As cloud giants fight over cybersecurity, what might be next in Google’s security shopping cart?

Before it considers more acquisitions in the cybersecurity space, Google has its hands full integrating previous big-ticket items.

The tech titan grabbed cyber defense and response vendor Mandiant earlier this week, following its acquisition of security orchestration, automation, and response (SOAR) vendor Siemplify last month. It bought the security information and event management (SIEM) platform Chronicle in 2019, which now becomes Google Cloud’s security analytics platform.

With Chronicle and Siemplify, Google Cloud offers a combination of security analytics and SOAR capabilities, Forrester analysts Jeff Pollard and Allie Mellen wrote in a blog post. 

Mandiant currently has more than 600 cybersecurity consultants and over 300 intelligence analysts powering Mandiant Advantage, its managed multi-vendor extended detection and response (XDR) platform. 

Analysts expect this expertise to advance Google's security analysts team Project Zero and accelerate the Google Cybersecurity Action Team expansion, which provides advisory, threat intelligence, and incident response services.

“For the most part, it's probably less about technical integration than some of the other acquisitions that Google has made and more about the actual people acquisition,” Amy DeCarlo, principal analyst at GlobalData, said in an interview with SDxCentral. 

"For now, Google Cloud Platform (GCP) relies on partnerships for a complete XDR offering, and Mandiant’s MDR [managed detection and response] service coupled up with direct Google competitor Microsoft via Defender,” Pollard and Mellen wrote.

Is the Acquisition About XDR or Incident Response?

Why did Google choose Mandiant? 

“It's more about bringing an XDR platform and MDR capabilities into Google, that's the priority,” Neil MacDonald, VP and distinguished analyst at Gartner, told SDxCentral.

Google and Microsoft were reportedly in talks with Mandiant during the last few weeks, and both aimed to bring Mandiant’s MDR platform in house, according to multiple analysts.

“If you think of Mandiant only as services, then you might be surprised, but most people don't realize that there's an MDR, XDR platform behind Mandiant,” MacDonald said. “When you understand that, then you start to realize there's a natural adjacency here to Google and Chronicle.”  

Alongside the recent Siemplify acquisition, “you realize what Google is building out is really a set of capabilities to target a modern security operations center,” he said. “The acquisition is about threat intelligence, the research capabilities, the XDR, MDR platform, the security brand name recognition.”

DeCarlo takes another view on Google's priority. “What Google was looking for was the incident response piece, the automation piece, advanced threat testing, and analytics,” she said.  “I don't think it's been put together in a way that you would call it a traditional XDR solution." 

Is Google Cloud a Better Match Than FireEye?

Analysts agree that Google Cloud might be a better match for Mandiant than FireEye. 

FireEye bought Mandiant for about $1 billion in early 2014. Last year it announced plans to reposition its Mandiant threat intelligence and incident response arm as an independent company, reclaimed the name and became a publicly-traded company. 

Mandiant’s brand name was too strong and its ability to convert instant response customers ultimately into MDR customers is too powerful, “so they may not have been a great fit for FireEye, but it was going to be a fit for some other large security company,” MacDonald said. 

“When it was part of FireEye, I think that there were some squandered opportunities back then,” DeCarlo said. Integrating it into Google Cloud will potentially help Mandiant have a focused and richer portfolio, she added.

Google can also offer scalability and economies of scale through the cloud that FireEye couldn’t, according to MacDonald.

Cloud Giants Fight Over Security

The acquisition of Mandiant exemplifies Google's ambitions in the cybersecurity market, MacDonald added. "Google is quite serious about growing its footprint in the security market, and doesn't matter whether or not the customer runs on GCP." 

Meanwhile, the largest public cloud provider Amazon Web Services (AWS) “has avoided becoming a security vendor" and chosen not to enter the SIEM space, he added.

Microsoft Azure rolled out a SIEM tool called Azure Sentinel in 2019 and then simplified its XDR platforms under its Defender brand. Microsoft also last summer acquired RiskIQ, including its attack surface visibility and threat intelligence capabilities. 

“Microsoft and AWS are more reliant on partners for incident response services,” DeCarlo said.

“Cloud-delivered security services is directionally where the bulk of the market is heading,” MacDonald said. “Google is taking advantage of that shift, and so is Microsoft, and so eventually will AWS, but Google and Microsoft are leading that.” 

What Might be Next in Google Cloud’s Shopping Cart?

Google’s “spree is not over”, as Google Cloud still has major portfolio gaps in endpoint detection and response (EDR), Forrester analysts wrote. “Given that GCP needs EDR to gain full ownership of the technologies that comprise its XDR offering, its next shopping list likely includes an EDR tool.”

DeCarlo expects Google to pursue improved threat analytics, threat intelligence, and potentially a company focused on machine learning and other areas of artificial intelligence or analytics development around security.

“Microsoft publicly stated they have a $15 billion security business, and Google's looking at opportunities that match its cloud delivery model ... that Microsoft is doing well with," MacDonald concluded. "I think that's a general way to look at that pattern."