Next year, we might see a cloud security showdown. Forrester analysts expect Amazon / Amazon Web Services (AWS) to acquire a managed detection and response (MDR) vendor in 2023, aiming to reclaim the cloud security lead over Microsoft and Google.

“As the cloud market leader, AWS is under pressure to match its hyperscale cohorts with security breadth,” analysts wrote in their cloud computing predictions for 2023. “An MDR play would complement AWS’s silicon-focused security approach and mollify current and potential enterprise-class Microsoft customers susceptible to Azure’s lure.”

Back in 2019, AWS had its first conference dedicated to cloud security — AWS re:Inforce. “It was the first cloud security event of that type. And it is that moment in AWS was well positioned to be the most authoritative security player in the big public cloud space,” Forrester Principal Analyst Lee Sustar told SDxCentral.

However, things have changed since then. Microsoft and Google announced a number of innovations and acquisitions in this field, and AWS “does not have that kind of de facto leader leadership that they enjoyed back in 2019,” he added.

That being said, AWS still has its unique position in cloud security with its silicon-focused Nitro system based on proprietary technology and confidential computing, Sustar noted.

Plus, AWS has partnerships with all the leading security players including Palo Alto Networks and Crowdstrike. During last month’s AWS re:Invent 2022, it announced the preview of the Amazon Security Lake which is designed to automatically centralize users’ security data from on-premises, cloud providers, and those security partners.

With an MDR buy, AWS could potentially feed security data into the service. And the acquisition could also better its position to compete with Microsoft and Google over cloud security.

Google completed its Mandiant buy in September in an all-cash deal valued at around $5.4 billion. The security vendor’s threat intelligence team, detection and response capabilities, and threat research strengthen the tech giant’s security portfolio. Google also acquired security orchestration, automation, and response (SOAR) vendor Siemplify earlier this year and bought the security information and event management (SIEM) platform Chronicle in 2019.

Microsoft’s Defender threat intelligence service is based on capabilities from the company’s RiskIQ acquisition last year, Microsoft’s nation-state tracking team, Threat Intelligence Center, and the Microsoft 365 Defender security research teams.

Meet Customers’ Needs on Consolidation

Forrester expects AWS to make an acquisition of MDR because there is a greater interest among the cloud customers to have a consolidated cloud-based approach and a complete array of security services directly from cloud providers, Sustar said.

“AWS is gonna have to make a move to address what customers are looking for,” he said. “Probably what their customers would be most interested in would be an array of security capabilities beyond what they have now. That might include an MDR. That might include some other capabilities.”

Some organizations might already have security vendors for MDR, but they would like to have another option from their cloud providers, as well as multi-cloud security capabilities, because security is becoming a more important consideration for cloud customers, Sustar added.

Who Will AWS Buy for MDR?

In a recent Forrester Wave on MDR report, it explained MDR can better customers' threat detection, faster their investigation to provide context as input into decision-making, and offer expertise to make faster, more accurate decisions on which response actions to choose.

The analysis firm evaluated 15 MDR providers in the report and named Expel, CrowdStrike, Secureworks, Red Canary, and Binary Defense as leaders; FireEye (now known as Trellix), Cybereason, Rapid7, Trustwave, Kudelski Security, SentinelOne, Deepwatch, and NCC Group as strong performers, and eSentire and Arctic Wolf as contenders.

Sustar expects AWS to make a pick of one or multiple MDR startups or a mature major security player to build out the capabilities. “The advantage that AWS has as the leading cloud provider, in terms of market share, is that almost everybody already integrates with AWS. So even if they were to buy, they wouldn't be starting from scratch. They would presumably be starting from some integrations that they already have.”

AWS has a lot of resources to ramp up and integrate one or several small MDR vendors through acquisitions or buy a strong brand name similar to Mandiant.

“They have a lot of options. They can go for a major security player that's already well-known and established and consolidate partnerships that they probably already have in place. Or they could buy one or more startups to address particular issues and ramp those up into services very quickly. And because it's AWS standing behind them, they could get the attention that a smaller company may not. And [AWS] may choose all of these approaches, but they do need to address this in a more systematic way. The market has moved in that direction that people want their cloud providers to play a more central role in security,” Sustar concluded.