* Symantec-Veritas deal opens up possibilities
endif; ?>The end of 2004 was particularly noteworthy for its large number of acquisition and alliance announcements. Casting a shadow over them all, however, was the announced merger of Symantec and Veritas.
Personally, I am a little amazed at how many were surprised by the announcement. Data resilience and business continuity are fundamental to comprehensive enterprise security, which increasingly has a more distinctive risk management flavor. In introducing its “information integrity” strategy in October, Symantec made it plain that these priorities would be central to a strategy that was clearly enterprise-oriented. In view of the fact that Symantec did not have a substantial portfolio in this area, acquisition was expected.
What was unexpected was the scale of the union – unexpected at first blush, that is. Symantec and Veritas actually have much in common. They have both been highly successful in their core markets. Both have amassed a large cash reserve (approximately $5 billion between the two companies – which, by the way, has been effectively preserved by the all-stock deal). Both have sought to acquire their way into a stronger enterprise presence to grow beyond their core competencies, and both have experienced mixed success along the way.
Both stand to gain much from each other’s strengths. Symantec wins a presence in the enterprise that it presently lacks. This would go far to mitigate the risks of its exposure both in the consumer market and to Microsoft – whose vulnerabilities have been fundamental to Symantec’s success and which could be problematic for Symantec, given Microsoft’s desire to make Windows more secure. Veritas gains consumer opportunities as well as a leg up in security credibility that few storage vendors have achieved, if their competitors have made it a priority at all.
The question now is what will the new Symantec be? Will it become mainly a “bigness” engine, taking advantage of its sheer size and resources simply to buy more markets, more presence, and more revenue? Or will it integrate its resources to actually redefine the management of security and storage – and potentially a number of other markets as well?
The history of both companies has looked more like the former. Both companies have made a series of acquisitions to shape their presence and flesh out an enterprise strategy. In fact, this aspect of the careers of executives of both companies was highlighted in a recent conference call they hosted concerning the merger, as was the value of potential markets beyond security and storage per se, so expect the trend to continue.
But the potential of the combined entity to reshape significant aspects of management is truly tantalizing, and it will have the resources to do so. So far, the strategy is largely confined to the realm of vision. Big pieces are missing. The market will not only expect execution on integrating storage management with security to justify the deal. The broader “information integrity” strategy will necessarily require significant aspects of infrastructure management not presently in the portfolio, and some assets already in the portfolio need to become more competitive. These aspects will not materialize out of the integration of storage and security management alone.
If Symantec is successful, the consequences would be disruptive to say the least. At a time when IT’s pocketbook has been shrinking, the enterprise is forced to budget for security and compliance regardless. It is also looking for consolidation. We have seen increasing convergence of mainstream management with security – but Symantec would make security a central priority rather than an aspect of its products.
These forces could combine to bring a distinctive risk- and compliance-management flavor to the market. The ability to diagnose a security event as the root cause of availability issues has often been overlooked by infrastructure management tools – yet availability assurance is a core principle of security management. Security management has long been predicated on adopting a process approach to implementation that fundamentally recognizes the role of people and policy – something relatively more recent to other aspects of IT, coming with the emphasis on compliance and process discipline centered on ITIL, for example.
Will the benefits of this security-based outlook influence the management industry as a whole, thanks to the size and weight of the new Symantec? The answer will take shape in stages and depends highly on the nature and success of significant milestones the new company has yet to achieve, like gaining a credible presence in more mainstream infrastructure management disciplines and execution on integrating the assets of today’s Symantec and Veritas.
We expect to see highly visible progress in each of these areas, however – and each milestone will have a bearing on the ultimate answer.




