible for protecting the security giant’s own infrastructure and employees, SOC Operations Specialist Devin Johnstone told SDxCentral.
7. CrowdStrike eyes market share gains as SentinelOne and BlackBerry in potential sale talksDuring an earnings call for the second fiscal quarter of 2024, CrowdStrike President and CEO George Kurtz responded to an analyst’s question about whether the vendor is already generating strong share gain opportunities in the small- and mid-sized markets as SentinelOne and BlackBerry Cylance are potentially up for sale.
“So we’ve already seen deals come our way,” Kurtz said. “We’ll see how everything shakes out, but for sure what we’re hearing from partners and customers about some of the latest movements in our space is concerning in terms of other competitors.”
8. Palo Alto Networks CEO eyes $200B market, predicts real-time security shiftThe enterprise security market has seen substantial growth to become an estimated $213 billion market over the last five years. The future will require a shift to more real-time and artificial intelligence (AI)-driven security delivered by platforms, noted Palo Alto Networks Chairman and CEO Nikesh Arora.
“What we think lies ahead is the need for security to stop bad actors mid-flight, real time, as it’s happening,” Arora said in his forward-looking statements, adding that the current average industry rate is around 30% or 40% in real-time actions. “What we still aren’t good at as an industry is being able to figure out unknowns and stop them before they happen.”
9. Cisco, VMware and other tech giants tackle end-of-life product issuesEleven tech industry leaders across networking, security and service providers launched the Network Resilience Coalition to address the persistent lack of network hardware and software resilience. The alliance is tackling the issue by encouraging timely updates and patching and better communication.
“If we’re going to address the full problem, we all need to work together," Ari Schwartz, coordinator at the Center for Cybersecurity Policy and Law, said during the launch event. "And that’s the goal of the Network Resilience Coalition — to work together on recommending solutions that need to be implemented by the software and hardware vendors, the communication platforms and policymakers.”
10. New vulnerability in Cisco’s Nexus switch could allow attackers to modify encrypted trafficFound during Cisco’s internal security testing, the bug is in the Cisco ACI Multi-Site CloudSec encryption feature of Cisco Nexus 9000 Series Fabric Switches in application-centric infrastructure (ACI) mode, which is typically deployed in data centers for controlling physical and virtual networks.
The networking giant noted this vulnerability affects Cisco Nexus 9000 Series Fabric Switches in ACI mode that are running releases 14.0 and later if they are part of a Multi-Site topology and have the CloudSec encryption feature enabled. Notably, Cisco Nexus 9000 Series Switches in standalone NX-OS mode are not affected by this flaw.
Comments