The combined McAfee Enterprise and FireEye cybersecurity venture has a new name — Trellix — but it remains focused on dominating the lucrative extended detection and response (XDR) market by enabling organizations to adopt what CEO Bryan Palma calls “living security.”
The $2 billion company’s new name also reflects this concept, Palma said in an interview with SDxCentral.
“Metaphors of battle really dominate cybersecurity,” he said. “And that was great in the days when you used to have to put up a perimeter and keep bad guys out, but I just see it as crazy how some of our competitors talk about stopping breaches — it’s just not the world we’re in today.”
Breaches will happen, and the attack surface is becoming much larger and more complex, Palma said. “Threats are getting way more sophisticated. You’ve got to be able to learn and adapt and respond.”
That’s where the name comes from. Trellix, which sounds like trellis, conjures images of a strong framework to support climbing plants. Similarly, Trellix’s XDR platform will support companies as they grow their own security posture.
“We’re in a world that requires adaptation, being able to be flexible, and being able to change your defenses,” Palma explained.
While both FireEye and McAfee had rolled out their own XDR platforms before merging, their complementary technologies across security operations, endpoint, network, cloud, email and data protection give Trellix an advantage in the competitive market, Palma added.
The combined company’s roots reach to early 2021, when Symphony Technology Group (STG) paid $4 billion cash to acquire McAfee’s enterprise security business. A few months later, FireEye said it would sell its products business to STG for $1.2 billion and reposition its Mandiant threat intelligence and incident response arm as an independent company.
McAfee Enterprise and FireEye officially merged in October 2021.
Also today, STG said it plans to spin off McAfee’s secure access services edge and zero-trust technologies into a separate business later this quarter. This portfolio will include cloud access security broker, secure web gateway, and zero-trust network access.
Trellix Doubles Down on XDR, Open SourceFireEye’s cloud-native Helix XDR platform, which provides security orchestration, automation, and response (SOAR); security incident and event management (SIEM); and correlation capabilities along with threat intelligence functions from Madiant, will become a foundational piece of Trellix’s technology stack, Palma said.
Helix is also an open platform, and its analytics engine ingests more than 600 native and open security technologies across a customer’s environment. “Right now we have over a billion sensors,” Palma said. It then correlates alerts and event data into actionable investigations with risk scores so organizations can see what threats to tackle first.
Trellix’s partnership with Mandiant will continue, too, Palma added. “So we get a lot of the frontline investigations that they do around incident response,” he said.
In addition to continuing the combined company’s XDR focus, Trellix will also continue McAfee’s commitment to open and open source security.
“I’m going to continue to drive us in two directions,” he said. “One is definitely more toward open source. The second one is more toward data science, which includes machine learning and artificial intelligence. So you’ll see us make a lot more investments in those areas.”
Comments