Palo Alto Networks and IBM expanded their alliance to counter AI threats through enterprise patch management cycles.
Alongside open source giant and IBM subsidiary Red Hat, the firms promise early vulnerability detection and fix deployment across open source software, operational technology (OT), commercial applications, and healthcare.
The venture integrates Palo Alto Networks’ Virtual Patching capability with IBM and Red Hat’s $5 billion commitment to open source security known as Project Lightwell. The process sees a virtual patch deployed at the network layer to block exploit attempts, software remediation for open source software via Lightwell for users to test and deploy in their environments.
According to IBM, capabilities include broader vulnerability coverage; preemptive virtual patch protections before official fixes become available; and protection deployed on the same day of discovery.
Nikesh Arora, CEO and chairman of Palo Alto Networks, said the venture comes in response to AI compressing the window between vulnerability discovery and exploit “from weeks to minutes.”
“Traditional patching cannot keep pace. By collaborating with IBM and Red Hat, we are shifting the advantage back to defenders. This powerful combination allows us to neutralize threats in the network while providing uninterrupted business continuity for our global clients,” Arora added.
"IBM established Project Lightwell to secure the open-source software foundation that enterprises rely on every day. By collaborating with Palo Alto Networks, we are extending that security from the source code directly to the network front lines. This joint solution gives our clients exactly what they need to thrive in the AI era: immediate, automated resilience against emerging threats, combined with the rigorous validation required to safely update their core systems," said Arvind Krishna, chairman and CEO of IBM.
Away from AI, the Palo/Lightwell integration also recognizes the increased need for OT security. As recently explored by this title, OT-based security threats have seen big ticket acquisitions this year such as Mitsubishi's buyout of Nozomi Networks, and ServiceNow snaring Armis for $7.75 billion.
Mauricio Sanchez, senior director at Dell’Oro Group, said cyber asset attack surface management (CAASM) and external attack surface management (EASM) are converging with IoT security needs, helping asset management become a “hot” security theme this year. The urgency has been reflected by government advice from authorities such as Britain’s National Cyber Security Centre, which recently published principles to help businesses manage OT system security.
Zero Networks CEO Benny Lakunishok said such advice is essential for natural infrastructure, adding: “In OT environments supporting energy, water, transport, and manufacturing, attackers often abuse trusted access that already exists – an approach seen in incidents affecting fuel pipelines, power grids, and water utilities.”
Comments