Better management and integration could be in the offing.
endif; ?>Major vendors continue buying security companies at a rapid clip, offering hope to corporate security executives that industry consolidation will produce multifaceted security architectures that are easier to configure and manage. Where some experts see opportunity, however, others see a trade-off resulting in fewer choices and a new set of risks.
Last week Secure Computing laid down $274 million for CipherTrust to broaden its product line with e-mail protection. This was just the latest deal in the close to $3 billion spent industrywide this year by vendors seeking to improve their security portfolios. Earlier acquisitions included Cisco’s buying Meetinghouse Data Communications, EMC’s purchase of RSA Security and McAfee’s taking on Preventsys.
These sales could be good news for customers thinking about consolidating products from many vendors under a single umbrella, says Babak Pasdar, CTO and chief information security officer for security services provider IGX Global.
Secure Computing’s purchase of CipherTrust makes sense because it could blend e-mail security into Secure Computing’s access, identity and application-control products, potentially making them all easier to manage, he says.
Such consolidation also could let customers whittle down the number of vendors they have to deal with. “It’s nice to see two security powers merging to provide more of a total security scope,” says Kyle Hussey, network analyst at Grant County Public Utility District, a hydroelectric utility in central Washington state. “We deploy Secure Computing products because of their reliability and security features. We deploy CipherTrust for the same reason,” Hussey says.
Companies with a range of security products could fill a gap not being filled effectively enough by security information management (SIM) vendors, Pasdar says. SIM software makers don’t push enough for standards about information collection and categorization, he says.
“They deal with disparate technologies, disparate vendors with disparate formats, and you cannot get a view centrally of what’s happening in your environment on a reasonable time frame,” he says.
A single vendor offering a number of security technologies could address this issue, albeit in a proprietary fashion, he says. “The product integration efforts of consolidation in that sense [are] a positive thing, but it remains to be seen how well they execute,” he says.
The potential for integrated management is the most exciting thing about consolidation, says Dave Row, security manager for holding company Retail Venture Services in Columbus, Ohio, which oversees chains such as DSW and Value City Department Stores. “Consolidation can’t happen fast enough,” he says.
Faced with increasing regulations such as payment card industry standards about processing, transmitting and storing credit card data, Row finds himself evaluating and buying many products with individual functions and their own unique management platforms.
Retail Venture uses encryption technology from Vormetric to protect credit card data at rest. The technology uses encryption keys and has its own key infrastructure. That’s fine for database encryption; for the separate task of encrypting laptop hard drives, he says another vendor, perhaps PGP, would be a better choice.
It would make sense and make his life easier, however, if they shared a common key infrastructure. “But they don’t integrate for a common key management,” Row says.
While Row is resigned to buying point products that answer today’s needs, he picks vendors carefully. It’s better if the vendor he chooses gets bought by a larger company, a scenario that has paid off for him. Row says Retail Venture is a big Cisco shop that was using Okena intrusion-prevention products when Cisco bought Okena. “That was good for me just by consolidating support,” he says.
Not everybody welcomes security firms getting bought up, however. As a general rule, says Jim Key, IT director for BigRiver.net, a Tennessee ISP, he prefers to deal with security vendors with a smaller range of products rather than a large, broad selection. “I find you get better support and more familiarity with the product with the smaller vendor,” he says.
He is also leery of how well acquiring companies will integrate purchased technology into their product lines. “Most buyouts I’ve seen, things seem to get worse,” he says.
Others view security as a unique market where to get the best protection possible from threats, diversity among vendors is particularly important.
“My concern is that when Symantec owns the hardware edge solution, the server antivirus solution, the desktop antivirus solution and the handheld antivirus solution, a vulnerability in a core Symantec product could manifest itself in the whole security solution for the enterprise,” says Michael Gonda, senior system administrator with a midsize professional services company in Pittsburgh. “The obvious problem here is that it seems like there are less and less providers to choose from.”
Although Gonda acknowledges the advantages of dealing with a single company’s products and support, “most of the positives are really only lazy conveniences, while the negatives could be pretty significant,” he says.
In addition to this rash of acquisitions changing the shape of the security market, one analyst says Microsoft is an important factor to consider. The company plans to buy VPN vendor Whale Communications, but it also has announced in-house security development, such as including a personal firewall in the upcoming Vista operating system, says Neil MacDonald, vice president and distinguished analyst with Gartner.
Microsoft’s aggressive pricing and its practice of bundling free products into its operating systems could drive down the cost of security products in general, he says.
Row says he’d welcome a stronger Microsoft presence in security because its software is so pervasive in end devices and servers. He says he looks forward to the desktop firewall capabilities being touted for Vista. “I’d like to be able to say this is business traffic and this is what we permit and here’s a violation of it. I don’t know of any tools that can help me do that today,” he says.
Pasdar, however, says he is unconvinced of how serious Microsoft is about becoming a security player. “If they choose to take security seriously, they could do a good job of it,” he says. “The question is if Microsoft is saying what they’re saying to seem involved — to pacify people and make it look like they care — or if they’re really focused on security.”
MacDonald points to another factor affecting security buying: the growing popularity of free, open source security products and products based on open source that cost significantly less than the competition. Enterprises’ increased interest in such products eventually should pressure vendors to lower the price of their proprietary offerings, he says.
However it shakes out for the vendors, Row says he eagerly anticipates the time when he can divest himself of some of his point-product suppliers and deal with fewer vendors that offer better-integrated architectures. He says he can’t keep adding stand-alone devices to his network forever. “At some point, I’m going to go through a consolidation of my own,” he says.
Bedfellows The security industry has experienced some significant consolidation in 2006. Among the deals made: | ||||||||||||||||||||||||||||||||||||||||||||||||||||
|




