SAN FRANCISCO — VMware’s buying spree in the leadup to last week’s VMworld added a slew of technology areas to its portfolio — everything from containers to artificial intelligence (AI) to security. But perhaps the most surprising acquisition announcement was Carbon Black, the endpoint security vendor that VMware plans to purchase for $2.1 billion.

Carbon Black developed a cloud-based endpoint security platform that uses big data and behavioral analytics to provide several capabilities including threat hunting, incident response, antivirus and endpoint detection, and real-time endpoint query and remediation. Its platform stops about 1 million cyberattacks per day, the company claims.

In a press conference at VMworld, Tom Corn, VMware’s SVP and GM of security products, said the acquisition was a “very thoughtful exercise that happened over several years together.”

VMware has been slowly moving into the security space since microsegmentation proved to be a top use case for its NSX network virtualization platform. It launched its initial standalone security product, AppDefense, in 2017 with Carbon Black as a partner and has since integrated Carbon Black’s technology into vSphere. VMware also jointly developed another product — cloud-based security software that automates threat detection and remediation — with Carbon Black.

In March, at the annual mega security event RSA Conference, VMware moved deeper into the security sector with an internal firewall it calls a Service-defined Firewall.

Just two days before announcing the Carbon Black deal, VMware purchased another security startup: Intrinsic.

Once the Carbon Black acquisition closes, VMware plans to embed that company’s technology into NSX and its other products including SecureState and Workspace One. And Carbon Black CEO Patrick Morley will lead VMware’s new security business unit.

VMware’s New Security Business

“Carbon Black is going to be at the heart of our intrinsic security solution,” Corn said. “The combination of Carbon Black solutions and VMware products … will create a modern security platform that can protect workloads and clients and applications for any app, any cloud, any device. With this acquisition VMware is going to take a significant position in next-generation security. This is a major milestone for VMware and the security industry at large.”

SDxCentral caught up with Morley on the expo floor at VMworld. He said he’s confident that the VMware-Carbon Black combo will provide the holistic security platform that enterprises need.

“There are two reasons we’re positioned in a way that will fundamentally help our customers and help us build a great security platform,” Morley said. “The first one is that cloud fundamentally changes security.”

What he means is before cloud, vendors were trying to cram a ton of security capabilities onto a device or endpoint and they were constrained by the device’s compute and storage powers. “Now with the cloud, I can drive more of my analytics up in the cloud,” he explained.

“And it allows me to take a set of services that customers think of as interrelated but we as vendors tend to think of as endpoint protection, and vulnerability management, and license management — all these different things that customer just look at holistically. The cloud totally transforms that paradigm and allows us to offer all these services on top of one platform,” Morley added. “So rather than having to bolt on each one from a different vendor, I can get great capabilities but in one platform. This will reduce costs, it’s a much better ROI for companies, and they only have one console.”

The second reason, Morley said, echoes what VMware CEO Pat Gelsinger has been saying for the past year about “intrinsic security,” or building security into the network instead of “bolting on” security as an afterthought.

“It’s way better to build it right in from the beginning,” Morley said. “The infrastructure management plane that they are building out at VMware, plus the ability to build our security products in natively to the VMware stack, it allows you to ensure you’re not missing gaps.”

Bigger Reach, Deeper Pockets

The deal also gives Carbon Black access to VMware’s massive customer base. Carbon Black has about 5,600 customers globally. VMware has 500,000, and you’d be hard pressed to find an enterprise that doesn’t use at least some part of its software stack and cloud services.

Additionally, Dell Technologies owns about 81 percent of VMware plus several other brands including Dell, Dell EMC, RSA, Secureworks, and Virtustream. It operates in 180 companies globally and claims 98% of the Fortune 500 as customers. So this acquisition will inevitably extend Carbon Black’s reach into the enterprise space — and provide much deeper pockets for things like product marketing and research and development.

“The opportunity for us, upon close of the transaction, you’re going to see us continue to invest aggressively in our roadmap,” Morley said. “We have a big, broad vision as Carbon Black. And with VMware, we just extended that vision pretty dramatically.”

He won’t give too many specifics on what this roadmap will entail that VMware executives haven’t already outlined. But it does involve embedding Carbon Black’s technology across VMware products and building additionally security services — like vulnerability management — on top of the Carbon Black-powered platform.

But perhaps the most important question: what will happen to all of the product names? VMware loves to put a “v” in front of its names, while Carbon Black’s products all start with “CB” — CB Response, CB Protection, you get the picture.

“That’s been a discussion,” Morley admitted, laughing. “You’ll probably see the letter 'v' get added in certain spots.”

Photo: Carbon Black CEO Patrick Morley at the VMworld 2019 General Session.