Cybersecurity
– Getty Images

Platformization is now shaping the cybersecurity landscape. Both vendors and buyers in the sector are driving this change, but why platformization – and is this a real thing or just another marketing concept?

Craig Porter, director for Gartner's security research and advisory team, told SDxCentral that the push towards platformization is a “two-pronged approach.”

“The vendors are expanding their capabilities, as well as the buyers are interested in consolidating,” he said.

From a security vendor perspective, a platform-based approach allows them to integrate more features and components that address both business and cybersecurity risks. On the other hand, buyers, overwhelmed by managing numerous security solutions, are seeking simplicity and efficiency, Porter said.

Buyers perceive security platform approach to be more efficient

Citing Gartner figures, Porter said that organizations now have 60-70 security tools from 10 to 15 different vendors, which brings in risks of misconfigurations, service overlaps, and inefficiencies.

There are several reasons that security product buyers are consolidating vendors and tools through a platform approach, including the following:

  • Business outcomes: End-user organizations are looking for business outcomes and use cases that meet their security control, business, and security risk-based requirements. “I don't think they're concerned about defining what a platform is. I think they're concerned about the outcome of that approach,” Porter said.
  • User experience: From an end-user perspective, a platform should offer integration between the tools with a single console to manage and monitor these tools. Porter emphasizes the importance of user experience; for example, buyers may ask, “Do these products integrate with my current stack? Do these products talk well with each other?”
  • External forces: Porter noted that leadership and management changes, mergers and acquisitions, and budget constraints are among the external forces driving vendor consolidation. Many security teams are aware of the vendor lock-in risks of a platform approach, but sometimes the decision is out of their hands.

Porter recommends that security buyers aim their consolidation project at improving risk posture for their organization through simplification instead of cost-saving.

“As far as the next step to get to vendor consolidation, you need to inventory your needs, you need to look at the roadmap and make sure that the vendors that you're considering align with your organization's strategy,” he said.

Porter added that efficiency is another factor to consider. “Look at products based on the functionalities that they're offering,” he said. “So, are your users happy with them? Are the admins happy with the tools? Because you may have a tool that your admins love, and if you take it away from them because you're going into a different platform and they don't like it, they may have an issue with that.”

Consolidated vs. converged platform approaches

Recently, a platform debate has unfolded between several major security players with distinct visions of what a true security platform should do.

A platform should have a few basic non-negotiables: one console, one agent, and multiple capabilities that can seamlessly deliver to that system, CrowdStrike’s CTO Elia Zaitsev told SDxCentral in an earlier interview.

But Palo Alto Networks cofounder and CTO Nir Zuk argued a true platform must first cover a substantial portion of the functionality the market needs within its domain. Second, what differentiates a portfolio from a platform is the measurable integration.

Porter noted there are two kinds of platform approaches: consolidation and convergence, adding, “I think that consolidated platform versus converged platform is probably where the debate is happening.”

A consolidated platform approach usually offers a single product with one policy, a single SKU, and a management console from one vendor; whereas a converged platform approach provides multiple integrated products from a single vendor, according to Porter.

On the flip side, despite the push for consolidation and convergence, there is still room for niche or “best of breed” security solutions that cater to specific needs that a platform approach may not fully address.

“I think there's still reason for best of breed, and I think it's that niche use case; it's, hey, does this platform work for 100% of my needs, and I don't think we're gonna get there anytime soon,” Porter said. “I think looking at those capabilities and mapping them to business outcomes is really crucial.”