2024 has been officially branded as the "Year of the Security Platform" by vendors, but lurking behind the marketing fanfare is the risk of creating a "Frankencloud" - a patchwork of disjointed security products masquerading as an integrated solution.
Indeed it would seem this is a little bit more than a marketing slogan, as one major security vendor’s announcement around platformization saw their stock value drop as they focused on longer-term goals (PAN). Two quick things: First spellcheck hates the word platformization and maybe it should. Is this even a real word? Second thing - this quarterly results focus for public companies sucks. I wish more public companies would take a longer-term view.
Back on topic….
At Fortinet Accelerate 2024 earlier in April, you were invited to “step into the Platform Era” and focus on the convergence of the network and cybersecurity, adopting a platform-centric approach.
But is this new? I was on the Cisco Security Customer Advisory board for a couple of years around a decade ago and they certainly had a vision that included a broad approach to security, albeit mostly network-centric. Once a year, we would be introduced to approximately half a dozen new acquisitions that were intended to be integrated into Cisco’s overall security portfolio. Ultimately, did this result in a security platform? Products were integrated to some extent, and there was always a vision of an overarching management layer (Cisco Prime at the time).
2023 saw Microsoft announce Entra Internet Access and Entra Private Access. While this isn’t their first foray into the world of proxies and private application access, it is their first “as-a-Service” offerings in these categories and expands the breadth of their security platform offerings considerably. Zscaler has moved the other way, from having cloud-based network security into the world of Endpoint DLP, CNAPP, deception and data protection.
When I started my career, defence in depth was a standard approach when it came to security architecture. This was well before terms like EDR and SASE existed. Back then it typically meant selecting more than one security vendor. For example, an enterprise network may have had an external firewall e.g. CheckPoint, an SLB/reverse proxy in the DMZ e.g. F5 and then another firewall which segregated internal network zones such as a Cisco ASA. The theory was that these layered controls and vendors reduced the risk of a single point of failure causing a widespread security incident. Defence in depth does not necessarily mean using different vendors but sometimes this can be desirable.
I would argue that the same theory can be applied to the existing discussions regarding security platforms. There are clear benefits to a platform approach, especially with the proliferation of security tools, but equally, there are clear risks. Therefore, it is about being deliberate in where you adopt a platform play, but also where you may choose to have the independence of vendors. Much has been made of Microsoft's recent security challenges, and for some that has been enough to push the diversification strategy.
For example, you may choose to have a predominant security platform but still select point products for use cases such as EDR or secure coding.
So 2024 is the year you feel trendy and you’re heading down the One Ring / Isildur's Bane path but how do you select the right security platform amongst the noise?
Here are my thoughts:
Finally, come back to your business needs. Buying tools for tools' sake can be a gigantic waste of time and money. Buying a platform doesn’t solve this and can actually perpetuate the problem by giving you access to more things you don’t need.
If you use a security framework which contains a list of domains and associated risks and controls allowing you to prioritise based on your business needs and identifiable risk, this is going to get you better mileage than simply focusing on the technology.
Security platforms can allow you to consolidate a lot of point solutions, but not all platforms are created equal.
If you remember one thing from this blog, remember the term “Frankencloud”. I was first introduced to this term about a decade ago and it was used to describe the worst in platform plays - cobbled together solutions that simply don’t work. In fact, they created dissynergies (cool word aye). Aristotle may have coined the term: “The whole is greater than the sum of its parts”, but he’d never met Frankencloud….