Palo Alto Networks added a marketplace to its security orchestration, automation, and response (SOAR) platform where customers can browse product integrations, security playbooks, and reports among other “content packs” to help them solve security use cases and protect against threats.
The security vendor acquired the technology for its Cortex XSOAR platform when it bought Demisto for $560 million last year, and earlier this year it added threat intelligence management to the platform.
Rishi Bhargava, VP of product strategy for Cortex XSOAR, said the marketplace focuses on “partners, customers, and vendors sharing and collaborating to build new automation and orchestrations.”
The idea behind the marketplace sparked a little over a year ago when Palo Alto Networks began interviewing customers about how they were using automation and developing security playbooks. However, Palo Alto Networks’ customers came back at the vendor with the same set of questions, Bhargava said. “What are other customers doing? What do your partners recommend? What is the best set of playbooks I should deploy in my environment?”
Of course, customers know their environment best, but there is still this collective desire to benefit from sharing best practices and procedures, Bhargava said. And for good reason. “Sharing best practices makes best practices better,” he said.
While the SOAR platform already integrates and automates processes and technologies, the marketplace benefits Palo Alto Networks and its partners because they can add new integrations and playbooks. And this, in turn, boosts the platform and third-party security tools use among joint customers. “The [return on investment] of the platform increases many-fold as people deploy more automations,” Bhargava said.
SOAR Marketplace Content Pack PartnersThe Cortex XSOAR Marketplace launches with content packs from customers and other cybersecurity providers including Code42, Google Chronicle, Illusive Networks, Recorded Future, RiskIQ, SafeBreach, Sixgill, Tufin, and Wipro. Customers can rank and review playbooks, and add on to them, which furthers the collaborative aspect of the marketplace, Bhargava said. The platform also includes more than 450 existing integrations currently available to customers.
While playbooks are an important tool in helping companies prepare for common types of attacks, they still aren’t widely used. A recent IBM Security survey found that only one-third of companies with a formal security response (that’s 17% of total respondents) had also developed attack-specific playbooks.
When asked to list his three most important playbooks, Bhargava said phishing tops the list. “Our most popular use case has been phishing, how do you respond to a phishing attack, and I would strongly encourage every customer to start there. We have seen some amazing ROI on that, and the amount of benefits that we deliver reducing the mean time to respond for a phishing attack.”
Threat intelligence and enrichment ranks No. 2, he said. This essentially adds an intelligence layer that ingests threat feeds to prioritize and block threats. “We have multiple marketplace launch partners focused on the threat intelligence feed side of things.” Bhargava said.
“And the third one I would highlight is inside threat protection,” Bhargava said. “I call if the overlooked risk” because companies often don’t know the amount of data and systems that their employees have access to, he explained.
Comments