How Should Enterprises Integrate Security Tools?

66 views
•
August 22, 2022
by
RSAC Cybersecurity
YouTube video player
How Should Enterprises Integrate Security Tools?

TL;DR

Enterprises should select security technology by considering total cost of ownership, integration capabilities, ease of use, and alignment with a documented security architecture. Surveyed professionals increasingly favor integrated solutions over isolated best-of-breed products because separate tools demand specialized training, complicate operations, fragment visibility, and place additional pressure on teams already facing staffing and skills shortages.

Transcript

I'm Jon Oltik. I'm a senior principal analyst and fellow at the Enterprise Strategy Group, and I'm joined by my good friend and distinguished president of ISSA, Candy Alexander. Good morning, everyone. Good morning. So we're gonna present this. This is, this is great. This is our inaugural presentation here. We do, uh, we do an annual, uh, report o... Read More

Key Insights

  • Security technology complexity is an operational burden because each product can require separate training, implementation, configuration, and ongoing management. This burden becomes especially serious when organizations lack enough cybersecurity staff or cannot maintain all the specialized skills demanded by their collection of tools.
  • Fragmented security visibility is a persistent problem because professionals must examine separate product interfaces and manually aggregate their findings. The resulting dependence on human effort prevents teams from obtaining a complete security picture efficiently, even though vendors are attempting to improve integration across their technologies.
  • Organization size influences security tool counts, with smaller organizations often using fewer than 25 products and larger organizations using more. The survey therefore challenges the blanket assumption that every enterprise simply has too many tools, while still identifying management and integration difficulties across technology environments.
  • Total cost of ownership is the leading consideration when organizations evaluate security technology. Purchase price alone does not capture the operational demands of learning, configuring, managing, and staffing a product, so buyers must account for the broader cost of making technology effective within their environments.
  • Product integration is increasingly important because cybersecurity teams face limited staffing and skills. Mature integration becomes particularly valuable as organizations adopt cloud and SaaS environments, where disconnected products can deepen operational problems for both IT operations and security operations personnel.
  • Peer networks are trusted sources for technology decisions because professionals want to know what colleagues and comparable organizations are using. Cybersecurity associations and professional groups help buyers cut through vendor marketing, while evaluations of isolated products become less relevant as endpoint, network, SIEM, and email technologies converge.
  • Open standards are strongly favored because future interoperability depends on vendors supporting common methods of integration. The presenters argue that standards need not eliminate competition, since vendors can still differentiate themselves through execution, functionality, and the resources they provide to help customers succeed.
  • Security purchasing strategy is shifting toward integration, with 38% of respondents favoring integrated solutions, 24% favoring best-of-breed products, and 15% using best-of-breed products while moving toward integrated solutions. All but 6% considered best-of-breed integration at least somewhat important.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: Why are separate security tools difficult to manage?

Separate security tools are difficult to manage because each product can demand its own training, implementation process, configuration, interface, and operating procedures. Teams must learn how to use every technology effectively while also combining information from multiple views. This workload becomes especially problematic when the organization lacks sufficient staff or skills, a challenge identified by 30% of surveyed professionals.

Q: What should enterprises consider when buying security technology?

Enterprises should first consider cost and total cost of ownership, which the survey identifies as the most important purchasing consideration. They should then assess product integration capabilities and ease of use. The evaluation should include the staffing, training, configuration, and management required after purchase, rather than treating the acquisition price as the complete cost of the technology.

Q: How does organization size affect the number of security tools used?

Security tool usage generally scales with organization size. The survey included 280 cybersecurity professionals from organizations ranging from fewer than 100 employees to more than 20,000 employees. Smaller organizations often reported using fewer than 25 tools and concentrating on basic technologies, while larger organizations tended to operate more tools. The findings therefore do not support one universal tool-count problem.

Q: Why is security product integration becoming more important?

Security product integration is becoming more important because limited staff must operate technologies across IT operations, security operations, cloud services, and SaaS environments. Without effective integration, professionals must manually combine information from separate products to understand security conditions. Integrated technology can reduce this fragmented visibility and help organizations use existing personnel and skills more efficiently.

Q: Are enterprises moving away from best-of-breed security products?

Enterprise preferences are gradually shifting away from relying exclusively on isolated best-of-breed products. The survey found that 24% of organizations tended to buy best-of-breed products, while 38% tended to purchase integrated solutions. Another 15% bought best-of-breed products at the time but were moving toward integrated solutions, showing a broader cultural change in purchasing strategy.

Q: How important is interoperability for best-of-breed security products?

Interoperability is important even when an organization continues choosing best-of-breed products. All but 6% of respondents described a best-of-breed product's ability to integrate with other technologies as critical, important, or somewhat important. Organizations may still want excellent individual components, but those components must contribute to a connected environment rather than operate as isolated technologies with separate views.

Q: Why do cybersecurity professionals rely on peers when selecting products?

Cybersecurity professionals rely on peers because colleagues and industry groups can describe how products perform in real organizational environments. The survey placed cybersecurity industry associations and interaction with peers among the leading decision resources. These conversations help buyers understand what comparable organizations use and cut through marketing claims, especially as integrated products become harder to assess through isolated product rankings.

Q: How can open standards improve enterprise security technology?

Open standards can improve security technology by giving products common foundations for interoperability. Survey respondents showed their strongest agreement with the desire for vendors to promote and support more open standards, and they connected future interoperability with industry standards. The presenters argue that vendors could still compete through execution, features, functionality, and customer support while making their products easier to integrate.

Summary & Key Takeaways

  • A survey of 280 cybersecurity professionals found that tool usage varies with organization size, with smaller organizations often using fewer than 25 tools and larger organizations using more. The central challenge is not merely the number of products, but the training, implementation, configuration, management, and human effort each separate technology requires.

  • Cost and total cost of ownership remain the most important considerations when organizations purchase security technology. Integration capabilities and ease of use follow closely because understaffed teams need products that work together across IT operations, security operations, cloud, and SaaS environments without requiring extensive manual aggregation or specialized expertise for every separate tool.

  • Purchasing preferences are shifting from isolated best-of-breed products toward integrated solutions. Only 24% of respondents said their organizations tend to buy best-of-breed products, while 38% favor integrated solutions and another 15% are moving toward them. Professionals also want vendors to support open standards, reduce complexity, and provide substance beyond marketing claims.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚