How Does a Cybersecurity Mesh Secure Growth?

3.0K views
β€’
August 22, 2022
by
RSAC Cybersecurity
YouTube video player
How Does a Cybersecurity Mesh Secure Growth?

TL;DR

A cybersecurity mesh secures digital acceleration by connecting protection across endpoints, networks, clouds, applications, and security operations. Shared policy, threat intelligence, visibility, and automation reduce the silos created by point products, while use-case-specific platforms preserve flexibility and help network and security teams coordinate responses across an expanding attack surface.

Transcript

All righty. Well, thanks everyone for getting up reasonably early to this session. I know it's listed at eight, eight AM I think. But, uh, so I'm John Madison. I'm the, uh, what am I? The CMO and the EVP of products at, uh, Fortinet. I also run our, uh, training team, education team. Uh, so far in the last five years, we've trained about just short... Read More

Key Insights

  • A cybersecurity mesh is a connected architecture spanning endpoints, networks, clouds, and security operations. It allows distinct products and teams to share policy and threat intelligence, helping organizations coordinate protection across the attack surface without forcing every capability into a single product or vendor.
  • The attack surface is becoming more distributed as organizations adopt remote work, mobile devices, cloud applications, operational technology, IoT, edge computing, and newer network infrastructure. Security therefore needs coverage across users, devices, networks, data, applications, and the different environments through which workloads move.
  • Point-product security creates operational silos when separate tools protect individual threat vectors or parts of the environment without communicating. Sending many isolated products into a single SIEM or security operations center does not provide the scalable coordination required for increasingly complex environments.
  • The primary purpose of a security platform is automation across the attack lifecycle. A threat detected through reconnaissance or another capability should immediately inform other parts of the system, enabling coordinated protection and response instead of leaving valuable detection information trapped inside a standalone tool.
  • Convergence combines networking and security functions within a product, team, and console. Examples in the presentation include bringing together firewall capabilities, software-defined wide area networking, and encrypted-traffic inspection so networking infrastructure can become more aware of applications, users, locations, and content.
  • Consolidation keeps multiple products and potentially multiple teams while connecting them as a coordinated platform. Unlike convergence, it does not necessarily eliminate separate tools. Its value comes from interoperability, shared policy, shared threat intelligence, and coordinated action across endpoint, network, cloud, and security operations.
  • Use-case-specific platforms are more practical than replacing every security product with a single vendor. Organizations can consolidate capabilities around needs such as working from anywhere, cloud-native environments, or operational technology, then require those platforms and their vendors to interoperate through open interfaces and information sharing.
  • The network remains central to both security and digital experience because it connects users, devices, applications, and data. Without ownership or visibility into the network, an organization may struggle to determine why user experience is poor, even when applications and security services increasingly operate in the cloud.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: What is a cybersecurity mesh platform?

A cybersecurity mesh platform is an architecture that connects security capabilities across endpoints, networks, clouds, applications, and security operations. Its products can remain separate, but they operate together by sharing policy and threat intelligence. The presentation also describes this concept as a fabric or platform, emphasizing coordinated coverage and automation across the entire attack surface.

Q: Why do organizations need a cybersecurity mesh?

Organizations need a cybersecurity mesh because digital acceleration has spread users, devices, applications, data, and computing across many environments. Separate security tools often operate in silos, creating complexity and visibility gaps. A mesh connects those capabilities so detections, policies, and threat information can move across the environment and support a coordinated response throughout the attack lifecycle.

Q: How does a cybersecurity mesh reduce security silos?

A cybersecurity mesh reduces silos by making distinct security products and teams exchange policy and threat intelligence. A detection made by one capability can inform other parts of the system instead of remaining isolated. This approach also encourages network operations and security operations to work together, improving coordination without requiring every product to be merged into one tool.

Q: What is the difference between convergence and consolidation?

Convergence combines several networking and security functions into one product, team, and console. Consolidation can retain multiple products and teams but connects them as a platform that shares policy and threat intelligence. The distinction is important because a mesh does not necessarily remove every separate product. It makes those products operate together as a coordinated system.

Q: Does a cybersecurity mesh require a single vendor?

A cybersecurity mesh does not require an organization to replace all security tools with products from one vendor. The recommended approach is to build platforms around specific use cases, such as remote work, cloud-native systems, or operational technology. Those platforms should then work together through cooperation, open interfaces, shared intelligence, and coordinated policy across the broader environment.

Q: Why is automation important in a cybersecurity mesh?

Automation is important because the volume of threats, vulnerabilities, and security tools makes purely manual coordination difficult to scale. The platform should carry a detection from one capability into other relevant controls and response processes. Automation needs to support both security operations and network operations, which requires closer coordination between the teams responsible for those functions.

Q: What role does AI play in cybersecurity platforms?

AI is presented as a future capability for detecting attack campaigns in the wild before they strike. Current technologies are described as relying more heavily on machine learning for specific threat vectors. Reaching broader campaign detection requires combining large amounts of threat information, correlating it, and determining where an attack is developing, which remains a highly complex goal.

Q: Why does network security remain important with cloud adoption?

Network security remains important because the network determines the digital experience of users and devices, even as applications and data move between cloud services, data centers, and private environments. If an organization does not own or control the network, it may not understand why the user experience is poor. The network also connects the assets that a mesh must protect.

Summary & Key Takeaways

  • Digital acceleration has distributed users, devices, applications, and data across endpoints, networks, clouds, operational environments, and edge systems. Security architectures built from isolated point products struggle to maintain visibility or coordinated protection across this expanding attack surface, creating a need for connected capabilities that address the full attack lifecycle.

  • A cybersecurity mesh connects multiple security products and teams without requiring every organization to adopt a single vendor. Products remain distinct, but they operate as coordinated platforms that share policy and threat intelligence. Organizations can build platforms around use cases such as remote work, cloud environments, or operational technology, then integrate them.

  • Automation is the primary reason to build a connected security platform. Detection from one component should inform protection and response elsewhere, rather than remaining isolated. This coordination must extend beyond security operations into network operations, eventually bringing AI-supported NetOps and SecOps together while preserving the network's role in user and device experiences.


Read in Other Languages (beta)

Share This Summary πŸ“š

Explore More Summaries from RSAC Cybersecurity πŸ“š