IBM today said it plans to acquire ReaQta, which rounds out its endpoint detection and response capabilities and will allow it to provide a full-stack extended detection and response (XDR) platform. And it simultaneously rolled out a new XDR software brand.
But while other vendors in the emerging XDR space debate a platform versus open or partner approach, IBM remains committed to providing both, says Chris Meenan, VP of IBM Security product management and strategy.
“The open nature is super important,” Meenan said. “Many organizations have made significant investments in the core telemetry pillars of XDR, and they are not ready to rip and replace but they want to streamline workflow. They want these insights brought together and made more actionable, which is what XDR is really focused on.”
However, other organizations want to simplify their security landscape and reduce the number of vendors and tools deployed in their environments. “And by providing each of these [XDR] capabilities natively, we provide that option to them, but we’re not going to lock them into using our components,” Meenan added.
Why Zero Trust Needs XDRXDR combines elements of security information and event management (SIEM); security orchestration, automation, and response (SOAR); endpoint detection and response (EDR); and network traffic analysis (NTA) in a software-as-a-service platform to centralize security data and incident response.
IBM’s security portfolio already includes SIEM, NDR, and SOAR. “ReaQta gives us that critical endpoint capability we were missing in our portfolio,” Meenan said.
The acquisition and XDR in general also plays into IBM’s zero-trust security strategy, he added. “When we think about the three pillars of zero trust — trust nobody, continuously verify, and assume breach — we see XDR as the core foundation of the assume breach part of zero trust.”
Additionally, IBM’s XDR software runs on its Cloud Pak for Security platform, which also pulls in IBM’s data security and identity portfolios
“This provides additional context and control points around what’s happening with data, what’s happening with identities, and being able to take action on those to help customers deliver zero-trust outcomes,” Meenan said.
How ReaQta Provides Endpoint SecurityReaQta (pronounced react-ah) is an endpoint security startup that uses artificial intelligence and behavioral analytics to detect and stop both known and unknown threats.
The Amsterdam-based company’s platform can be deployed on premises or in the cloud as well as in air-gapped environments. It blocks any abnormal behavior via deep learning on each endpoint, which also constantly improves its threat-behavior identification, according to the vendor. Plus, its Nano OS monitors the operating systems from the outside, which helps prevent interference by adversaries.
IBM didn’t disclose the financial terms of the deal but said it expects the acquisition to close later this year. At that time, ReaQta’s technologies will become part of IBM’s new QRadar XDR brand, which it also announced today.
As part of IBM’s open XDR strategy, customers can use IBM’s native XDR security tools or those from third-party vendors. Through its ongoing commitment to the Open Cybersecurity Alliance (OCA), as well partnerships and integrations with 200-plus cloud and security vendors, IBM claims to have the industry’s largest XDR ecosystem.
Open XDR Needs Open StandardsAnd while XDR alliances and so-called open XDR have become almost as popular as the buzzy acronym itself, with vendors including CrowdSrike, VMware, and Exabeam among those launching new XDR groups, there’s something to be said for open-standards-based security platforms, Meenan said.
“Any form of vendors working together is positive,” Meenan said. “But I don’t think any of these alliances are really moving the needle or changing the space. They still end up with lots of point-to-point integrations, where you have one vendor talking to the vendor-specific APIs of another. We end up with this n-factorial complexity of keeping interfaces up to date and customers bearing the brunt of that.”
The OCA aims to solve this problem. “The whole purpose of the Open Cybersecurity Alliance was: Why are we all building these integrations multiple times? Why don’t we build these integrations once and share them in the community,” Meenan said.
IBM Security and McAfee spearheaded the open source group in 2019 and contributed to the initial open source content and code. It aims to make the myriad security products on the market interoperable using open source code, as well as open standards and protocols. The group now has about 30 member organizations, and it’s governed under the auspices of OASIS Open.
Comments