Microsoft today announced the acquisition of cybersecurity software maker RiskIQ. The deal comes as the threat of ransomware intensifies across all industries and as Microsoft battles a spate of recent critical vulnerabilities that hackers exploited to breach its customers’ systems.
While the software giant didn’t disclose terms of the deal, Bloomberg yesterday reported that Microsoft agreed to pay more than $500 million in cash for the startup, citing people familiar with the purchase.
The RiskIQ acquisition follows several other cybersecurity buys over the past few years, and Microsoft execs have repeatedly said the company invests more than $1 billion annually on security. Last month, it bought IoT security startup ReFirm Labs for an undisclosed amount.
Buying RiskIQ “just reaffirms Microsoft’s emphasis on providing security resiliency in their offering,” IDC Program VP Frank Dickson said, in an interview with SDxCentral. “We’ve seen this constant drumbeat of acquisitions as Microsoft looks to improve their posture and get increasingly more serious about security. I would be surprised if this was the last acquisition we saw.”
RiskIQ raised a total of $83 million over five funding rounds since 2013. The San Francisco-based company’s platform discovers an enterprise’s entire attack surface, including known and unknown devices, across clouds, on-premises data centers, and the supply chain. It provides visibility from the network to the application layer and can detect and respond to threats and vulnerabilities across all external assets.
“In addition, RiskIQ offers global threat intelligence collected from across the internet, crowd-sourced through its PassiveTotal community of security researchers and analyzed using machine learning,” Microsoft Cloud Security VP Eric Doerr wrote in a blog post about the acquisition. “Organizations can leverage RiskIQ threat intelligence to gain context into the source of attacks, tools and systems, and indicators of compromise to detect and neutralize attacks quickly.”
How Will Microsoft Integrate RiskIQ?Acquiring RiskIQ — plus its attack surface visibility and threat intelligence — is a smart move for Microsoft, analysts say. But how the cloud giant plans to integrate these cybersecurity capabilities across the rest of its portfolio remains to be seen.
“Microsoft already has a solid security presence in identity and access management, threat protection and remediation, data security and compliance management,” Moor Insights and Strategy senior analyst Will Townsend wrote in response to questions. “This acquisition brings needed strength to their Azure toolset from a visibility and cloud apps security perspective.”
In fact, the acquisition could boost Microsoft’s stature as a security vendor, said Zeus Kerravala, principal analyst at ZK Research.
“Microsoft has talked a big game in security historically, but it’s not really delivered in this area. I think the purchase of RiskIQ brings some best-of-breed capabilities into the Azure fold,” Kerravala wrote in response to questions, noting that RiskIQ’s combination of visibility and threat intelligence enables customers to “not only identify a breach, but then understand all the possible implications from the systems connected to the breached one.”
Microsoft’s challenge will be to integrate RiskIQ with its other products, which include Sentinel and Defender, “to create a broader platform approach,” he added.
RiskIQ integrations could allow Microsoft to “do some pretty amazing things around attack surface management,” added Forrester senior analyst Brian Kime.
In an emailed response to questions, he said while these new, advanced security features will be “great for Microsoft customers already paying for E5 licenses,” he doubts that customers with lesser licenses will have access to many of the RiskIQ threat intelligence and security services. “Also, Microsoft traditionally offers very little in the way of freemium services, and they don’t directly sell threat intelligence,” Kime added.
On the flip side, RiskIQ customers may lose access to some of the security telemetry and threat data now that Microsoft owns the software vendor, Kime said.
“RiskIQ’s PassiveTotal service is famous for its Community version that provides users with most of the data RiskIQ has access to on threat infrastructure. I’m sure RiskIQ Community users are all nervous about losing that access for the few searches a day they conduct for free,” he explained. “Furthermore, RiskIQ has had subscription services for discovering phishing pages and social media spoofing to help protect customers. PassiveTotal subscribers also get to track threat infrastructure as it comes online. It will be interesting to see if Microsoft opens up its enormous amount of security telemetry to RiskIQ customers.”
Comments