The big events of the last two years — COVID-19 and ransomware — put a fine point on the importance of cybersecurity. And in 2022 that’s going to translate into bigger security technology budgets.
A recent ESG report, for example, found that 69% of technology decision makers say their organization will increase security technology spending this year, and IDC forecasts security product revenue will hit $77.8 billion this year, up from $67.7 billion in 2021.
With this money burning holes in their pockets, CISOs are looking to invest in security products that support their companies’ digital transformation efforts and remote, distributed workforces, according to analysts.
“So they are buying solutions for cloud application security, data security, cloud infrastructure security, network security, and endpoint security,” ESG analyst Melinda Marks wrote in response to questions.
Marks pointed to ESG’s report that found nearly two-thirds (62%) of respondents said their organization will increase spending on cloud application security, followed by data security (58%) and cloud infrastructure security (56%). About half said they plan to increase spending on network security (55%) and endpoint security (50%).
“We also expect them to invest in ransomware solutions and cyber insurance to deal with the rise of ransomware and the inevitability of attacks,” Marks said.
How COVID-19 Shaped Security SpendingLike everything else over the past two years, the COVID-19 pandemic has shaped cybersecurity strategy and spending trends.
In 2020, shortly after the coronavirus became a global pandemic, companies shut their doors and sent their employees home to work remotely while schools closed and rolled out online classes en masse.
“So 2020 was, oh my gosh, everybody is sent home, how do we get everybody up and running? And so we did that,” IDC Security and Trust Program VP Frank Dickson said.
Companies accelerated their digital transformation efforts and moved more of their apps and infrastructure to the cloud, while security teams were tasked with securing fully-remote workers, consumers, and learners. VPN popularity spiked.
But then by 2021, with the pandemic still raging and people still largely at home, companies started re-thinking VPNs as the answer to securing a remote workforce, Dickson said.
Meanwhile, as organizations struggled to protect perimeter-less IT environments and workers from skyrocketing cyberattacks, zero trust became the latest security buzzword. It soon won celebrity endorsement as high up as the White House.
“So we all rushed out to buy zero-trust type resources,” Dickson said. “We understand zero trust in concept, but how do we implement it? How do we make it real?”
CISOs Prioritize Remote Worker Security, Zero TrustIn 2022, Dickson expects CISO spending to focus on ways to improve remote worker security and implement a zero-trust security architecture. Securing identity is a good place to start.
“One of the areas that was quietly popular through COVID and 2021 was identity,” Dickson said. “I think you’re going to see more and more identity solutions being implemented. How do we implement least-privilege access? How do we start limiting access to application and data that you need and ensuing that we don’t give you access to data that you don’t need? Identity is one big theme.”
Identity becomes increasingly important as CISOs secure a remote workforce and one that accesses corporate assets from multiple devices, said Zeus Kerravala, founder and principal analyst at ZK Research.
“Because a user is a user is a user. You could be coming from different places and difference devices,” he explained. “And so trying to provision everything at the IP level, at a network level, gets increasingly complicated the more devices people have. You want to start with good identity protection and then expand your zero trust from there.”
Focusing on identity protection — as opposed to network protection — requires a mindset change, Kerravala added. “In some ways the network becomes almost transparent,” he said. “The zero-trust policies almost run as an overlay to that.”
Dickson describes this as “one policy to rule them all.” By this he means setting identity- and access-based policies, and then replicating those policies via APIs across a company’s entire architecture. “In the cloud world you have maybe six different IaaS environments, five different PaaS environments, and hundreds of different applications,” Dickson said. “Setting those policies one at a time doesn’t work.”
Security Tool Consolidation, XDR Bubbles UpAdditionally, CISOs want to consolidate security tools and converge network, endpoint, data, and workload security and telemetry. So it makes sense to invest in products that make this easier.
“CISOs are coming to grips with the fact that they don’t have enough security people,” Dickson said. “They’ve got hundreds of applications to protect, thousands of devices to protect, and too many security tools are making it hard to implement security. So we’re looking for more and more integrated solutions.”
Most analysts agree that a consolidated, platform approach to security is the way to do this, and this has given rise to things like extended detection and response (XDR).
XDR combines elements of security information and event management (SIEM); security orchestration, automation, and response (SOAR); endpoint detection and response (EDR); and network traffic analysis (NTA) in a software-as-a-service platform to centralize security data and incident response.
“Siloed security platforms — SIEMs, and EDR, and [network detection and response], and things like that — only give you a very small snippet of what’s going on in the environment,” Kerravala said. “Where you should be seeing the investment is the platform-based approach, products that ingest data from a whole bunch of different sources and use AI to look across the entire kill chain.”
This consolidated approach doesn’t mean companies need to consolidate their security landscape to a single vendor. But their products do need to integrate and provide a unified view and security posture across an organizations’ landscape, said Mauricio Sanchez, research director for network security at Dell’Oro Group.
CISOs Want Choice“A lot of CISOs would like to have choice,” he said. “In the security landscape, it hasn’t necessarily been an easy thing to get integrations to happen between different solutions, but they are happening at an increasing level. CISOs need to make a decision about that from a procurement path. Do they prefer a single-vendor approach where that single vendor offers a huge portfolio of technologies that they can pick from? Or do they value having a more integrated, best of breed where they may have to take on some of that integration?”
While historically integrating different vendors’ security products was a sometimes insurmountable task, more vendors are moving in this direction and building awareness between “what used to be individual silos in the cybersecurity landscape,” Sanchez added, pointing to XDR and the unified telemetry it provides as an example.
“It’s ultimately bringing that platform view to the table,” he said. “It’s seeing am I buying a bunch of parts that aren’t necessarily working together in any cohesive way? Or is there a strategy in place where these parts are, in fact, a cohesive set of technologies that are together more valuable than the individual pieces may be on their own?”
According to Kerravala most vendors can’t provide full XDR across a company’s entire environment. He suggests CISOs that do adopt XDR start with their biggest pain point. “For most companies, it’ll be web-based applications. So start with vendors that have good [cloud access security broker] and good [secure web gateway] as part of your XDR,” he said.
“EDR is also an important part of it,” Kerravala continued. “To me the core components of XDR are network, cloud, and endpoint, and then you can build the rest around that. If you don’t have good knowledge about what’s going on in the cloud, knowledge of what’s going to the network, and good knowledge going down to the endpoint, that’ll just leave them a bunch of blind spots.”
Gain Efficiencies With AI, AutomationWhile securing remote workers and developing an integrated, XDR approach may top the list of CISO spending trends, the ongoing cybersecurity skills gap will also influence investments. Because of this, analysts suggest spending money on automation and artificial-intelligence-based products and services.
“CISOs should prioritize solutions that utilize automation and that can analyze data coming from different sources in ways to eliminate manual work and streamline workflows across teams,” Marks said. “It’s not just about the cost of the security solution, it’s about what efficiencies you can gain, or how you can best prioritize your actions according to what will make the highest impact in reducing security risk.”
Security teams don’t have the time or the resources to comb through massive amounts of data manually, Kerravala added. “There’s a lot of nervousness around AI and automation, but I think it’s time to start trusting machines.”
Comments