COVID-19 affected every sector during 2020, and cybersecurity’s no different. Some of the pandemic-related changes proved beneficial as companies realized overnight the necessity of securing a now-perimeter-less workforce. As a result, security budgets were the one area that typically didn’t see any cuts — and in some cases even increased — during the economic downturn. But will that cybersecurity spending continue in 2021?
While many companies put more money into security tools and services in 2020, security startups (and startups in general) faced a new set of challenges when it came to fundraising and landing customers. By late March, travel basically stopped, which made face-to-face meetings between companies, investors, and prospective customers virtually impossible — and only possible virtually.
“So much of venture is really about forming relationships between investors and entrepreneurs, and it’s very, very difficult to build those relationships virtually,” said Bob Ackerman, co-founder of DataTribe and Allegis Capital, a VC firm that focuses on seed and early-stage investing in cybersecurity companies. “I don’t care how many Zoom calls you have, it’s not a substitute for sitting down and spending hours or spending days together, getting to know each other. And we are simply not making investments in teams that we haven’t spent significant time.”
How Do You Sell Over Zoom?While it’s difficult to raise money without in-person contact, it’s also hard to convince new customers to sign large contracts over video meetings, added CrowdStrike co-founder and former CTO Dmitri Alperovitch. “It’s very hard to sell to new customers, particularly big deals, without having a preexisting relationship,” he said.
“In 2020, companies relied on existing relationships with customers that they established before the pandemic hit,” Alperovitch continued. “But as you’re sort of moving into prospecting for new customers, it’s really hard to do it over Zoom and build a close relationship with the CISO or the CIO to snag that million-dollar or multi-million-dollar contract.”
Both Ackerman and Alperovitch, along with CodeDX CEO and founder Anita D'Amico, this week sat on a panel (also via Zoom) that discussed the hot technology investments for 2021 and beyond. Most of these technologies and the trends shaping them started before the pandemic hit. But COVID-19 gave them a major jolt because the virus has likely forever changed where and how we work, and therefore how we secure corporate infrastructure and assets, the panelists said.
COVID-19 Will Shape 2021 Cybersecurity PrioritiesCOVID-19, and the related virtualization of the enterprise perimeter, will shape cybersecurity in 2021 and beyond, Ackerman said. “The new endpoint is the individual, and that really forces us to rethink our architectures for securing the enterprise,” he explained.
Because of this, enterprises are prioritizing spending on technologies that secure their new virtual perimeter and support a zero-trust and distributed cloud edge approach.
“Expect to see a lot of innovation in terms of how we secure that new virtualized perimeter — the individual working at home or working remotely,” Ackerman said. “So one device that device supports the work environment and also supports our home environment. How do you bifurcate those two, manage those two? How do you put a firewall between those two? Certainly, we see a lot of adversarial activity kind of coming in through the individual side of the device, looking to penetrate into the enterprise side of device. So it really creates an entirely new dynamic from a perimeter perspective.”
Remote Work Here to StayEven after a COVID-19 vaccine becomes widely available, Alperovitch said he doesn’t expect employees to return en masse to company facilities. “Remote work is here to stay,” he said. And as such, the migration from on-premises workloads to cloud-based services will continue. This means business will continue to invest in technologies to secure their cloud environments, and they will also use more cloud-delivered security tools, he added.
This also means that developers will build more cloud-native business applications, which requires a DevSecOps approach, D’Amico said. DevSecOps, or embedding cybersecurity controls and processes into DevOps, will see more investment in 2021, she added.
“We’re seeing software come out faster and faster than it ever has before, and we’re seeing a reliance on mobile applications. These release cycles are some time in minutes, and yet there’s security that has to be put into DevOps,” D’Amico said. “There’s a lot of opportunity there for investment, there’s a lot of opportunity for innovation.”
Automation, Managed Services Will SkyrocketWhile many companies’ security budgets got a boost in 2020, in part because of government stimulus checks, Alperovitch forecasts security spending will slow next year as travel resumes and the long-term effects of the pandemic continue to weigh on the economy. There was already a well-documented shortage of skilled cybersecurity professionals before 2020, and because of this Alperovitch expects automation to become increasingly important in the years ahead.
“There will be pressures on hiring and security teams — how do you do more with less? How do you automate a lot of the work that currently gets done manually? The security technologies that help you with that will be very hot,” Alperovitch said.
And similar to automation: “managed services are the future of security,” he added. “It’s not even about not having enough budget to hire people. It’s also about not being able to recruit the talent that you need because of the highly competitive environment that exists for really top-notch employees.”
Threat Intelligence, Data-Centric Cybersecurity in 2021Threat intelligence is another cybersecurity area where Ackerman expects to see innovation — and VC dollars — in 2021.
Today, it typically takes organizations 270 days to identify an attack has occurred, he said. “At that point, you’re cleaning up after the fact. Anything we can do to identify those attacks while they are in formation, or while they’re in the early stages of being launched allows us to mitigate a lot of the risk a lot of exposure.”
And finally, data-centric security technologies are hot right now, and rightfully so, Ackerman said. While cybersecurity vendors talk a lot about securing infrastructure, the reason to secure infrastructure is to protect what runs on these systems. “The mouse is after the cheese, and the cheese in the cybersecurity world is the data,” he said. “So, I think there’s going to be a lot more focus on securing data, controlling who has access to data, and taking more of a data-centric approach to cybersecurity.”
Comments