Cisco security executives argued current security approaches are “untenable” given the rise of the cyberattack sophistication and the platform approach is going to reshape the security vendor landscape.
“Think about the way that this market evolved. It was completely a patchwork-based evolution,” Jeetu Patel, executive vice president and GM of security and collaboration, told SDxCentral.
Many organizations are working with different security vendors to meet specific security needs, from identity issues to threat detection to lateral movements. This strategy worked until they got to a point where there are an estimated 3,500 vendors in the market and customers juggle an average of 50-70 vendors.
“That means there are 70 places where there could be cracks in the system, where you might have contention between two policies that cannot be auto-resolved, because they're two separate policy engines,” Patel said.
Additionally, as cyberthreats evolve and become more sophisticated with the use of artificial intelligence (AI), it's becoming increasingly difficult to distinguish between a normal and legitimate activity and a malicious event, he added.
“What we have to do is tie those together in a way where telemetry across these domains can actually be correlated. And it's hard to do without a platform-based approach,” Patel argues.
What counts as a security platform approach?
A consolidated platform should streamline the user experience; offer an integrated management console, common data plans, and government rule constructs among various environments; and reduce the number of touchpoints on the endpoints or end users. Otherwise, it’s just a portfolio of products, Gartner’s senior director analyst Charlie Winckless told SDxCentral in an earlier interview.
Senior Vice President and GM of Cisco’s Security Business Group Tom Gillis also noted “a platform is not a bag of parts.” It’s a system that can coherently gather telemetry from various sources, such as email, web, endpoints and networks, to identify and stop threats and orchestrate an intelligent response.
“We have firewalls, IPS [intrusion prevention system], micro-segmentation, multi-cloud connectivity, network detection, remediation, all integrated as a single offering, a single set of telemetry, single policy administration, single sign-on, that's the level of integration that we're building this [Security Cloud] platform,” Gillis told SDxCentral.
Cisco is not the only security company that pushes for this change and other vendors such as Palo Alto Networks and CrowdStrike also touted their security consolidation platform approach.
However, Patel argues very few vendors “actually think about an end-to-end platform that includes endpoint network, firewall, email and the network, all pulled together. It's just hard.”
He added scale matters in cybersecurity because it's a data game and to operate security at a machine scale requires the capability to handle vast amounts of data. “The more data you put into the models, the better the models are gonna get, and the better they're going to perform. We have to have a variety of data and scale of data, both dimensions.”
Cisco doubles down on integration
Cisco’s platform approach is around its integrated networking and security platform — Security Cloud, which unified its 27 security services into a few product suites such as its most recent extended detection and response (XDR) announcement.
The vendor unveiled the Security Cloud last June, which is a set of cloud-based services that provides threat detection and prevention, minimizes cyber risks, and integrates breach response and remediation with machine learning technology, Patel said in an earlier interview.
To create an integrated platform rather than individual biennials, he stated Cisco's security business has altered its organizational structure by streamlining the leadership team to be under a single general manager — Gillis — who leads all the product teams.
The platform is composed of two major components: a number of prevention technologies such as firewalls, secure connectivity, identity, and access management; and threat detection, response and remediation capabilities that deal with the breach aftermath.
The goal is to make security more straightforward for the defender and more complicated for the attacker, Patel said. “Right now, what's happened is it's very easy for the attacker to attack and it's very complicated for the defender to defend, and you got to flip that equation.”
Cisco priorities security business
During the latest earnings call, Cisco Chairman and CEO Chuck Robbins reiterated the security business now becomes the tech giant’s “top priority.” The company’s end-to-end security business revenue went up 2% year over year in the third fiscal quarter of 2023 to $958 million “driven by our unified threat management and zero-trust offerings,” according to CFO and Executive Vice President Scott Herren.
Robbins noted Cisco plans to roll out more innovations building on its Cisco Security Cloud strategy starting at Cisco Live next month. “When you look out to the second half of next fiscal year, I think you'll see security really accelerating into a growth driver for us.”
In the quarter, Cisco closed its acquisition of cloud security startup Valtix and announced the intent to buy Israel-based cloud security posture management (CSPM) startup Lightspin and digital experience monitoring vendor Smartlook for full-stack observability.
Photo (left to right): Tom Gillis and Jeetu Patel. Source: Cisco
Comments