Secureworks CEO Wendy Thomas has two goals for the cybersecurity vendor. One involves leading a $40-billion market. The other addresses a more existential crisis that has plagued the industry for years. And both play to the managed security services provider’s 20-plus years of threat intelligence and research.
“My primary goal is to be the XDR platform of choice, period, full stop,” said Thomas, who took the reins earlier this month following former Secureworks CEO Michael Cote’s retirement.
“The second one is to address the security skills shortage by enabling others to leverage that platform at scale,” she continued. “That’s not just saying hey, you can deliver security services on top of the Taegis platform or trying to change out the tech stack of other managed security service providers. I’m talking about expanding the opportunity by taking our brand reputation for running scaled security operations as a market-leading MSSP, and to turn managed services providers in the technology space into managed security service providers.”
Taegis is Secureworks’ extended detection and response (XDR) platform, which the Dell Technologies-owned company launched in 2019. Thomas led the team that developed Taegis. And on the company’s most recent earnings call, as well as during an interview with SDxCentral, Thomas noted that during the second quarter of 2021, Taegis’ annual recurring revenue (ARR) passed $100 million and grew 200% year over year.
The XDR product now represents about a quarter of Secureworks’ total ARR, and the company expects Taegis to nab at least $155 million ARR for the full year.
Secureworks Targets $40B XDR Market“This is a $40-billion market in a few years with high-teen growth rates, Thomas said. She’s referring to the $40-plus-billion total addressable market by 2025 that analysts forecast as endpoint protection, security information and event management (SIEM), vulnerability assessment, and other products become features of broader XDR platforms.
XDR combines elements of SIEM; security orchestration, automation, and response (SOAR); endpoint detection and response (EDR), and network traffic analysis (NTA) in a software-as-a-service (SaaS) platform to centralize security data, threat hunting, and incident response. Gartner called it a top security and risk management trend of 2020, and by now all of the large security platform vendors, along with most of the EDR and SIEM players, have rolled out their own XDR platforms — or at least something that they label XDR.
“What we see happening is that standalone products today are increasingly going to become features of an integrated XDR platform,” Thomas said. “And we certainly are doing some of that today, but we’re not done, and I don’t think that the market is done. Vulnerability assessment and prioritization, SIEM use cases, SOAR, threat intelligence, email security — having this standalone in a separate piece of software outside of that platform just doesn't make a lot of sense.”
As it builds out its platform capabilities, Secureworks has “a build, a buy, and a partner strategy” around XDR, Thomas added. However, there are some pieces where “we absolutely think that our expertise in designing and building is strategically important.”
“Anything that is core to detection, response, threat intelligence, prioritization, orchestration, playbooks — those have to be designed fundamentally with security first in mind,” Thomas said. “We view that as our special sauce, and we want to make sure that everything around that we own and build.”
Make MSPs Into MSSPsThis ties into Thomas’ second goal around fixing the cybersecurity skills shortage by turning managed services providers (MSPs) into managed security services providers (MSSPs). It will benefit the industry, which, in the U.S. alone needs to fill half-a-million cybersecurity jobs. And it makes sense to integrate MSPs and MSSPs, Thomas said.
“[MSPs] see that as an incredible, adjacent, incremental business opportunity,” she added. “And when they can leverage our training and certification programs, and a platform that is built to run a security operation at scale, the opportunity is both compelling from a business perspective, and it starts to address an increasingly difficult problem of an insufficient number of security resources trained at running really effective security programs for customers.”
Secureworks launched this partner program earlier this year, and one of its marque partners is its parent company: Dell.
Dell now offers a subscription-based, managed detection and response service that targets organizations with 50 or more endpoints. It combines Secureworks’ Taegis XDR platform and Dell’s analysts.
Secureworks’ platform monitors, detects, and investigates potential threats, and then automates response across the customer’s IT environment.
Additionally, Dell’s security analysts help customers deploy security controls and integrate technologies across their data sources. When threats surface, the analysts investigate and provide recommended actions to remediate them.
Where Are the Female CEOs?As Secureworks new CEO, Thomas now belongs to a very elite club. Only about 5% of cybersecurity companies are led by women.
Thomas, like many female executives, finds it a bit awkward to answer questions about her role as a woman and a CEO — something most male executives never have to address. However, considering the lack of diversity and inclusion in C-level suites across technology as a whole and specifically in cybersecurity, she says it’s an important issue to discuss.
“Lots of teammates, and family, and colleagues have asked, and if I’m perfectly honest, my first reaction was a little bit frustrated,” she said. “Everybody wants to be judged on their own merit, not the things that they can’t control: their gender, the color of their skin. But if one person can picture themselves doing something that they were afraid to imagine or just assumed that they couldn’t imagine because they see one step in the change of the statistically dominant profile of CEOs, then I am proud for someone to call out my gender, and say it is possible, dream big.”
Her new role presents an opportunity to increase the number of people who might consider a career in cybersecurity, Thomas said. And this is important because “we absolutely need to look like the markets that we serve.”
Thomas said she’s talked with several CISOs and Secureworks’ higher education customers about increasing cyber literacy, and the opportunity to build a science, technology, engineering, and mathematics (STEM) pipeline of talent to help fill this gap.
“Basic cyber literacy is a crisis of our time,” she said. “If we can show people that this is a great and meaningful career path, and start to make our industry look like the populations that we serve, I would be proud to call that my life’s work.”
Comments